About Business Unit:
At the core of all that Epsilon does is a team that sets the foundation of our IT infrastructure. The team drives innovation and efficiency through pioneering technology across Epsilon's platforms and business verticals. From being the first point of contact for infrastructure needs to final deployment, the team provides end-to-end solutions for our client-facing platforms. ETS supports all aspects of revenue-generating platforms for Epsilon and sets the architectural direction for our enterprise deployments. By adopting the newest technologies, such as Cloud, Automation, and Artificial Intelligence, the team is at the front of redefining our digital business and capturing new opportunities
.
As a Principal Cloud Network Engineer, you will define and drive Epsilon's enterprise cloud and hybrid network architecture across AWS, GCP, and Azure. You will set the technical direction for multi-account, multi-region connectivity—replacing legacy datacenter patterns with modern cloud-native equivalents such as Transit Gateway and VPC Lattice, Private Service Connect, Route 53 Resolver endpoints, cloud WAF/CDN edge controls, and zero-trust connectivity models at enterprise scal
e.
In this role, you partner with Cloud Engineering, Security, Platform, and Application leadership to establish network standards, landing zone designs, and operational models that support reliable connectivity for revenue-generating platforms in 24x7x365 environments. You develop and champion Python-based automation and API driven network services that give teams consistent, repeatable outcomes at scale. You lead resolution of the most complex hybrid and multi-cloud network issues, define observability and SLO frameworks for network services, and mentor senior engineers and architects on cloud networking guidelines. You delegate implementation work across the team while remaining hands-on on the highest-impact architecture and critical issue scenari
os.
Your work directly shapes uptime, security posture, cost efficiency, and developer velocity across internal and client-facing platforms—and establishes the network foundation for Epsilon's continued cloud and AI-enabled gro
wth.
This role is ideal for a principal-level practitioner who combines expert networking fundamentals with deep multi-cloud expertise, infrastructure-as-code field, Python-based automation, and a track record of building secure, observable, and automatable network platforms— including APIs that give the business consistent, repeatable outcomes—while developing ot
hers.
Click here to view how Epsilon transforms marketing with 1 View, 1 Vision and 1
Voice.
Responsib
ilities
Enterprise Network Archi
- tecture:Define and evolve Epsilon's enterprise cloud network architecture across AWS, GCP, and Azure—including hub-and-spoke, mesh, and centralized egress models (e.g., AWS Transit Gateway, GCP VPC Network Connectivity Center, Azure Virtu
- al WAN).Establish multi-account landing zone network standards (AWS Organizations, GCP folders/projects, Azure Management Groups)—including shared services connectivity, centralized inspection, and cross-environment routing
- policy.Design private service access patterns at scale: AWS VPC Lattice / PrivateLink, GCP Private Service Connect, Azure Private Link—enabling secure east-west and north-south traffic without exposing services to the public i
- nternet.Architect zero-trust network access (ZTA) and identity-aware connectivity patterns alongside traditional segmentation controls; align network design with enterprise security s
- trategy.Evaluate emerging cloud networking capabilities and drive adoption aligned to business outcomes, cost targets, and operational m
aturity.Hybrid Connectivity &a
- mp; DNS:Own hybrid connectivity strategy using Direct Connect, ExpressRoute, Cloud Interconnect, VPN, and modern overlay patterns; optimize for resilience, latency, throughput, and cost across production and DR top
- ologies.Define and govern enterprise DNS strategy in the cloud: Route 53 hosted zones and Resolver endpoints/rules, Private DNS, split-horizon resolution, forwarding to on-premises, and GCP Cloud DNS / Private DNS zones integrated with Private Service
- Connect.Lead design reviews for complex routing, BGP, and cross-cloud connectivity scenarios; resolve architectural conflicts between network, security, and application requi
rements.Edge Security & Segme
- ntation:Define standards for edge and application-layer security controls including AWS WAF, AWS Shield, CloudFront, GCP Cloud Armor, Azure Front Door / Application Gateway WAF, and integration with security tooling a
- nd SIEM.Establish network segmentation and micro-segmentation models using security groups, NACLs, cloud firewall policies (e.g., AWS Network Firewall, GCP Firewall Policies, Azure Firewall), and policy-as-code where app
- licable.Partner with Security on DDoS mitigation strategy, TLS/certificate lifecycle at scale, egress filtering, threat detection integration, and compliance requirements (segmentation, logging retention, audit rea
diness).Platform, Automation & Observ
- ability:Drive infrastructure-as-code standards (Terraform preferred) for repeatable, auditable network provisioning; govern CI/CD pipelines and change workflows for network modifications a
- t scale.Develop and support network automation in Python—building tooling, integrations, and services that expose APIs to the business for consistent, repeatable network outcomes (provisioning, validation, connectivity requests, and operational wor
- kflows).Design self-service and platform automation patterns that reduce manual toil, enforce standards, and scale network capabilities across engineering and produc
- t teams.Define network observability architecture—Flow Logs, VPC Reachability Analyzer, Cloud Monitoring, synthetic probes, and alerting frameworks tied to SLOs and error
- budgets.Champion automation, self-service network patterns, and operational maturity (ITIL-aligned change, incident, and problem management) across the network engineering f
- unction.Guide platform networking for container and Kubernetes workloads (EKS/GKE/AKS CNI, service mesh integration) and high-throughput data platform conne
ctivity.Qualif
icationsWhat you'll bring w
- ith you:10+ years of experience in network engineering or infrastructure roles, with 5+ years focused on cloud networking in large-scale production envir
- onments.Expert-level understanding of TCP/IP, routing, switching, BGP, VPN, DNS, TLS, and load balancing—applied across cloud, hybrid, and multi-cloud c
- ontexts.Deep hands-on experience designing and operating AWS networking (VPC, Transit Gateway, Direct Connect, Route 53 / Resolver, PrivateLink, VPC Lattice, Network Firewall, WAF, CloudFront) and comparable services in GCP an
- d Azure.Solid experience with GCP Private Service Connect, Cloud DNS, Cloud Armor, VPC peering/shared VPC and Azure Virtual WAN, Private Link, Application Gateway WAF, and Azure F
- irewall.Expert proficiency with infrastructure-as-code (Terraform preferred), version-controlled network change workflows, and policy-as-code for network security c
- ontrols.Strong Python development experience—building or supporting automation, integrations, and API driven services that deliver consistent, repeatable network outcomes for internal teams and business co
- nsumers.Experience defining network observability, SLOs, capacity planning, and operational metrics for highly available, multi-region s
- ervices.Demonstrated ability to lead technical initiatives, mentor senior engineers and peers, and delegate work while maintaining architecture quality and operational st
- andards.Ability to lead troubleshooting across all layers (DNS, TLS, routing, NAT, firewall policy, application) and communicate clearly to executive, technical, and operational p
- artners.Demonstrated success in regulated or security-sensitive environments with change management, least-privilege access, and audit-ready docume
- ntation.Self-directed with strong prioritization skills in high-volume, 24x7 operational c
- ontexts.Willingness to participate in after-hours on-call r
otation.Why you might stand out from other
- talent:Multi-cloud certifications (e.g., AWS Advanced Networking Specialty, GCP Professional Cloud Network Engineer, Azure Network Engineer Associate) or equivalent demonstrated expertise across all three major
- clouds.Experience architecting zero-trust network access (ZTA), SASE, or identity-aware proxy patterns at enterprise scale alongside traditional network c
- ontrols.Deep experience with service mesh, container networking (EKS/GKE/AKS CNI), or platform networking for Kubernetes and microservices a
- t scale.Track record building network automation platforms and APIs—self-service connectivity, validation tooling, or workflow services used by multiple engineering and busines
- s teams.Advanced automation skills beyond Python (Bash, Go, or similar) for network operations, drift detection, and continuous compliance val
- idation.Background in NOC, SRE, or incident command roles with demonstrated operational rigor under high-severity production
- events.Contributions to enterprise standards, training programs, or platform initiatives that materially improved reliability, security posture, or developer exp
- erience.Familiarity with AI/ML platform networking requirements—high-throughput, low-latency, or GPU cluster connectivity patterns in cloud envir
onments.