Haystack
← Back to Jobs
Remote
Technology

100% Remote - Sr. Cloud Network Engineer

Empower ProfessionalsUnited States🇺🇸United StatesPosted 22 Jul 2026

Why This Role Stands Out

This 100% remote Sr. Cloud Network Engineer role offers significant opportunities to leverage your expertise in AWS networking and Terraform while contributing to impactful projects. If you are a seasoned professional with a passion for cloud infrastructure and a knack for DNS architecture, you will thrive in this dynamic and flexible environment. Apply today to advance your career with Empower Professionals!

Quick Overview

Work Type
Remote
Level
Mid Senior

Job Description

Role: Sr. Cloud Network Engineer
Location: 100% Remote
Duration: 12+ Months
Must have:

  • 7 yrs of exp in: AWS Networking, SIEM Integration Required
  • 7 yrs of exp Terraform Hands-on DNS Architecture Required
  • 5 yrs of exp GovCloud Strongly Preferred & AWS Security & Firewall Design Required
  • 5 yrs of exp Kafka/Event Hubs + Redis
  • 5 yrs of exp Kubernetes (AKS) + Microservices
  • AWS GovCloud
  • VPC
  • Transit Gateway
  • AWS Network Firewall
  • Route 53 DNS
  • VPC Endpoints
  • Terraform
  • BGP Routing
  • FIPS Compliance
  • FedRAMP
  • VPC Flow Logs
  • Splunk/SIEM Integration
  • Entra GCC High Federation
  • Multi-Account AWS Architecture
  • Network Security

Requirements:

  • Network Engineering 8+ Years
  • AWS Networking 5+ Years
  • Terraform Hands-on
  • GovCloud (Strongly Preferred)
  • AWS Security & Firewall Design
  • DNS Architecture
  • SIEM Integration

Responsibilities:

  • The Senior Cloud Network Engineer (Onshore) will lead the design, deployment, and support of the AWS GovCloud network foundation for the Landing Zone program. Working directly with the client, this role is responsible for implementing and managing secure, scalable, and highly available multi-account AWS networking environments. The engineer will design and configure core AWS networking components including VPCs, Transit Gateway, AWS Network Firewall, VPC Endpoints, Route 53 DNS, and FIPS-compliant service endpoints while ensuring alignment with AWS best practices and approved architecture standards.
  • The role requires hands-on expertise in deploying multi-account VPC architectures, including subnet design, route tables, security groups, and Network ACLs (NACLs). The engineer will implement and manage AWS Transit Gateway attachments, route propagation, and inter-account connectivity within hub-and-spoke network topologies. In addition, the candidate will deploy AWS Network Firewall using both stateful and stateless rule groups to enforce enterprise security policies and network segmentation requirements.
  • A strong understanding of AWS GovCloud networking and security is essential, particularly experience with FIPS-compliant endpoints, FedRAMP-aligned architectures, and GovCloud-specific networking constraints. The engineer will configure Interface and Gateway VPC Endpoints to provide secure access to AWS services, validate FIPS endpoint configurations, and ensure compliance with government security requirements.
  • The position also requires advanced DNS expertise, including Amazon Route 53, private hosted zones, resolver rules, conditional forwarding, split-horizon DNS, and private DNS architectures. The engineer will be responsible for implementing and troubleshooting DNS resolution across multiple AWS accounts and hybrid environments.
  • From a monitoring and security perspective, the candidate will configure VPC Flow Logs and integrate network telemetry with centralized logging and SIEM platforms such as AWS Security Lake, Splunk, and Cribl. Experience with network traffic analysis, troubleshooting connectivity issues, and validating end-to-end traffic flows across AWS environments is critical.
  • The ideal candidate will have strong experience with Infrastructure as Code (IaC), particularly Terraform, for provisioning and managing AWS network resources. Expertise in routing protocols, especially BGP, inter-network routing, hybrid connectivity, and enterprise networking principles is required. Experience integrating AWS Identity Center with Microsoft Entra GCC High federation and enabling secure cross-platform authentication is highly desirable.
  • Candidates should possess at least 8 years of network engineering experience, including 5+ years focused on AWS networking technologies. Deep expertise in AWS VPC, Transit Gateway, AWS Network Firewall, Route 53, VPC Endpoints, Terraform, DNS architecture, and network security is required. Experience with AWS GovCloud, FedRAMP compliance, VPC Flow Logs, SIEM integrations, and hybrid networking solutions involving Cisco or Palo Alto technologies is highly preferred.

Skills

Microservices
AWS
Splunk
DNS
Kafka
Kubernetes
Redis
Terraform

Similar jobs