job summary:
onsite Omaha, Nebraska
Position Overview
We are seeking a Senior Azure Government Cloud Network Engineer to design, automate, and maintain a high-performance, software-defined network that powers our zero-trust, shift-left deployment model. In this role, you will be the architectural anchor for our autonomous microservices platform. You will engineer fully automated, immutable networks across all lifecycle stages to completely eliminate environmental configuration drift and guarantee absolute environment parity.
Operating within a multi-location Scaled Agile framework, you will build automated infrastructure gates, integrate service virtualization, and implement expert-level routing frameworks. You will leverage VWAN with Routing Intent, Secured Hubs, Forced Tunneling, and advanced BGP configurations to support dark launching, dynamic feature flagging via Azure App Configuration, and multi-tiered automated performance testing.
location: Omaha, Nebraska
job type: Contract
salary: $65 - 70 per hour
work hours: 9am to 5pm
education: Bachelors
responsibilities:
Core Responsibilities
1. Expert-Level Enterprise Routing & Traffic Engineering
- Advanced VWAN Orchestration: Design and manage global Azure Virtual WAN (VWAN) architectures utilizing Secured Virtual Hubs integrated with security partners or Azure Firewall to centrally govern all cloud-native traffic.
- Deterministic Routing Intent: Implement Routing Intent and Routing Policies within VWAN to systematically direct all private and internet-bound traffic (Internet and Private Traffic categories) through security appliances without complex manual programming.
- Dynamic Hybrid BGP Optimization: Engineer resilient, multi-site Azure ExpressRoute data paths using advanced Border Gateway Protocol (BGP) communities, multi-exit discriminators (MED), and AS-path prepending to enforce predictable failover paths for distributed federal sites.
- Forced Tunneling & Symmetric Routing: Author rigorous User-Defined Routes (UDRs) and BGP policies to mandate Forced Tunneling, ensuring all branch, cloud, and edge-bound traffic is backhauled to specific inspection boundaries without causing asymmetric routing drops.
2. Immutable Infrastructure as Code (IaC) & Automation
- 100% Code-Driven Architecture: Define, provision, and lifecycle all complex routing fabrics-including BGP peering, VWAN configurations, Hub policies, and UDR matrices-strictly via modular, repeatable Terraform templates.
- State & Configuration Governance: Implement secure backend state management, drift detection mechanisms, and policy-as-code validations (e.g., Azure Policy, OPA/Rego) to prevent unauthorized, out-of-band manual network alterations.
- Automated Pipeline Gates: Embed network IaC directly into Azure DevOps CI/CD pipelines. Network deployments must automatically execute linting, static analysis security scans, and trigger immediate environment-specific compliance gates upon Git check-in.
3. Azure Government Cloud Compliance & Security
- Sovereign Cloud Isolation: Architect and maintain high-fidelity environments within Azure GovCloud, ensuring strict compliance with US federal security frameworks (e.g., FedRAMP High, DoD SRG Impact Level 4/5, CJIS).
- Zero-Trust Micro-segmentation: Enforce rigorous Network Security Groups (NSGs) and Application Security Groups (ASGs) at the IaC layer to isolate autonomous microservices by default, blocking automated defects and lateral threat movement at the packet level.
- High-Assurance Gateways: Manage high-assurance cryptographic gateways, cross-domain solutions, and dedicated ExpressRoute Gov circuits to securely connect distributed government enclaves and multi-location development sites.
4. Environment Parity & Distributed Scaled Agile Execution
- Eliminate Staging Drift: Manage identical software-defined networking layouts and routing boundaries across all pre-production and production tiers via automated nightly continuous deployment pipelines, preserving absolute multi-environment stability and parity.
- Decoupled Integration & DEV Isolation: Configure Azure Private DNS zones and localized routing mechanisms via IaC to support API Contract Testing and Service Virtualization, keeping early-stage testing entirely self-contained for distributed teams.
- Distributed Scaled Agile Collaboration: Partner closely with decentralized, multi-location engineering squads, Product Leads, Quality Leads, and App Leads across Agile release trains (ARTs) to map infrastructure requirements directly to ADO User Stories and maintain a 100% Requirements Traceability Matrix Depth.
- Performance-Ready Fabrics: Provision automated, high-throughput network segments to accommodate multi-tiered automated testing under heavy simulated traffic loads (Reliability, Scaling, Load, and extreme Stress/Chaos testing).
5. Traffic Management & Zero-Day Validation
- Dark Launch Infrastructure: Design quiet routing paths and backend network connections to allow microservices and data migrations to run silently "in the dark" on live production infrastructure.
- Targeted UI Routing: Configure Azure Application Gateway and Azure Front Door to support targeting filters, allowing distributed QA and Product Managers to securely test features using real production data while keeping them logically hidden from standard users.
- Centralized Configuration Access: Secure and optimize ultra-low-latency network pathways (via Azure Private Link) to across all geographic deployment regions.
- Instantaneous Failure Recovery: Optimize routing tables, global traffic managers, and DNS TTLs to support automated tracking mechanisms that trigger millisecond-level traffic routing rollbacks if telemetry spikes or memory leaks occur.
qualifications:
Required Technical Skills & Qualifications
Expert-Level Azure Routing Toolkit: Proven history deploying Azure Virtual WAN (VWAN) with Routing Intent, Secured Virtual Hubs, Forced Tunneling, and complex User-Defined Routes (UDRs).
Advanced BGP & Hybrid Connectivity: Mastery of Border Gateway Protocol (BGP) engineering over multi-circuit Azure ExpressRoute and VPN gateways in high-availability enterprise configurations.
Advanced Infrastructure as Code (IaC): Proven mastery of Terraform to build declarative, production-grade, and immutable multi-environment architectures.
Azure Government Cloud Expertise: Deep experience navigating the specific constraints, endpoint differences, and compliance parameters of Azure GovCloud.
Microservices & Container Networking: Strong understanding of service-to-service communication, ingress controllers, and overlay/underlay networking (e.g., Azure CNI) for autonomous microservices.
Scaled Agile Workflow Integration: Solid experience operating in distributed, multi-location environments utilizing frameworks like SAFe or Scrum-at-Scale, leveraging Azure DevOps (ADO) for linking infrastructure work items to application features.
Traffic & Packet Analytics: Proficiency using Azure Network Watcher, Traffic Analytics, and Azure Monitor to capture database lag, CPU/memory telemetry, and error behaviors under heavy simulated traffic loads.
[hr align="center" size="2" width="100%"]
Preferred Mindset & Culture Fit
Shift-Left Advocate: You believe that infrastructure validation belongs as early in the deployment lifecycle as possible and should be codified entirely.
TDD/BDD Aligned: While you may not write application code, you understand Git workflows (Draft PRs) and appreciate how automated network rules protect the stability required to trigger product readiness tests.
Zero-Bug Accountability: You maintain an exceptionally high bar for infrastructure deployment quality, targeting zero escaped architectural defects into subsequent environments.
skills:
Agile Execution,Agile Collaboration,Agile,API,automated testing,Azure DevOps CI,backend,BGP,Border Gateway Protocol,Government Cloud,Cloud,linting,continuous deployment,Analytics,database,CD pipelines,DNS,drift detection,Workflow Integration,Firewall,Git,Git workflows,Infrastructure as Code (IaC),latency,memory leaks,microservices,Azure,ADO,Microsoft Azure,Azure DevOps,network connections,Network deployments,Network Security,Micro-segmentation,production data,performance testing,policy-as-code,Requirements Traceability,Routing,software-defined networking,Scaled Agile framework,Scrum,service virtualization,Application Security,static analysis,Terraform,VPN,Zero-Trust,resilient,Accountability,Reliabi
![]()