About the Business Unit
At the core of everything Epsilon does is a team that builds and operates the foundation of our enterprise technology platforms. ETS drives innovation across Epsilon's infrastructure through cloud, automation, and AI, delivering scalable, secure, and reliable solutions that power revenue-generating platforms. The team provides end-to-end infrastructure services while defining the architectural direction for enterprise deployments across the organization.
As a Principal Cloud Network Engineer, you will define and drive Epsilon's enterprise cloud and hybrid network architecture across AWS, GCP, and Azure. You will establish scalable, secure, and resilient networking standards for multi-cloud environments while modernizing legacy networking using cloud-native services such as AWS Transit Gateway, VPC Lattice, Private Service Connect, Azure Virtual WAN, Route 53 Resolver, and cloud edge security services.
Working closely with Cloud Engineering, Security, Platform Engineering, and Application teams, you will define landing zone architectures, hybrid connectivity strategies, network observability, automation standards, and operational best practices. You will provide technical leadership for enterprise-wide networking initiatives, mentor engineering teams, and lead the resolution of complex production networking challenges.
Your work will directly improve platform reliability, security, scalability, operational efficiency, and developer productivity across Epsilon's global cloud platforms.
Responsibilities
Enterprise Cloud Network Architecture
- Define and evolve enterprise cloud network architecture across AWS, GCP, and Azure, including hub-and-spoke, mesh, and centralized egress models.
- Establish multi-account landing zone networking standards, including shared services, centralized inspection, and routing governance.
- Design secure private connectivity using AWS PrivateLink, VPC Lattice, GCP Private Service Connect, and Azure Private Link.
- Architect zero-trust networking and identity-aware connectivity aligned with enterprise security standards.
- Evaluate emerging cloud networking technologies and drive adoption aligned with business objectives.
Hybrid Connectivity & DNS
- Own hybrid connectivity architecture using AWS Direct Connect, Azure ExpressRoute, Cloud Interconnect, VPN, and resilient hybrid networking patterns.
- Define enterprise DNS architecture using Route 53, Cloud DNS, Azure Private DNS, Resolver endpoints, split-horizon DNS, and on-premises integration.
- Lead architecture reviews for complex routing, BGP, DNS, and cross-cloud connectivity.
Network Security
- Define standards for AWS WAF, AWS Shield, CloudFront, GCP Cloud Armor, Azure Front Door, Application Gateway WAF, and related edge security technologies.
- Design segmentation using Security Groups, Network ACLs, AWS Network Firewall, Azure Firewall, and GCP Firewall Policies.
- Partner with Security teams on DDoS protection, certificate lifecycle, logging, compliance, and threat detection.
Automation & Platform Engineering
- Define Infrastructure as Code standards using Terraform and CI/CD pipelines.
- Develop Python-based network automation and API-driven services for provisioning, validation, and operational workflows.
- Design self-service networking capabilities that improve consistency, scalability, and operational efficiency.
- Define network observability using Flow Logs, Reachability Analyzer, Cloud Monitoring, synthetic monitoring, SLOs, and operational metrics.
- Guide networking architecture for Kubernetes platforms including EKS, AKS, and GKE.
Technical Leadership
- Lead enterprise network modernization initiatives and establish technical direction.
- Mentor senior engineers and architects while driving engineering excellence.
- Lead incident response, root cause analysis, and continuous service improvements for critical networking issues.
- Own enterprise network documentation, architecture standards, and Well-Architected Reviews.
- Drive network cost optimization through FinOps best practices.
- Participate in on-call support for critical production incidents.
Required Qualifications
- 10+ years of network engineering or infrastructure experience, including 5+ years designing and operating cloud networking in large-scale production environments.
- Expert knowledge of TCP/IP, routing, switching, BGP, VPN, DNS, TLS, load balancing, and hybrid networking.
- Deep hands-on experience with AWS networking services including VPC, Transit Gateway, Direct Connect, Route 53, Resolver, PrivateLink, VPC Lattice, Network Firewall, WAF, and CloudFront.
- Strong experience with GCP networking including Private Service Connect, Cloud DNS, Cloud Armor, Shared VPC, and Azure networking including Virtual WAN, Private Link, Azure Firewall, and Application Gateway.
- Experience designing enterprise landing zones with centralized networking and governance.
- Strong Infrastructure as Code expertise using Terraform and version-controlled deployment pipelines.
- Strong Python programming skills for automation, orchestration, and API-based networking solutions.
- Experience implementing network observability, capacity planning, SLOs, and operational metrics.
- Strong troubleshooting skills across networking, DNS, routing, security, TLS, NAT, and application connectivity.
- Experience working within regulated environments using change management, least privilege, and audit-ready processes.
- Excellent communication, leadership, prioritization, and stakeholder management skills.
- Willingness to participate in an on-call rotation.
Preferred Qualifications
- AWS Advanced Networking Specialty, GCP Professional Cloud Network Engineer, Azure Network Engineer Associate, or equivalent certifications.
- Experience implementing Zero Trust Network Access (ZTNA), SASE, or Identity-Aware Proxy architectures.
- Deep experience with Kubernetes networking, service mesh, and container networking across EKS, GKE, and AKS.
- Experience building enterprise network automation platforms, APIs, and self-service networking capabilities using Python and additional scripting languages such as Bash or Go.
- Experience leading enterprise network transformation initiatives, including data center migrations, cloud modernization, or landing zone implementations.
- Background in SRE, NOC, or incident command for large-scale production environments.
- Experience contributing to enterprise standards, architecture governance, and engineering best practices.
- Familiarity with AI/ML infrastructure networking, including high-performance GPU and low-latency networking environments.