Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobWe are seeking a Network Architect to design and govern enterprise network infrastructure across Azure, on-premises VMware environments, and multi-vendor security platforms, ensuring a scalable, secure, and automated foundation for hybrid connectivity and network operations.
Responsibilities
- Design the core network connectivity foundation — Azure VNets/subnets, Application Gateway, WAF, and Azure Firewall with NSGs and Route Tables — as the foundational layer that all other Azure automation modules depend on
- Architect the DNS and NetBox IPAM integration: internal zones/records, public authoritative DNS, and the prefix/role/tenant/site/VRF data model, reconciling existing on-premises and Azure network estate data into a single source of truth
- Design multi-vendor firewall automation architecture across PaloAlto, F5, and Cloudflare (security rules, address/service objects, NAT, VIP/pool configuration, WAF policy attachment, certificate binding), including commit/lock handling for concurrent pipeline execution
- Architect VMware NSX-T network segments (segments/T1 routers), distributed firewall (DFW) rules/groups/tags, and load balancing/NAT, ensuring addressing consistency with NetBox
- Define hybrid connectivity architecture for Azure VMware Solution (AVS)/ExpressRoute, ensuring consistent routing and security posture between on-premises, VMware, and Azure environments
- Contribute network-architecture input to next-phase capabilities identified in the roadmap, including global traffic management/multi-region patterns and additional infrastructure modules (SSE/ZTNA, BGP/routing)
- Partner with the Azure Architect, VMware Architect, and Integration Architect (Security Focus) to ensure network design aligns with identity, certificate, and secrets architecture
- Provide architectural governance for network and firewall change control, given the high blast-radius nature of these changes, and support production validation during Implementation and Adoption
Requirements
- 2+ years of enterprise network architecture experience across Azure networking (VNets, Application Gateway, WAF, Azure Firewall, NSGs) and network/security platforms (PaloAlto, F5)
- Experience automating network infrastructure via Infrastructure as Code (Terraform/OpenTofu), including complex modules for firewalls and application delivery controllers
- Understanding of DNS architecture (split-horizon, internal/public authoritative) and IP address management (IPAM) tooling such as NetBox
- Familiarity with VMware NSX-T network segmentation and distributed firewall policy modeling
- Experience designing hybrid on-premises-to-cloud connectivity, including ExpressRoute-based patterns
- Ability to operate within change-control processes for high-blast-radius network and security modifications
- Proficiency in English at a B2+ level
Nice to have
- Experience with Cloudflare for VIP/pool, WAF policy, and certificate-binding automation
- Familiarity with global traffic management/multi-region failover patterns (active/passive)
- Exposure to SSE/ZTNA architectures and BGP-based routing modules
- Experience integrating network provisioning with a self-service developer portal (Backstage or equivalent)
- Familiarity with certificate distribution (Venafi) tied to network and load-balancer endpoints
