Senior Network Cloud Engineer
About Us
At our organization, everyone is a caregiver - regardless of their title or responsibilities. Exceptional patient care, academic excellence, and leading-edge research make our premier health system a place where we can help you build the career you deserve. We are a dedicated team working together as one health system in a relentless pursuit of healing for our patients, community, and each other. Everyone, in their own unique way, plays an important part every day.
Position Summary
The Senior Network Cloud Engineer is responsible for designing, implementing, and managing secure, scalable, and reliable network infrastructures across cloud and hybrid environments. This role ensures optimal connectivity, high availability, and performance while aligning with enterprise architectural and security standards. The engineer will partner closely with service teams, Cloud Architects, and Security to support solution design, operations, troubleshooting, and continuous improvement of network services.
Major Responsibilities
- Cloud & Hybrid Network Architecture: Designs, implements, and maintains cloud network architectures including VPCs, VNets, subnets, routing, peering, endpoints, gateways, and load balancers. Configures and supports secure connectivity between on-premises datacenters and cloud environments. Ensures network reliability and performance through monitoring of traffic flows, latency, and throughput; proactively identifies and resolves bottlenecks.
- Operations, Troubleshooting & Incident Response: Performs troubleshooting and incident response for network-related issues, collaborating with service providers. Maintains network health and compliance. Runs compliance and audit reports as required.
- Collaboration & Communication: Partners with Cloud Architects and Security teams. Communicates service health, risks, and performance challenges to service owners and customers.
- Documentation & Automation: Creates and maintains network topology diagrams, firewall rulebooks, and runbooks. Automates network resource provisioning using Terraform and ARM templates. Maintains accurate network documentation and compliance records.
Required Qualifications
- Bachelor's degree in Computer Science, Engineering, Information Technology, or a related field
- Minimum of 5 years of cloud environment experience
- Experience designing and operating Azure VNets, routing, peering, and DNS
- Strong proficiency with Azure VPN Gateway, IPSec/IKE, TLS, and BGP
- Experience with ExpressRoute, Azure Load Balancer, Application Gateway, Front Door, Traffic Manager, Azure Monitor, Log Analytics, and Network Watcher
- Strong communication skills
Preferred Qualifications
- Certifications: Azure Administrator Associate (AZ-104), Azure Network Engineer Associate (AZ-700), or additional Microsoft Certifications including: Azure Solutions Architect Expert, Cybersecurity Architect Expert, DevOps Engineer Expert, Azure Security Engineer Associate, Azure Support Engineer for Connectivity Specialty, Identity and Access Administrator Associate, Windows Server Hybrid Administrator Associate, Security Operations Analyst Associate, Azure Stack Hub Operator Associate, or Azure Virtual Desktop Specialty
- Cloud Networking Expertise: Advanced proficiency in Azure VNets, routing, gateways, and hybrid connectivity; strong understanding of VPN and ExpressRoute
- Network Protocols & Security: Deep knowledge of TCP/IP, DNS, VPN, IPSec/IKE, TLS, BGP; ability to implement and troubleshoot security controls and encryption
- Performance & Reliability Engineering: Skilled in troubleshooting latency, throughput, and traffic flow; designs scalable and resilient network architectures
- Automation & IaC: Proficiency with Terraform, ARM templates, and automation of network resources
- Additional Microsoft Ecosystem Skills: Expertise with Azure Firewall, Azure Firewall Manager, Azure DDoS Protection, and Azure Web Application Firewall (WAF); experience with Azure Virtual WAN and Secure Hub; proficiency in Azure Private Link, Private Endpoints, and Zero Trust segmentation; strong understanding of Azure DNS Private Resolver and hybrid DNS designs; advanced use of Azure Monitor, Log Analytics, and KQL for network observability; experience with Microsoft Defender for Cloud and Microsoft Sentinel; automation with Azure PowerShell, Azure CLI, Bicep, and GitHub Actions; knowledge of Azure Stack HCI, Azure Arc-enabled networking, and hybrid integration
- Analytical & Problem-Solving Skills: Strong diagnostic reasoning and troubleshooting proficiency
- Collaboration & Communication: Effective communication with stakeholders across technical and non-technical teams
- Customer & Service Orientation: Strong service-delivery mindset with proactive communication
- Adaptability & Continuous Learning: Stays current with Azure networking and cloud architecture best practices
Pay & Schedule
- Location: Worcester, MA (Hybrid – onsite 1-2 days per week)
- Time Type: Full Time, Exempt
- Schedule: Monday through Friday, 8:00 AM – 4:30 PM, 40 hours per week
- Hiring Range: $87,276.80 – $157,081.60 (final offer may vary based on experience, skills, qualifications, and internal equity)
- This position may have a signing bonus available; eligibility will be confirmed during the interview process