Azure Cloud Network Architect
Location: NYC, LA, Boston, DC or San Francisco – contract-to-hire, no third-party vendors.
About the role
The Network Infrastructure Cloud Architect is a senior-level position in the IT Department responsible for supporting the design and architecture of the firm’s data, wireless, video, and VOIP networks, as well as cloud and IaaS-based network connectivity. The primary focus is Microsoft Azure, with familiarity in AWS and GCP. This role ensures secure, operationally sound solutions across on-premises and cloud environments, encompassing physical and cloud-based designs, logical/secure designs, and monitoring to validate digital experience and business value in hybrid and multi-cloud deployments.
The architect will recommend emerging cloud and networking technologies, including software-defined networking, cloud-native services, and infrastructure as code practices. They will collaborate across IT teams to propose improvements in security, scalability, availability, supportability, and cost, leveraging cloud-native capabilities. The role also involves providing technical guidance on cloud migration strategy and project planning.
Responsibilities
- Contribute to the strategic design and architecture of the firm’s data network environment, including hybrid cloud connectivity and Azure virtual networking (VNets, ExpressRoute, Azure Virtual WAN).
- Design, deploy, and maintain network systems and components such as routers, switches, internet services, WAN services, wireless networks, VPNs, firewalls, video and VoIP infrastructure, security, cloud network gateways, and performance monitoring systems.
- Design and manage cloud network architectures in Azure, including hub-and-spoke topologies, network security groups, Azure Firewall, Private Link, and DNS integration, with awareness of equivalent services in AWS and GCP.
- Participate in physical build planning and design for new spaces, as well as cloud landing zone design and implementation. Scope, recommend, design, plan, oversee, and test inter-rack and station cabling for office, MDF, IDF, and datacenter builds, alongside cloud infrastructure provisioning using infrastructure as code tools (Terraform, Azure Resource Manager templates).
- Configure on-premises and cloud-based networks to ensure smooth and reliable operation for business objectives.
- Evaluate emerging cloud and networking technologies (Azure-native services, SD-WAN, SASE, zero trust architectures) and recommend hardware/software enhancements.
- Recommend performance standards, processes, policies, and procedures for on-premises and cloud network environments.
- Provide senior-level technical support for network elements, systems, and cloud networking services.
- Design and monitor network performance across on-premises and cloud environments using tools like Azure Monitor, Azure Network Watcher, and third-party observability platforms; troubleshoot issues as needed.
- Collaborate with executive management and department leaders to assess near- and long-term network capacity needs, including cloud resource planning and cost optimization.
- Create and maintain documentation for network architecture, configuration, cloud network topology diagrams, runbooks, and infrastructure as code repositories.
- Ensure knowledge transfer for new systems, including cloud-based services and hybrid connectivity solutions.
- Coordinate with other firm members for business continuity and disaster recovery programs, including cloud-based disaster recovery, geo-redundancy planning, and Azure Site Recovery configurations.
Requirements
- Bachelor’s Degree or equivalent experience.
- 7+ years of experience in the network field.
- Proven experience with network planning, installation, and management, including BGP, LAN, MAN, WAN, Optical Networking, Silverpeak SDWAN, F5 Load Balancers, iRules, F5 Global Traffic Manager, Infoblox/BloxOne, Illumio, Checkpoint firewalls, Checkpoint Identity Collector, VPN, DMZ, IDS/IPS, Zscaler Web Proxy, content filtering, NAC, Cisco Client, Ciena DWDM, 100 Gig optics, DNS Traffic Control, Cisco ACI & NXOS, SDN, network segmentation, Cisco Catalyst Center, Cisco CLI, ACL management, SNMP MIBs, Aruba wireless controllers and APs, SSL certificate management, DNS domain registration, Citrix Netscaler, VMware NSX, network taps, and Extrahop.
- Experience with Azure networking solutions, including Virtual Network Peering, VPN Gateway, and ExpressRoute to support SaaS and cloud-based initiatives.
- Familiarity with infrastructure as code (IaC) tools such as Ansible, Terraform, Azure Resource Manager, and Chef.
- Familiarity with EntraID, Active Directory, LDAP, PKI, SAML, OAUTH, and SSO.
- Experience with network monitoring and tools (OpenView, Spectrum, NetScout, Gigamon, APCON, NetMRI, MRTG, CACTI, Solarwinds, SmokePing, NetFlow, Tufin, Splunk, syslog).
- Proven experience with network capacity planning, security principles, and general network management best practices.
- Strong hands-on knowledge of LAN/WAN/MAN protocols and technologies, including Carrier Ethernet, T1, DS3, optical, DWDM, NTP, Spanning Tree, VLANs, 802.1q, VFR, LFA, SNMP v1-v3, OSPF, BGP, MPLS, VPLS, SIP, H.323, QoS, Multicast, Anycast, 802.1x, Radius, TACACS+, SSH, NAC, DHCP, DNS, F5 Wide-IP, VRRP, HSRP, GLBP, PBR, VPC, LACP, SGT, SGACL, SXP, VxLAN, OTP, LISP, SPAN, WCCP, PfR, IPSLA, iWAN, VPN, IPSec, WiFi 6, 6E, and 7.
- Strong working knowledge of Cisco routers and switches (Nexus 9K, 7K, 5K, 2K, 1K; Catalyst 9410, 9300; ISR-4451, 8300).
- Experience with fiber optic cabling, patching, cleaning, and troubleshooting.
- Strong hands-on knowledge of DNS record creation: A, CNAME, TXT, SRV, NS, and PTR.
- Experience with DNS SPF, DMARC, and DKIM records.
- Experience with racking, patching appliances and servers, power management, and monitoring (managed PDUs).
- Experience with console servers for out-of-band serial access.
- Experience with DevOps, automation, and scripting.
- Experience with data center, server room, and IDF design; station cabling layout design and implementation; UPS management and monitoring; and environmental monitoring systems.
Essential Capabilities
- Ability to maintain strict confidentiality of the firm’s internal and personnel affairs.
- Ability to influence at all levels of the organization.
- Self-starter who understands details within a broader context.
- Ability to work collaboratively in a team environment.
- Creativity and flexibility to respond quickly to shifting demands and opportunities; ability to work under tight deadlines and handle multiple tasks.
- Team-oriented with the ability to share information, goals, opportunities, successes, and failures.
- Strong organizational and planning skills for multiple related activities.
- Attention to detail with follow-up and follow-through.
- Ability to work effectively in a multi-office environment.
- Strong verbal and interpersonal skills.
- Strong analytical and problem-solving skills.
- Strong customer service and leadership skills.
- Strong project management skills.
Preferred Qualifications
- Certifications: CCNA, CCNP, CCDE, CCDA, CCSP.