Cloud Network Architect (338)

WSPMeridian, ID
4d

About The Position

WSP is one of the world’s leading professional services firms operating in over 50 countries and employs approximately 75,000 professionals, known as Visioneers. Together they pioneer solutions and deliver innovative projects in the transportation, infrastructure, environment, building, energy, water, and mining and metals sectors. Position Summary We’re seeking a hands-on Cloud Network Architect with strong DevOps automation capability to design, standardize, and deliver secure, scalable, and resilient Azure networking. This role blends network architecture authority with platform implementation discipline: you will define and govern network patterns and guardrails, and you will also build and operationalize them using Infrastructure-as-Code and CI/CD so they are repeatable, consumable, and reliable at scale. Your Impact Main Responsibilities Azure Network Architecture & Standards Define, document, and govern Azure networking reference architectures, standards, guardrails, and reusable patterns (segmentation, routing, DNS, private access, and network security). Provide architectural review and formal sign-off on Azure network designs, ensuring consistency, scalability, resiliency, and security alignment (including Zero Trust-aligned controls). Architect and maintain global connectivity patterns and cloud connectivity services that support enterprise and hybrid needs. Network-as-Code (IaC) & Platform Enablement Develop and maintain Infrastructure-as-Code for cloud network provisioning; champion reusable modules to make networking self-service and repeatable. Integrate network builds into CI/CD workflows (state management, drift detection, automated validation) to enforce consistent baselines. Implement automated baseline checks, compliance controls, configuration consistency, and telemetry pipelines for network services. Networking & Security Implementation Implement hub-spoke / Virtual WAN patterns across Azure regions; operationalize private connectivity (Private Endpoints, Private DNS zones, NSG/UDR patterns). Publish secure external endpoints (Azure Front Door) and implement internal/egress routing patterns (Azure Firewall). Troubleshoot complex cloud and hybrid network issues across. Operations & Reliability Implement monitoring/alerting/dashboards for network services (Azure Monitor/Log Analytics and security telemetry where applicable). Support incident response, runbooks, and change/release coordination for network/platform changes. Validate resiliency, DR, and continuity plans through hands-on testing; drive operational readiness and smooth transition into run-state. Continuous Improvement Improve delivery performance through standardization and automation; reduce lead time and increase reliability via repeatable patterns. Partner with Security, Identity, and Platform architecture leaders to evolve network guardrails that enable delivery while protecting platform integrity. Mentor engineers and influence roadmaps toward reusable, extensible network platform services.

Requirements

  • 5+ years of practical, hands-on network engineering and architecture experience.
  • Deep expertise in Microsoft Azure networking (segmentation, routing, DNS, private access, and network security).
  • Expert knowledge of BGP, OSPF, DNS, DHCP, SD‑WAN, VPN/IPSec, IPv4/IPv6, and enterprise-scale troubleshooting.
  • Strong proficiency with IaC workflows; ability to build automated network deployments and maintain consistent baselines.
  • Deep hands-on experience with DevOps automation and CI/CD best practices for infrastructure delivery.
  • Prior participation in architecture review or governance forums.
  • Strong written communication: you will author and review ADRs, architecture documents, and pattern guides.
  • Comfortable operating with senior autonomy and collaborating across globally distributed teams.
  • Excellent written and spoken English.
  • Ability to work independently with low-level supervision and in a global team distributed geographically.
  • Strong organization skills (set priorities, meets deadlines, multiple simultaneous projects) and excellent documentation skills.
  • Excellent analytical and diagnostic problem-solving skills with the ability of providing solutions to identified problems.
  • Demonstrated experience in understanding, designing, delivering, and demonstrating compliance with information security requirements.
  • Knowledge and experience in performing information security practices in the management and delivery of infrastructure and operations.
  • Bachelor’s degree or equivalent experience in Information Technology, Computer Science, Engineering, or a related field.

Nice To Haves

  • Multi-region Azure experience with data residency constraints.
  • Experience working with third-party vendor development teams.
  • FinOps exposure and cost-aware automation.
  • Advanced degrees or certifications are a plus but not required.

Responsibilities

  • Define, document, and govern Azure networking reference architectures, standards, guardrails, and reusable patterns (segmentation, routing, DNS, private access, and network security).
  • Provide architectural review and formal sign-off on Azure network designs, ensuring consistency, scalability, resiliency, and security alignment (including Zero Trust-aligned controls).
  • Architect and maintain global connectivity patterns and cloud connectivity services that support enterprise and hybrid needs.
  • Develop and maintain Infrastructure-as-Code for cloud network provisioning; champion reusable modules to make networking self-service and repeatable.
  • Integrate network builds into CI/CD workflows (state management, drift detection, automated validation) to enforce consistent baselines.
  • Implement automated baseline checks, compliance controls, configuration consistency, and telemetry pipelines for network services.
  • Implement hub-spoke / Virtual WAN patterns across Azure regions; operationalize private connectivity (Private Endpoints, Private DNS zones, NSG/UDR patterns).
  • Publish secure external endpoints (Azure Front Door) and implement internal/egress routing patterns (Azure Firewall).
  • Troubleshoot complex cloud and hybrid network issues across.
  • Implement monitoring/alerting/dashboards for network services (Azure Monitor/Log Analytics and security telemetry where applicable).
  • Support incident response, runbooks, and change/release coordination for network/platform changes.
  • Validate resiliency, DR, and continuity plans through hands-on testing; drive operational readiness and smooth transition into run-state.
  • Improve delivery performance through standardization and automation; reduce lead time and increase reliability via repeatable patterns.
  • Partner with Security, Identity, and Platform architecture leaders to evolve network guardrails that enable delivery while protecting platform integrity.
  • Mentor engineers and influence roadmaps toward reusable, extensible network platform services.

Benefits

  • WSP provides a comprehensive suite of benefits focused on a providing health and financial stability throughout the employee’s career. These benefits include coverage related to medical, dental, vision, disability, and life; retirement savings; paid sick leave; paid vacation (or other personal time); paid parental leave; and paid time off for purposes of bereavement, voting, and/or attendance at naturalization proceedings.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service