CAN_Network Administrator
Varite View all jobs
- Toronto, ON
- Permanent
- Full-time
Design, implement, secure, and operate cloud networking (VPC/VNet, hybrid connectivity, routing, firewalls, private access, load balancing) with a strong focus on Infrastructure as Code (IaC) using Terraform.
Ensure high availability, compliance, observability, and cost efficiency across environments (Dev → Prod).Core Responsibilities:
1) Cloud Network Architecture & Design- Design VPC/VNet topologies: CIDR planning, subnets, route tables, NAT/IGW/ER/Direct Connect, DNS (public/private).
Define hybrid connectivity: Site-to-Site VPN, ExpressRoute/Direct Connect, Transit architectures, SD-WAN integration.
Architect resilient and secure network paths (multi-AZ/region, hub-and-spoke, segmentation/micro-segmentation).
Produce HLD/LLD, network diagrams, decision logs, and reference patterns aligned to enterprise standards.2) Implementation & Configuration (Azure / AWS)- Build and configure:
Azure: VNets, Subnets, NSGs, UDRs, Azure Firewall, Application Gateway/WAF, Private Endpoints, Route Server.
AWS: VPCs, Subnets, Route Tables, IGW/NAT, Security Groups/NACLs, ALB/NLB, Transit Gateway, PrivateLink.
(GCP as applicable: VPCs, firewall rules, Cloud Router, Cloud NAT, load balancing)
Implement DNS (Azure DNS/Route 53/Cloud DNS), IPAM hygiene, and name resolution across hybrid.3) Security & Compliance by Design- Enforce least privilege and network segmentation, zero-trust patterns, and WAF/DDoS protections.
Implement private access patterns (Private Link/Private Endpoints/Service Endpoints) to avoid public exposure.
Partner with security/GRC for threat modeling, control mapping, evidence collection, and remediation.4) Operations, Monitoring & Troubleshooting- Enable observability: VPC Flow Logs / NSG Flow Logs, Network Watcher, CloudWatch/CloudTrail, Log Analytics; build dashboards and alerts.
Troubleshoot latency, packet loss, asymmetric routing, MTU/Client, and TLS/WAF issues.
Participate in incident, problem, and change management with clear runbooks and post-incident reviews.5) Infrastructure as Code (Terraform-First)- Author and maintain Terraform modules for reusable network patterns (VPC/VNet, TGW, firewalls, private endpoints).
Implement environment promotion via workspaces or pipelines; parameterize with tfvars.
Enforce state management (remote backend, state locking), versioning, code reviews, and policy as code (Sentinel/OPA).
Integrate Terraform in CI/CD pipelines (Azure DevOps/GitHub Actions/GitLab/Jenkins) with plan/apply gates and approvals.Top 3 Required Skills:
1. Cloud Network Engineer
2. Terraform Knowledge
3. CI/CD pipelineSkills: Digital: Terraform~Google Cloud Network and ConnectivityExperience Required: 6-8 Years
Skills: Category Name Required Importance Experience
SkillCategoryTest1_MN Network Routing(WAN Technology) Yes 1 7+ years