Senior Cloud Network Engineer

KinectiveGolden, CO
Remote

About The Position

Kinective is seeking a Senior Cloud Network Engineer to own and evolve the networking backbone that powers its products and connects to its customers. This is a product-facing role where the engineer will design, build, and operate cloud and customer-facing network infrastructure that directly impacts product reliability, security posture, and compliance standing. The role primarily involves working across AWS with supporting Azure environments, managing VPN tunnel infrastructure for client connectivity, and actively participating in SOC 2 and PCI DSS audit readiness and evidence collection. The ideal candidate thinks in systems, communicates clearly across engineering, security, and customer teams, and takes ownership end-to-end. All network infrastructure changes are delivered as code, with no click-ops in production.

Requirements

  • Bachelor’s degree in computer science, software engineering, or a related field, or equivalent practical experience.
  • 5+ years of hands-on network engineering experience in cloud-native or hybrid environments.
  • Deep expertise with AWS networking (VPC, Transit Gateway, Route 53, Security Groups, NACLs, Network Firewall).
  • Cloud security & connectivity — hands-on with AWS IAM (roles, policies, identity federation), SSM (Systems Manager, Session Manager, Parameter Store), GuardDuty, and Security Hub.
  • Working knowledge of Azure networking (VNet, Azure Firewall, NSGs).
  • Proven experience designing and operating IPsec/IKEv2 and SSL VPN tunnels with enterprise clients.
  • Solid understanding of BGP, OSPF, and routing policy in multi-cloud and hybrid contexts.
  • Hands-on experience with compliance programs — SOC 2 and/or PCI DSS — specifically network controls and audit evidence.
  • Experience authoring reusable OpenTofu or Terraform modules, not just consuming them.
  • Strong TCP/IP fundamentals: subnetting, DNS, TLS, NAT, load balancing.
  • Hands-on packet-level troubleshooting — Wireshark, tcpdump, mtr, iperf, dig.
  • Proficiency with AWS CLI, Azure CLI, Python, Bash/PowerShell, and Docker for automation, tooling, and troubleshooting.
  • Strong written and verbal communication skills — comfortable running technical calls with customer network engineers.

Nice To Haves

  • Working understanding of modern AI tooling and hands-on experience with coding assistants (e.g., GitHub Copilot, Cursor, Claude, ChatGPT) to accelerate module authoring, troubleshooting, and documentation.
  • Experience with network observability tooling (e.g., VPC Flow Logs, Azure NSG Flow Logs, Datadog, Grafana, Dynatrace).
  • Familiarity with Nagios or similar network monitoring platforms.
  • Familiarity with zero trust network architecture (ZTNA) principles and implementation.
  • Familiarity with Cisco Meraki and IPS/IDS platforms.
  • DDoS protection and WAF experience — AWS Shield/WAF or Azure Front Door/WAF.
  • Hybrid DNS design across Route 53, Azure Private DNS, and on-prem resolvers.
  • Exposure to Kubernetes networking (CNI, ingress controllers, service mesh) in multi-cloud deployments.
  • Financial-services or regulated-industry background.
  • Relevant certifications: AWS Advanced Networking Specialty, Azure Network Engineer Associate, CCNP, or equivalent.
  • Experience working within a CI/CD-driven infrastructure model (Harness, GitHub Actions, or similar).

Responsibilities

  • Design and operate network architectures across AWS (primary) and Azure, including VPCs, VNets, and Transit Gateways.
  • Enforce strict network segmentation between production and non-production environments.
  • Manage routing, peering, and segmentation across multi-cloud environments to support product SLAs and security boundaries.
  • Maintain and optimize network performance, availability, and observability across cloud regions.
  • Collaborate with platform and infrastructure engineering teams to integrate networking into CI/CD pipelines and IaC workflows.
  • Design, provision, and maintain IPsec and SSL/TLS VPN tunnels connecting product environments to enterprise clients.
  • Own the full lifecycle of client tunnel onboarding — from technical scoping through cutover and steady-state support.
  • Serve as the primary technical point of contact during client network onboarding and connectivity incidents; lead customer-facing troubleshooting calls and produce written RCAs when client connectivity is impaired.
  • Troubleshoot and resolve tunnel stability, latency, and routing issues in coordination with client network teams.
  • Maintain documentation for all client connectivity configurations.
  • Support SOC 2 (Type II) and PCI DSS audit cycles — collecting network evidence, remediating findings, and responding to auditor requests.
  • Implement and enforce network controls aligned to SOC 2 Common Criteria and PCI DSS network segmentation and firewall requirements.
  • Conduct periodic firewall rule reviews, NACLs/security group audits, and access control assessments.
  • Collaborate with the security team on threat modeling, vulnerability remediation, and incident response for network-layer events.
  • Maintain network diagrams and data flow documentation required for compliance scoping.
  • Author and maintain reusable OpenTofu / Terraform modules for network infrastructure components.
  • Track work, changes, and incidents in JIRA; contribute to clear ticket hygiene and change-management workflows.
  • Build and maintain monitoring, alerting, and runbooks for network health across environments.
  • Participate in on-call rotation for network-layer incidents; lead post-incident reviews for network events.
  • Mentor junior engineers and contribute to architectural decisions and standards.

Benefits

  • Comprehensive health coverage (medical, dental, vision, prescriptions, life & disability)
  • Flexible PTO, 11 company holidays, and generous parental and caregiver leave
  • An immediately vested 401(k) with company contributions
  • Wellness resources and professional development opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service