Job Description
We are seeking a skilled
Senior Cloud Network Security Architect . In this role, you will own the end-to-end architecture, design, deployment, and day-to-day operational management of secure network Security infrastructure across Microsoft Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI), working closely with cloud, security, application, and operations teams to keep our clients environments connected, secure, and highly available.
You will lead the full lifecycle of network Security architecture — from designing hub-spoke topologies and secure connectivity patterns, through deploying and configuring the underlying infrastructure, to running day-to-day operations: patching, monitoring, incident response, and continuous improvement. Your responsibilities will span network Security architecture and design, connectivity and interconnects, security and access control, NVA and vulnerability management, monitoring and diagnostics, and backup and resilience across hybrid and multi-cloud environments.
You will define secure network Security reference architectures, lead deployment of new environments and connectivity solutions, and own daily operational responsibilities including change management, patch and vulnerability remediation, incident response, and performance/health monitoring. The role requires deep technical expertise, strong architectural judgment, and the ability to translate connectivity and security requirements into practical, scalable, and operationally sustainable network Security designs.
Responsibilities
- Architecture & Design: Define secure reference architectures for VNet/VPC/VCN environments, including hub-spoke topologies, subnetting strategy, IP/CIDR planning, route tables, and static/BGP-based dynamic and policy-based routing across Azure, GCP, and OCI. Architect secure connectivity patterns (VPN, peering, and interconnects), and lead network Security design reviews with actionable recommendations aligned with industry best practices.
- Deployment & Implementation: Deployment and configuration of network Securityenvironments, including Site-to-Site VPNs (IPSec/IKEv2) with redundant tunnels and BGP dynamic routing, dedicated interconnects (Azure ExpressRoute, GCP Interconnect, OCI FastConnect), VNet/VPC/VCN peering, Local Peering Gateways (LPG), Remote Peering Connections (RPC), and DRG v2 transit routing. Deploy and tune GCP Cloud Armor (WAF) and Cloud CDN, and stand-up Security Lists, NSGs, Network Security ACLs, and Internet/NAT/Service Gateways as part of new builds and migrations.
- Day-to-Day Operations & Management: Own daily operational management of the network Security environment: change management, patching and upgrades of Network Security Virtual Appliances (NVAs), vulnerability tracking and remediation, and coordination of patch windows and incident response. Maintain monthly operations reporting on policy changes, patches, and incidents, and act as the senior escalation point for operational issues across all managed platforms.
- Monitoring, Logging & Diagnostics: Configure and maintain monitoring integrations — Azure Monitor/App Insights, GCP Cloud Monitoring, OCI Monitoring Service — including metrics, dashboards, and alerting. Capture, store, and analyze VPC/VCN flow logs, and use diagnostic tooling such as OCI Network Security Path Analyzer to proactively identify and resolve complex, end-to-end connectivity issues.
- Backup, Resilience & Continuous Improvement: Design, deploy, and validate backup and restore procedures for NVAs, firewall policies, and network Security state. Own disaster recovery and cross-region DR networking design and continuously review architecture and operational processes to improve resilience, security posture, and efficiency.
- Governance & Reporting: Prepare and maintain architecture documentation, runbooks, and operational procedures. Provide regular network Security and security posture updates to internal stakeholders and clients, and ensure changes and deployments follow proper governance, risk, and change-control processes.
Qualifications
- Education: Bachelor's / college degree in Computer Science, Network Security Engineering, or a related field.
- Experience: At least 10 years of experience in cloud network Security engineering or architecture, including hands-on responsibility for designing, deploying, and operationally managing network Securityenvironments, with demonstrable depth across at least two of Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure (all three strongly preferred).
- Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:
- Microsoft Certified: Azure Network Security Engineer Associate
- Google Professional Cloud Network Security Engineer
- Oracle Cloud Infrastructure Network Security Professional
- Cisco CCNA/CCNP or equivalent vendor-neutral networking certification
- Azure Solutions Architect Expert, Google Professional Cloud Architect, or OCI Architect Professional
- Technical Skills: Hands-on experience with network Security technologies including virtual network/VPC/VCN design, dynamic and policy-based routing (BGP), VPN and dedicated interconnects, NSGs/security lists/ACLs, NVAs and next-gen firewalls, cloud-native monitoring and flow log analysis, and vulnerability management tools. Familiarity with integrating network Security and security controls across multi-cloud environments is preferred.
- Knowledge: Strong understanding of networking and cybersecurity principles including defense-in-depth, zero trust, least privilege, segmentation, redundancy, and incident response. Familiarity with frameworks and guidelines (e.g., CIS Benchmarks, NIST, ISO 27001) and general compliance/governance concepts. Knowledge of Qatar National Information Assurance (NIA) is a plus.