06 Aug
|
Hitachi Digital Services
|
Hyderabad
06 Aug
Hitachi Digital Services
Hyderabad
Role Overview
The Principal Cloud & WAN Network Engineer is a senior technical authority responsible for architecting, deploying, and operating enterprise-grade hybrid network infrastructure spanning multi-cloud environments (AWS, Azure, GCP) and on-premises WAN fabrics. Operating within the Business Enablement Foundation (BEF) and Centres of Excellence (COE), this role drives the end-to-end design of scalable, secure, and high-availability network platforms that support mission-critical workloads for thousands of global consumers.
The incumbent owns the complete lifecycle of cloud network designfrom Transit Gateway hub-and-spoke topologies and Gateway Load Balancer inspection chains to SD-WAN overlay fabrics, MPLS backbone optimization, and Zero Trust Network Access (ZTNA) integration. The role acts as the definitive escalation point for P1/P2 major incidents, provides architectural governance for change advisory boards, and mentors junior engineers across disciplines.
Key Responsibilities
1. Cloud Network Architecture & Design
Architect and own end-to-end AWS networking topologies: multi-region Transit Gateway meshes, AWS Network Firewall with centralized Suricata inspection via Gateway Load Balancer (GWLB), PrivateLink service endpoints, and VPC Lattice service networking.
Design AWS Direct Connect architectures using hosted and dedicated connections, LAG bonding, and MACsec encryption for private connectivity to on-premises sites; integrate with AWS Transit Gateway (TGW) route tables and association/propagation policies.
Architect hybrid DNS resolution strategies leveraging Route 53 Resolver, inbound/outbound endpoints, and forwarding rules integrated with corporate DNS (BIND/Infoblox) for seamless split-horizon resolution.
Design and govern AWS VPC segmentation strategies—CIDR planning, shared VPC models, IPAM (AWS VPC IPAM), and inter-VPC connectivity patterns (TGW, VPC Peering, AWS PrivateLink) aligned to zero-trust principles.
Lead Azure hybrid networking designs: Azure Virtual WAN (vWAN) hub deployment, ExpressRoute Global Reach, Azure Firewall Premium with IDPS and TLS inspection, Azure Private Link, Private DNS Zones, and Virtual Network Peering at scale.
Define and implement GCP network patterns: Shared VPC, Cloud Interconnect (Partner and Dedicated), Cloud Armor WAF policies, Private Service Connect, and Cloud NAT strategies for enterprise workloads.
2. On-Premises WAN & Campus Networking
Engineer and optimize enterprise WAN fabrics built on MPLS/SR-MPLS (Cisco IOS-XR, Juniper MX), BGP policy design including route reflectors, community tagging, and MED/local-pref optimization across multi-AS environments.
Architect and deploy SD-WAN overlays (Cisco SD-WAN / Viptela,
VMware VeloCloud, or Fortinet Secure SD-WAN): control-plane policies, app-aware routing, SLA-based path selection, and zero-touch provisioning (ZTP) for branch rollouts.
Design resilient site-to-site IPsec VPN architectures with IKEv2, crypto map policies, DMVPN Phase 3, and BGP over tunnels; integrate with AWS Site-to-Site VPN for hybrid failover paths alongside Direct Connect.
Manage BGP peering with upstream ISPs and cloud providers; implement advanced BGP features including route dampening, max-prefix limits, prefix filtering with prefix-lists/route-maps, and communities for traffic engineering.
Oversee QoS end-to-end: DSCP marking, queuing policies (LLQ, CBWFQ), traffic shaping, and policing from branch CPE through WAN cloud to data center—ensuring SLA adherence for real-time (voice/video) and mission-critical application traffic.
Lead physical and logical data center network design: spine-leaf fabrics (EVPN/VXLAN, Cisco ACI or Aruba CX), BGP underlay, overlay tenant segmentation, and east-west traffic control.
3. Network Security & Zero Trust
Design and enforce Zero Trust Network Access (ZTNA) architecture integrating identity-aware proxy, micro-segmentation (NSX-T / AWS Security Groups / Azure NSG), and continuous verification across cloud and WAN.
Architect centralized security inspection models: GWLB-based bump-in-the-wire for inline IDS/IPS (Suricata, Palo Alto VM-Series), East-West inspection within VPCs, and North-South traffic hairpinning via AWS Network Firewall.
Own firewall policy governance across Palo Alto Networks (Panorama-managed), Cisco ASA/FTD, Azure Firewall Premium, and cloud-native firewall solutions; define rule lifecycle management and automated compliance validation.
Implement DDoS protection strategies: AWS Shield Advanced with Route 53 health-check failover, Azure DDoS Protection Standard, cloud-native WAF rules (AWS WAF, Azure Front Door, Cloudflare), and on-premises scrubbing center integration.
Drive PKI/TLS inspection architecture for encrypted traffic visibility: SSL forward proxy configurations, certificate management (ACM, DigiCert, Venafi), and mutual TLS (mTLS) for service-to-service authentication.
4. Automation, Infrastructure-as-Code & Observability
Lead network automation initiatives using Python (Netmiko, NAPALM, Nornir), Ansible network modules,
and Terraform providers (AWS, AzureRM, Juniper) for repeatable, auditable infrastructure provisioning.
Define and maintain network IaC pipelines in Git: Terraform modules for VPC/VNet, TGW, Direct Connect associations, route table management, and security group lifecycle; enforce policy-as-code via OPA/Sentinel.
Architect and operate network observability platforms: VPC Flow Logs Kinesis Firehose OpenSearch, AWS Network Manager topology views, Azure Network Watcher, distributed packet capture, and synthetic monitoring (ThousandEyes, CloudWatch Synthetics).
Build IPAM/DDI automation: integrate AWS VPC IPAM, Infoblox NIOS API, and DNS-as-code workflows to eliminate manual IP management and enforce CIDR governance at scale.
Develop runbooks and ChatOps integrations for automated incident triage: network telemetry correlation, anomaly detection (CloudWatch Anomaly Detection, Azure Monitor), and PagerDuty/ServiceNow event-driven response.
5. Incident, Problem & Change Management
Act as the technical authority and primary escalation for P1/P2 network incidents spanning cloud and WAN; lead war-room bridge calls, drive structured RCA (5-Whys, fault-tree analysis), and ensure post-incident reviews produce permanent remediations.
Provide authoritative pre-change impact assessment for all CAB submissions touching network infrastructure; review blast-radius analysis, rollback procedures, and ECMP implications before change approval.
Drive Problem Management: own the network problem backlog, identify recurring failure patterns through trend analysis, and deliver permanent solutions aligned to ITIL v4 continual improvement practices.
Maintain network change documentation to enterprise standards: LLD (Low-Level Design), HLD (High-Level Design), runbooks, test plans, and as-built diagrams in Confluence/SharePoint.
6. Governance, Standards & Mentorship
Establish and maintain cloud network design standards, reference architectures, and guardrails—published as reusable Terraform modules, CloudFormation StackSets, and Bicep templates accessible to product teams.
Participate in architecture review boards and cloud CoE governance; provide network SME input on application onboarding, security exception review, and recent cloud service adoption.
Author and maintain technical documentation: system design specifications, functional requirements, operational runbooks, capacity planning models, and cost optimization reports.
Mentor and develop a team of network engineers; conduct design reviews, establish coding standards for automation, and drive skills uplift in cloud networking across the broader infrastructure organization.
📌 Principal Cloud & WAN Network Architect (Hyderabad)
🏢 Hitachi Digital Services
📍 Hyderabad