
Senior Multi-Cloud Network Engineer
American Express · Posted Oct 5
Banking, credit card, payment network, and travel services
Get a personal compatibility score
Add a resume for personal matches
About the role
Enterprise Cloud under Global Infrastructure is responsible for designing, building, securing, automating, and operating enterprise-scale cloud network fabrics across Amazon Web Services (AWS) and Google Cloud Platform (GCP). The role focuses on multi-account/multi-project architectures, hybrid and inter-cloud connectivity, routing, DNS, IP address management, segmentation, traffic inspection, and centralized security controls. This Senior Multi-Cloud Network Engineer will design secure-by-design, highly available, scalable, observable, automated, and resilient cloud networks, build them with Infrastructure as Code, and serve as a senior technical authority mentoring engineers and guiding architecture decisions.
What you will do
- Design and build enterprise-grade AWS and GCP network fabrics from the ground up.
- Design networking based on sound engineering principles rather than simply connecting cloud resources.
- Explain end-to-end packet flows across AWS, GCP, on-premises, and security infrastructure.
- Design scalable routing and segmentation models across hundreds of cloud accounts/projects and VPCs.
- Build highly resilient hybrid and multi-cloud connectivity architectures.
- Implement secure network boundaries without unnecessary operational complexity.
- Make informed decisions between native AWS, native GCP, and third-party networking capabilities.
- Automate network infrastructure, build comprehensive observability, and diagnose complex problems at both the architecture and packet level.
- Balance security, resiliency, scalability, performance, operability, and cost in architecture decisions.
- Design, build, and operate enterprise-scale cloud network fabrics across AWS and GCP.
- Develop architectures supporting multiple AWS accounts, GCP projects, business units, application environments, regions, and hybrid data centers.
- Define standardized multi-cloud connectivity patterns covering cloud-to-cloud, cloud-to-data-center, application-to-application, internet ingress/egress, east-west traffic, shared services, private service connectivity, and centralized traffic inspection.
- Design scalable routing, segmentation, IP addressing, DNS, and connectivity strategies across AWS and GCP.
- Develop multi-region architectures with appropriate availability, redundancy, failover, route convergence, and disaster recovery characteristics.
- Evaluate architecture trade-offs across cloud-native networking services based on security, scalability, performance, resiliency, operational complexity, and cost.
- Design and engineer AWS networking using Amazon VPC, Transit Gateway, Cloud WAN, Direct Connect, Site-to-Site VPN, Transit Gateway Connect, VPC Peering, PrivateLink/VPC Endpoints, Network Firewall, Firewall Manager, Route 53/Resolver, DNS Firewall, Elastic Load Balancing, Global Accelerator, VPC IPAM, and flow logs.
- Design network architectures for complex multi-account and multi-region AWS environments, including centralized and distributed connectivity and security models.
- Design and engineer GCP networking using Google Cloud VPC, Shared VPC, VPC Network Peering, Network Connectivity Center (NCC), Cloud Router, Cloud Interconnect, Partner Interconnect, HA VPN, Private Service Connect, Private Google Access, Cloud NAT, Cloud DNS, Cloud Load Balancing, Cloud Armor, Firewall Policies, Network Intelligence Center, and VPC Flow Logs.
- Design network architectures supporting multi-project, multi-region, and Shared VPC environments, with appropriate separation between host projects, service projects, shared services, security controls, and application workloads.
- Design highly available connectivity between AWS, GCP, enterprise data centers, colocation facilities, and third-party environments.
- Design and operate architectures utilizing AWS Direct Connect and Google Cloud Interconnect.
- Engineer resilient BGP-based routing across cloud and on-premises environments and VPN-based connectivity for primary, secondary, and contingency use cases.
- Develop secure connectivity patterns between AWS and GCP while avoiding unnecessary internet exposure.
- Understand and mitigate asymmetric routing, overlapping IP space, route propagation, route preference, MTU, NAT, DNS, and stateful security-device challenges.
- Develop routing strategies that prevent unintended transit paths and connectivity between security zones, with clear failure domains and predictable failover behavior.
- Design cloud network architectures using security-by-design and Zero Trust principles.
- Implement segmentation based on application, environment, business function, data classification, and trust boundaries.
- Design centralized and distributed firewall architectures and secure ingress, egress, east-west, and inter-cloud traffic patterns.
- Implement appropriate traffic inspection and security enforcement points; apply least-privilege connectivity and minimize unnecessary network reachability.
- Design private access patterns using AWS PrivateLink/VPC Endpoints, GCP Private Service Connect, and Private Google Access.
- Implement controls using AWS Security Groups, NACLs, Network Firewall; GCP VPC Firewall Rules/Policies, Cloud Armor; DNS security controls; and third-party NGFW technologies where appropriate.
- Partner with cybersecurity teams to translate security standards into enforceable cloud network controls.
- Identify excessive connectivity, unintended routing paths, insecure internet exposure, and weaknesses in segmentation or firewall policies.
- Incorporate logging, monitoring, detection, and auditability into network architecture from the outset.
- Demonstrate expert-level understanding of TCP/IP, IPv4/IPv6, BGP, DNS, NAT, CIDR/subnetting, route summarization, route propagation, route preference, ECMP, and stateful/stateless filtering.
- Develop enterprise-scale IP Address Management (IPAM) strategies spanning AWS, GCP, and on-premises environments.
- Prevent and remediate overlapping address-space issues across cloud environments.
- Design hybrid DNS architectures spanning AWS Route 53, GCP Cloud DNS, and enterprise DNS infrastructure.
- Understand provider-specific routing behavior and diagnose complex routing issues across cloud boundaries.
- Build and manage cloud networking using Infrastructure as Code (IaC) rather than manual configuration.
- Develop reusable networking modules and patterns using Terraform, AWS CloudFormation/CDK, Google Cloud Infrastructure Manager or equivalent tooling, Python, and Ansible.
- Integrate network infrastructure deployments into CI/CD pipelines and implement automated validation, testing, compliance, and policy enforcement.
- Develop guardrails to prevent insecure or non-standard network configurations.
- Promote repeatable, version-controlled, auditable deployments and automate routine network operations, configuration validation, route analysis, and compliance checks.
- Establish comprehensive network observability across AWS and GCP using VPC/TGW Flow Logs, CloudWatch, Reachability Analyzer, Network Manager, GCP VPC Flow Logs, Cloud Logging/Monitoring, Network Intelligence Center, and Connectivity Tests.
- Diagnose complex connectivity problems across cloud, hybrid, and inter-cloud environments.
- Perform end-to-end packet-flow analysis through routing, NAT, firewalls, load balancers, private endpoints, VPNs, and hybrid connectivity.
- Troubleshoot BGP advertisements, route propagation, asymmetric routing, DNS resolution, MTU issues, firewall policies, and application connectivity.
- Lead root-cause analysis for major cloud networking incidents and implement permanent corrective actions.
- Serve as a senior technical authority for cloud networking across AWS and GCP.
- Develop cloud network reference architectures, engineering standards, design patterns, and guardrails.
- Conduct architecture and design reviews for new cloud connectivity requirements.
- Provide technical guidance to application, platform, SRE, infrastructure, and cybersecurity teams.
- Challenge architecture proposals where network complexity, security exposure, scalability, or operational risk is unnecessary.
- Mentor engineers and translate complex networking concepts into clear architectural decisions for technical and non-technical stakeholders.
Skills used in this role
What the employer is looking for
- Significant professional experience (10-12+ YOE) in network engineering, including substantial hands-on experience with public cloud networking.
- Demonstrated experience designing and implementing enterprise-scale AWS and GCP network architectures.
- Deep practical knowledge (7-8+ YOE) of TCP/IP, BGP, DNS, NAT, routing, VPN, firewalls, load balancing, and network segmentation.
- Strong hands-on AWS experience (4-5+ YOE) with VPC, Transit Gateway, Direct Connect, PrivateLink, Route 53, VPN, and AWS Network Firewall.
- Strong hands-on GCP experience (4-5+ YOE) with VPC, Shared VPC, Network Connectivity Center, Cloud Router, Cloud Interconnect, HA VPN, Private Service Connect, Cloud DNS, and Firewall Policies.
- Experience designing hybrid connectivity between public cloud environments and enterprise data centers, and secure connectivity between cloud providers.
- Strong understanding of cloud network security architecture, segmentation, firewalling, traffic inspection, private connectivity, and secure ingress/egress patterns.
- Strong Infrastructure as Code experience (3-4+ YOE), preferably using Terraform, with CI/CD and automated deployment practices.
- Advanced troubleshooting skills with the ability to trace application traffic across multiple network and security layers.
- Ability to communicate complex cloud network architecture to engineers, architects, cybersecurity teams, and senior technology stakeholders.
Preferred qualifications
- Experience building large-scale AWS multi-account environments and GCP multi-project/Shared VPC environments.
- Experience with AWS Transit Gateway, AWS Cloud WAN, and GCP Network Connectivity Center at enterprise scale.
- Experience integrating AWS Direct Connect and Google Cloud Interconnect with enterprise WAN environments.
- Experience designing multi-cloud connectivity using SD-WAN or cloud networking platforms.
- Experience with Palo Alto Networks, Fortinet, Cisco, Check Point, Aviatrix, o...
Benefits and support
- Compensation and benefits are detailed in the job posting
About American Express
American Express Company is a globally recognized multinational financial services corporation specializing in payment cards, travel-related services, and network banking. Founded in 1850, the company provides charge and credit cards, expense management products, and merchant services to consumers, small businesses, and large corporations worldwide. It operates a proprietary payments network known for its premium customer engagement and lifestyle rewards programs.
- Industry
- Banking
- Company size
- 76800 employees
- Founded
- 1850-03-18
- Location
- New York City, New York, USA
- Funding stage
- Public Company
Leadership
Chairman and Chief Executive Officer
Chief Financial Officer
Chief Information Officer and Executive Vice President
Chief Colleague Experience Officer
Chief Marketing Officer
Recent coverage
Business Travel Executive
American Express Launches 'Next Generation' of Amex Corporate2026-10-01
American Express IR
American Express Declares Regular Quarterly Dividend on Common Shares2026-09-28
American Express IR
American Express Reports Second-Quarter 2026 Financial Results2026-07-24