Responsibilities
1. Azure Network Provisioning & Management
· Provision, configure, and manage core Azure networking components, including VNets, Subnets, VNet Peering, User Defined Routes (UDRs), and Azure Route Server.
· Implement and manage hub-and-spoke network topologies and Azure Virtual WAN (vWAN).
· Deploy and maintain Private Endpoints, Private Link, and Service Endpoints to secure access to Azure PaaS resources (Storage, SQL, App Services).
2. Hybrid Connectivity & Traffic Routing
· Implement and maintain hybrid cross-premises connectivity via Azure ExpressRoute, Site-to-Site (S2S) VPNs, and Point-to-Site (P2S) VPNs.
· Configure BGP routing, route tables, and express-route circuits to ensure high availability and low-latency interconnects.
· Deploy and optimize application delivery and load-balancing services using Azure Application Gateway (WAF), Azure Front Door, Azure Load Balancer (Public/Internal), and Traffic Manager.
3. Network Security & Infrastructure Protection
· Configure and maintain Network Security Groups (NSGs), Application Security Groups (ASGs), and Azure Firewall / Network Virtual Appliances (NVAs) (e.g., Palo Alto, Fortinet).
· Monitor and manage Azure DDoS Protection, Web Application Firewall (WAF) rules, and network micro-segmentation.
· Enforce network access control policies aligning with Zero-Trust principles.
4. Operations, Monitoring, & Infrastructure as Code (IaC)
· Deploy network infrastructure using IaC frameworks such as Terraform, Bicep, or ARM templates.
· Perform end-to-end network troubleshooting using Azure Network Watcher, Connection Monitor, NSG Flow Logs, Packet Capture, and Log Analytics.
· Manage DNS architecture in hybrid setups, including Azure Private DNS Zones, Private Resolver, and integration with on-premises Active Directory DNS.
Required Qualifications & Technical Skills
· Core Azure Networking: Hands-on experience configuring VNets, Subnets, Route Tables, VNet Peering, and Private Endpoints.
· Hybrid Connectivity: Deep knowledge of ExpressRoute, IPSec VPNs, BGP routing protocols, and NAT configurations.
· Network Security: Practical experience with Azure Firewall, NSGs/ASGs, Third-Party NVAs, and WAF configuration.
· DNS & Traffic Management: Strong understanding of DNS routing (Azure Private Resolver/Zones), Load Balancing (L4 vs. L7), and HTTP/HTTPS traffic flows.
· Automation: Proficiency in deploying network resources via Terraform or Bicep, along with Azure CLI or PowerShell scripting.
· Troubleshooting: Expertise with packet inspection tools (Wireshark), Azure Network Watcher, and IP routing diagnostic commands.