JustJoin.IT Praca zdalna Senior

Senior NetDevOps Engineer

Vecten

⚲ Warszawa

35 000 - 50 000 PLN netto (B2B)

Wymagania

  • Security
  • CI/CD
  • AWS CloudWAN
  • Terraform
  • Palo Alto
  • AWS VPC
  • Networking

Opis stanowiska

Senior NetDevOps Engineer

Full-time B2B | Remote EU / Poland | Financial Services Context

We are an AI-native data and technology partner for private capital and healthcare. Founded in 2010 and headquartered in Warsaw, we work with leading PE firms, VC funds, and healthcare organizations to build proprietary data infrastructure, deploy AI solutions, and drive AI-native transformation.
Our clients manage a cumulative $1.2T+ in assets. Our average engagement runs five years. Our NPS sits above 80. We don't need to claim credibility - we can show it.
We've also done to ourselves what we now do for clients. We've restructured our own company around AI - tools, policies, roles, delivery models. This isn't a pitch. It's a playbook we've already run, and we're hiring the engineers who will run it for others.

The Opportunity
A leading global alternative asset management firm is looking for a Senior NetOps Engineer to own cloud networking at scale — across ~413 AWS accounts, ~4,000 VPCs, and multiple regions. This is a hands-on role sitting at the boundary between Platform Engineering and Networking: the person who translates network requirements into infrastructure code, drives active migration programmes, and builds the reusable patterns that every engineering team provisions their networks against.
The environment is AWS-first with no on-premises data centres. You'll work directly with AWS CloudWAN (an active TGW → CloudWAN migration is in flight), AWS Network Firewall alongside Palo Alto NGFW via Gateway Load Balancers, and a centralized firewall programme replacing the legacy NACL model. 
You won't be designing networks in Visio. You'll be writing Terraform — and deriving firewall rules from VPC Flow Log analysis.

What You'll Own
• Drive the active Transit Gateway → AWS CloudWAN migration — ~10 Cloud WAN segments, tag-based segmentation, phased TGW decommission; this is already in flight and needs an engineer who can own it to completion
• Lead the centralized firewall programme replacing the NACL model — policing cross-account traffic, analysing VPC Flow Logs in S3 to derive firewall rules, and managing the change control process at scale
• Operate and evolve a hybrid firewall architecture: AWS Network Firewall for east-west traffic + Palo Alto NGFWs via Gateway Load Balancers; understand the boundary between them
• Manage and extend Palo Alto Prisma SD-WAN — deployed at every site and in cloud, with tunnelless Cloud WAN attachment; you'll be inheriting a running deployment and improving it
• Build and maintain a Terraform module library for network provisioning (VPC layouts, routing, firewall policies, Cloud WAN policies) consumed across the org via GitHub / GitHub Enterprise
• Own IP address management via AWS IPAM at 400+ account scale; maintain hygiene, support account vending workflows
• Manage DNS infrastructure: Route 53 + inbound resolvers to Active Directory; participate in the migration toward public hosted zones + AWS-managed certificates
• Operate Direct Connect from NY (Virginia POP as failover), targeting four-nines availability; understand BGP, failover paths, and monitoring
• Act as the primary technical bridge between Platform Engineering and the Networking organization — translating routing requirements, security standards, and network architecture into IaC that both sides can operate and trust

AWS Networking
• Deep, hands-on experience with AWS VPC fundamentals: subnets, route tables, security groups, NAT/Internet gateways, Transit Gateway, PrivateLink


Production experience with AWS CloudWAN — core network policy documents, segments, tag-based routing, multi-region and multi-account topologies; ideally with involvement in a TGW → CloudWAN migration
• AWS Network Firewall — stateful and stateless rule groups, east-west inspection architectures, centralized policy management
• Palo Alto NGFW + Gateway Load Balancer — operating Palo Alto firewalls in a GWLB insertion model; understanding the operational boundary with AWS-native firewall services
• Palo Alto Prisma SD-WAN — site and cloud deployments, Cloud WAN tunnelless attachment mode; operational experience preferred over greenfield design
• Direct Connect — NY-based DX, BGP routing, failover design, monitoring for HA targets
• Route 53 — inbound resolvers, hybrid DNS with Active Directory, hosted zone management; exposure to migration from private to public hosted zones is a plus
• PrivateLink — SaaS vendor connectivity (e.g. GitLab Dedicated), endpoint management at scale
• AWS IPAM — IP address management across hundreds of accounts; allocation policies, pool hierarchy

Infrastructure as Code & Automation
• Strong Terraform at scale — module design, state management, workspace patterns, remote backends, versioning — via GitHub / GitHub Enterprise
• Experience building reusable, versioned Terraform modules consumed by multiple teams across a large account estate


Data-driven network automation: ability to query VPC Flow Logs in S3 — using Athena, Python/pandas, or equivalent — to analyse traffic patterns and translate findings into actionable firewall rule changes; this is where purely traditional network engineers fall short

• Familiarity with CI/CD pipelines for infrastructure: plan/apply automation, drift detection, policy-as-code (OPA, Sentinel, or AWS Config rules)

Cross-domain Fluency
• Comfortable working across DevOps and traditional Networking disciplines — pull request reviews and BGP routing discussions in the same week
• Experience with multi-account AWS environments (AWS Organizations, SCPs, Resource Access Manager) where networking crosses account and organizational unit boundaries
• Understanding of network security governance: least-privilege traffic control, traffic inspection architectures, audit logging (VPC Flow Logs, Firewall logs to CloudWatch/S3)
• Change management discipline — operating a centralized firewall programme means changes have blast radius; you treat rule changes with the same rigor as a prod deployment

Nice to Have
• AWS certifications: Advanced Networking Specialty or Solutions Architect Professional
• Experience with AWS Control Tower or Landing Zone Accelerator in the context of network account vending
• Exposure to ZScaler client access integration with AWS network architecture
• Familiarity with GitOps workflows for infrastructure — Atlantis, ArgoCD, or equivalent
• Background in financial services or regulated industries where network segmentation, audit trails, and change control are compliance requirements, not preferences
• Exposure to VPC Lattice (the client has evaluated it and may revisit — awareness of its maturity trajectory is useful)

Benefits

• Unrestricted AI Stack & Premium Gear: Fully paid licenses for Cursor, Claude Pro, etc.
• Total Autonomy (Remote-First): No filler meetings, no Jira bloat, no micromanagement. You own the workflow. We care about shipped systems in production, not logged hours.
• Direct Impact: You’ll work face-to-face with our CEO, CTO & VPs and VC/PE General Partners.
• Frontier Engineering Culture: Build alongside elite engineers who are shipping systems that drive real investment decisions. Backed by continuous growth and a strong knowledge-sharing culture (check our YouTube).

Sounds like a perfect place for you? Don’t hesitate to click apply and submit your application today!

🔍 Dekoder Ogłoszenia

🔴
own cloud networking at scale — across ~413 AWS accounts, ~4,000 VPCs, and multiple regions
Oczekuje się od Ciebie przejęcia pełnej odpowiedzialności za złożoną i rozległą infrastrukturę sieciową w chmurze, co może wiązać się z dużą presją i koniecznością szybkiego podejmowania decyzji.
🔴
This is a hands-on role sitting at the boundary between Platform Engineering and Networking
Rola wymaga łączenia kompetencji z obszaru inżynierii platformowej i sieciowej, co może oznaczać konieczność pracy nad zadaniami wykraczającymi poza tradycyjny zakres inżyniera sieciowego.
🔴
the person who translates network requirements into infrastructure code, drives active migration programmes, and builds the reusable patterns that every engineering team provisions their networks against
Oczekuje się od Ciebie nie tylko implementacji, ale także proaktywnego tworzenia standardów i narzędzi, które będą wykorzystywane przez inne zespoły, co może oznaczać dużą odpowiedzialność za procesy.
🔴
an active TGW → CloudWAN migration is in flight
Będziesz zaangażowany w duży i potencjalnie złożony proces migracji infrastruktury sieciowej, co może wiązać się z wyzwaniami i nieprzewidzianymi problemami.
🟡
We don't need to claim credibility - we can show it.
Firma podkreśla swoje osiągnięcia i stabilność, co sugeruje dojrzałe i dobrze ugruntowane procesy, ale może też oznaczać mniejszą elastyczność w porównaniu do młodszych startupów.