Source description
About the role
Platform Architecture (40%)
Design and implement secure, scalable AWS network architectures (VPCs, subnets, routing, multi-tenant isolation)
Architect hybrid connectivity solutions using Direct Connect, VPNs, Transit Gateways
Design and implement firewall strategies: Network ACLs, Security Groups, AWS Network Firewall, and WAF rules aligned with security best practices
Advanced understanding of NACLs, Security Groups, WAF, and AWS Network Firewall
Implement Route 53, DHCP, AWS PrivateLink , and DNS/IPAM solutions
Design high-availability and disaster recovery network architectures
Create and maintain network architecture diagrams and SOPs
Collaborate with Infosec team to design network architectures that align with threat models and security controls
Participate in security incident response involving network systems
Infrastructure Automation (40%)
Develop and maintain Terraform modules for AWS infrastructure with security guardrails embedded (e.g., encryption at rest/transit, least-privilege IAM policies, NACLs, Security Groups)
Partner with Infosec to establish and enforce Terraform coding standards and security controls
Build environment aware Terraform modules for reusability
Implement GitOps workflows and promote infrastructure changes across dev/staging/prod
Automate firewall rule provisioning and updates; implement drift detection for security controls
Automate operational tasks using Python and shell scripting
Manage backup and recovery procedures
Implement CI/CD integration for infrastructure deployments
Operations & Observability (20%)
Audit, maintain, and troubleshoot firewall rules and security controls (NACLs, Security Groups, Network Firewall, WAF) including rule optimization, change management, incident response, and compliance reviews
Design and implement monitoring/alerting using DataDog , Prometheus and AWS CloudWatch
Analyze VPC Flow Logs and AWS networking metrics for performance optimization
Lead troubleshooting of complex network and platform issues
Participate in on-call rotation
Maintain runbooks and operational documentation
More at Smarsh
