Responsibilities
- Shape the future of the enterprise hybrid cloud network by designing highly available Azure networking solutions that support business-critical services across Azure, GCP and on-premises environments
- Design next-level monitoring solutions using KQL, Azure Workbooks, Alerts and Azure Connection Monitor to proactively detect anomalies, monitor ExpressRoute connectivity and identify business-critical issues before they become incidents
- Modernize the network security architecture by analyzing and challenging existing designs, implementing Azure Firewall Premium capabilities, refining the Network Security Group strategy, enhancing micro segmentation, evolving the environment towards enterprise standards, improving scalability and reducing operational costs
- Drive the future of infrastructure automation by establishing Infrastructure as Prompt as a strategic capability within the platform
- Design and establish governance guardrails for the Azure networking platform that can evolve into Azure Policies, Blueprints and enterprise governance standards
- Develop innovative concepts that enable decentralized network management without compromising security
- Strengthen cyber resilience by developing disaster recovery strategies, challenging existing backup concepts, designing automated failover testing and recovery simulations, and ensuring the Azure network platform can be restored quickly and reliably after major incidents
- Build an intelligent security platform by integrating Microsoft Sentinel, Microsoft Defender and advanced network telemetry to automatically detect, investigate and respond to cyber threats before they impact the business
- Collaborate across infrastructure, cloud and security teams, sharing networking expertise, supporting cross-team troubleshooting, optimizing connectivity and routing between Azure, GCP and on-premises environments, and working closely with teams operating Sophos-based network infrastructure
- Translate complex technical concepts into clear architectural recommendations and decision papers that support strategic decision-making
- Explore future network security technologies, including Zero Trust Network Access (ZTNA) with Microsoft Entra Private Access and Global Secure Access, helping to continuously evolve the enterprise connectivity strategy
Requirements
- Deep expertise in Azure networking, including Azure Firewall, ExpressRoute, Virtual WAN, BGP, Private Link and enterprise Hub & Spoke architectures
- Experience with Microsoft Sentinel, Microsoft Defender, KQL, Azure Monitor and cloud observability, enabling the ability to build intelligent monitoring, automate threat detection and proactively respond to security incidents
- Passion for challenging existing architectures and evaluating emerging new technologies such as Infrastructure as Prompt, AI-assisted infrastructure management and intelligent network automation
- Passion for learning new technologies, sharing knowledge, simplifying complex networking topics for different audiences, and helping other engineering teams build secure and scalable solutions
Nice to Have
- Experience with Google Cloud networking
- Experience with Sophos Firewall
- Experience with enterprise on-premises networking
Work Arrangement
Hybrid — office
Additional Information
- Welcome days: comprehensive onboarding program
- Remote space: 500,00 € granted to set up home office space
- Anchor days: travel to office fully reimbursed including travelling costs or hotel expenses
- Personal development: supported through various in- and external trainings
- Employee referral program: successful recommendations rewarded with a bonus