AWS Network Engineer
Key Responsibilities
Design and implement AWS network architectures, including Hub-and-Spoke, Shared Services, and Landing Zone models
Design, configure, and manage Amazon VPC environments, including CIDR allocation, subnetting, route tables, and network segmentation
Implement centralized routing and security using AWS Transit Gateway
Configure and manage VPC Peering, VPC Endpoints (PrivateLink), Internet Gateways, and NAT Gateways
Design and support hybrid connectivity solutions, including Site-to-Site VPN, Client VPN, and AWS Direct Connect
Automate AWS network infrastructure using Terraform modules and Infrastructure as Code (IaC) best practices
Design, deploy, and manage firewall solutions, including AWS Network Firewall, Security Groups, and Network ACLs
Configure and troubleshoot routing protocols such as BGP and static routing within AWS environments
Manage and support switching technologies, including VLANs, trunking, and Layer 2/Layer 3 switching
Troubleshoot complex network issues involving routing, switching, firewall policies, latency, and packet flow
Implement and manage AWS load balancing solutions, including ALB, NLB, and Gateway Load Balancer (GWLB)
Monitor and optimize network performance using VPC Flow Logs, CloudWatch, and other monitoring tools
Maintain up-to-date network diagrams, architecture documentation, and Terraform repositories
Architect and manage multi-account and multi-region AWS environments using AWS Organizations and Control Tower (good to have)
Technical Stack & Tools
Strong expertise in AWS Networking Architecture (must have)
Hands-on experience with Terraform for AWS network automation (must have)
In-depth knowledge of routing concepts and protocols (BGP, static routing) (must have)
Strong experience with switching technologies (VLANs, STP, Layer 2/Layer 3 switching)
Solid experience with firewalls and AWS network security controls
Deep understanding of TCP/IP, DNS, DHCP, subnetting, and network segmentation
Preferred Qualifications
AWS Certified Advanced Networking – Specialty (good to have)
Experience with AWS Landing Zone / Control Tower (good to have)
Knowledge of Zero Trust architecture and defense-in-depth security models
Familiarity with AWS networking and DevOps best practices (good to have)