24 Sep
|
First American (India)
|
India
24 Sep
First American (India)
India
Job Title: Senior Platform Engineer II, Cloudflare & Cloud Networking (AWS or GCP)
About the Role
Design, deliver, and operate enterprise Cloudflare services integrated with AWS or Google Cloud Platform (GCP). Deep networking expertise in either AWS or GCP is required;
experience across both platforms is advantageous. You will own secure application onboarding from existing cloud infrastructure to Cloudflare for DNS, Web Application Firewall (WAF), load balancing, and Cloudflare Tunnel capabilities. The role requires strong Layer 3 networking, hands-on Cloudflare operations, infrastructure-as-code delivery using Terraform and Spacelift, systematic troubleshooting, and end-to-end ownership of resilient edge and cloud connectivity.
Key Responsibilities
Own and enhance the Cloudflare edge platform, including authoritative and proxied DNS, WAF, DDoS protection, load balancers, health monitors, traffic steering, TLS, and Cloudflare Tunnels.
Lead application onboarding and migration from AWS or GCP to Cloudflare, covering discovery, dependency mapping, traffic-flow design, origin readiness, DNS cutover, validation, rollback, and production stabilization.
Design and operate Layer 3 networking in at least one cloud platform: AWS networking such as VPCs, subnets, route tables, Transit Gateway, peering, NAT, endpoints, security groups, and network ACLs; or GCP networking such as VPCs, Shared VPC, peering, routes, Cloud Router, Cloud NAT, Private Google Access, firewall policies, and load balancers.
Design secure connectivity between Cloudflare and AWS or GCP origins using Cloudflare Tunnel and approved public or private origin patterns; enforce origin isolation, least-privilege access, segmentation, and controlled egress.
Develop DNS architecture across Cloudflare and Amazon Route 53 or Google Cloud DNS, including delegation, records, split-horizon DNS, resolver and forwarding paths, DNSSEC, proxy modes, TTL strategy, and controlled migration cutovers.
Configure and tune Cloudflare WAF managed and custom rules, rate limiting, bot controls, DDoS protections, TLS policies, certificates, and origin controls based on application risk.
Build highly available Cloudflare load-balancing designs using origin pools, health monitors, failover, session-affinity requirements, and geographic or latency-based traffic steering.
Troubleshoot Layer 3 through Layer 7 issues using Cloudflare analytics, packet captures, route analysis, DNS tools,
HTTP traces, TLS inspection, AWS VPC Flow Logs or GCP VPC Flow Logs, and origin or load-balancer logs.
Develop, publish, and maintain reusable Terraform modules for Cloudflare DNS, Tunnels, WAF, and Load Balancing in the central module registry, enabling consistent self-service adoption by application teams; manage module validation and deployment through Spacelift.
Enforce infrastructure-as-code-only changes and maintain consistent configurations across development, QA, UAT, and production environments through Git-based workflows and policy controls.
Implement monitoring and logging for Cloudflare and cloud network services, including Cloudflare Logpush and audit logs, AWS or GCP flow and DNS logs, load-balancer logs, alerting, dashboards, and SIEM integration.
Participate in incident response and problem management for availability, security, DNS, routing, connectivity, WAF, tunnel, and application-performance events; document root cause and preventive actions.
Partner with application, security, cloud platform, and network teams to define onboarding patterns, resolve dependencies, and deliver low-risk migrations with clear acceptance criteria.
Design for resilience, performance, capacity, and disaster recovery; regularly test health checks, failover behavior, routing, origin reachability, and rollback procedures.
Maintain architecture diagrams, network-flow documentation, DNS inventories, standards, operational runbooks, and change records; support CAB submissions for production changes.
Apply a robust product mindset and take end-to-end accountability for platform capabilities, stakeholder communication, adoption, operational health, and continuous improvement.
Key Requirements
8–10 years of experience in network, cloud, or platform engineering, including 3–5+ years of hands-on networking in either AWS or GCP and substantial production support experience.
Expert-level networking knowledge in at least one cloud platform: AWS VPC architecture, routing, Transit Gateway, endpoints, Route 53,
and load balancers; or GCP VPC and Shared VPC architecture, routing, Cloud Router, Cloud NAT, Cloud DNS, Private Google Access, firewall policies, and load balancers.
Hands-on Cloudflare experience with DNS, WAF, DDoS protection, load balancing, health monitoring, traffic steering, TLS, analytics, and Cloudflare Tunnels.
Proven experience onboarding or migrating internet-facing applications to Cloudflare with controlled DNS cutovers, origin integration, validation, rollback, and post-production support.
Strong understanding of TCP/IP, BGP fundamentals, DNS, HTTP/HTTPS, TLS, proxies, Anycast, subnetting, route selection, and Layer 3 through Layer 7 troubleshooting.
Experience securing AWS or GCP origins and network paths using least privilege, segmentation, controlled ingress and egress, encryption, certificate management, and defense-in-depth controls.
Advanced Terraform skills and hands-on experience with Spacelift or a comparable IaC orchestration platform, plus strong Git, module lifecycle, testing, and CI/CD practices.
Demonstrated ability to diagnose complex network and application-delivery issues using logs, metrics, traces, packet-level evidence, and systematic fault isolation.
Experience building operational monitoring, alerting, dashboards, audit trails, and SIEM integrations for Cloudflare and networking services in AWS or GCP.
Robust product mindset with end-to-end accountability for design, implementation, migration, production support, documentation, and continuous improvement.
Clear communication and proven collaboration across application, security, network, and platform engineering teams, including incident and stakeholder updates.
Nice to Have
Cloudflare certification, AWS Certified Advanced Networking – Specialty, Google Cloud Professional Cloud Network Engineer, or an equivalent certification.
Python, PowerShell, Rego, or Bash automation experience and familiarity with Cloudflare, AWS, or GCP APIs.
Experience with hybrid connectivity and centralized inspection using AWS Direct Connect, Google Cloud Interconnect, VPN, AWS Network Firewall, GCP firewall policies, Gateway Load Balancer, or Palo Alto.
Networking experience in the second cloud platform—AWS or GCP—for multi-cloud architecture and migration alignment.
Knowledge of AI-assisted engineering tools such as Claude and Cursor is a plus.
📌 Senior Platform Engineer II(Cloudflare & Cloud Networking) (India)
🏢 First American (India)
📍 India