Job Title: Cloud Network Engineer (contract)
Location: London Hybrid 2-3 days a week in the London office
Duration: 4 months
Contract Start Date: ASAP *please note that onboarding will take 4-6 weeks from the offer
Day Rate: Competitive (Inside IR35)
Deloitte
Working with the Deloitte Associate (Contractor) Programme means we can offer you the opportunity to work on a variation of industry and client related projects. Our aim is to retain the best talent and so when your project end date nears our team of Talent Community Advisors will be working with you to look at alternative projects within the firm that suit your experience should you wish to continue with Deloitte.
The Role
We are looking for a Cloud Network Engineer to help deliver secure, resilient and scalable network platforms across AWS, Google Cloud and on-premise environments. You will design and automate multi-cloud and hybrid connectivity, including routing, segmentation, DNS, load balancing, API gateways and private connectivity. Working to a 'you build it, you run it' model, you will own service reliability, monitoring, incident response and performance optimisation. You will collaborate across engineering and security teams, maintain clear technical documentation and support the development of junior engineers.
Deliverables: Responsibilities but not limited to:
- Multi-Cloud Network Architecture & Engineering: Design, implement, and manage advanced network architectures across AWS and GCP, including VPC/VNet design, subnetting, routing, IP addressing schemes, and network segmentation
- Hybrid Cloud Connectivity: Establish and maintain robust, high-performance, and secure connectivity between on-premise data centers and public cloud environments using technologies such as AWS Direct Connect, Google Cloud Interconnect, VPNs, and SD-WAN integration
- Network as Code (NaC) & IaC: Develop, maintain, and optimize cloud network infrastructure using Infrastructure as Code (IaC) tools such as Terraform, CloudFormation (AWS), and Deployment Manager (GCP). Create reusable modules and blueprints for standardized network deployments
- Advanced Network Services: Configure and manage critical network services including DNS (Route 53, Cloud DNS), Load Balancing (ALB, NLB, Cloud Load Balancing), API Gateways, and Content Delivery Networks (CDNs)
- Network Automation & Orchestration: Automate the provisioning, configuration, and management of cloud network resources and services. Develop scripts and tools (e.g., Python, Go, Bash) to streamline network operations, ensure consistency, and improve efficiency
- Site Reliability Engineering (SRE) for Networks: Embrace a "you build it, you run it" mindset for network services. Take ownership of the reliability, performance, and availability of the cloud network platforms. Implement robust network monitoring, alerting, and logging solutions, and participate in on-call rotations to ensure rapid incident response and resolution for network-related issues
- Network Security Implementation: Implement and enforce network security best practices, including network access control lists (NACLs), security groups, cloud firewalls (AWS WAF, GCP Firewall Rules), and network intrusion detection/prevention systems. Ensure compliance with policies, industry standards, and regulatory requirements
- Troubleshooting & Optimization: Perform advanced network troubleshooting and performance optimization across hybrid and multi-cloud environments
- Documentation & Knowledge Sharing: Create and maintain comprehensive documentation for cloud network architectures, configurations, and operational procedures. Mentor junior engineers and contribute to knowledge sharing within the team.
Essential Skills and Experience
- Cloud Engineering expertise - A deep understanding of public cloud services adoption at scale.
- Hands-on experience of AWS and Google Cloud networking across the following;
-
- Internet Application Hosting - Network Segmentation, Security controls, Network Firewall and Packet Mirroring & Inspection and Content Delivery Networks.
- B2B Connectivity - AWS & GCP Experience with Third party connectivity patterns, Cloud B2B Architectures and familiarity with VPN, AWS Privatelinks and Google Cloud Private Service Connect.
- Application Resiliency - DNS and DNS Routing, AWS Route53, Load Balancers, Google Cloud CloudDNS, High availability & Resiliency and API platforms
- Hybrid cloud connectivity solutions - using Direct Connect, Cloud Interconnect, VPN and SD-WAN,
- Networking concepts: TCP/IP, routing protocols (BGP), network segmentation, firewalls and network security principles.
- Network monitoring, logging, and alerting tools in a cloud context.
- Hands-on experience with Infrastructure as Code (IaC) and Network as Code (NaC)
- Programming and automation experience with Python and Go plus CI/CD tools such as Harness, Tekton or Jenkins.
- Automated testing experience using Terratest, Cucumber, Pytest-BDD, AWS Fault Injection Simulator or Chaos Mesh.
- Experience applying DevOps, agile and SRE practices to cloud networks, including monitoring, logging, alerting, incident response and performance optimisation.
- Strong communication skills with strategic thinking and adaptability
Desirable
- AWS Certified Advanced Networking - Specialty or Google Cloud Professional Cloud Network Engineer certification.
- Experience with network security tools such as WAF, DDoS protection, intrusion detection/prevention, SDN, Kubernetes networking, CNI or service mesh.
- Knowledge of financial services controls and frameworks such as PCI DSS, NIST or ISO 27001, plus network performance testing tools.
IR35
As a means of managing tax, commercial and reputational risks, Deloitte prohibits the use of Associates through Personal Service Companies (‘PSCs’). All Associates must contract under PAYE arrangements through a Deloitte approved ‘Employment Company’ (aka ‘umbrella company.’)