About the role
sudocodelab_new is hiring a Senior Network Engineer to design, migrate and operate Google Cloud networking for a large enterprise environment. This is a hands-on engineering role: you will design VPC and connectivity architectures, execute migrations of live networking services, and troubleshoot end-to-end traffic paths that traverse Google Cloud constructs, third-party firewall appliances and hybrid VPN links. You will produce HLDs/LLDs, IP addressing plans, traffic flow matrices and runbooks, and translate architecture into clear, actionable requirements for the client's firewall/security teams. The role requires ownership of Shared VPC designs, Private Service Connect, custom routing, load balancer cutovers and Cloud Armor migration patterns. You will work remotely with client stakeholders and security teams to plan and execute migrations with rollback positions, validate enforcement parity when WAF policies move between enforcement points, and support incident/problem management with packet-level and log-based root cause analysis.
Requirements
- 8+ years in network engineering, including 4+ years working on Google Cloud networking
- Deep, hands-on experience with Google Cloud networking constructs: VPCs, Shared VPC, custom routing, route priority, next-hop types and longest-prefix-match behavior
- Practical experience with Private Service Connect for Google APIs and published services, including DNS design and global vs subnet-scoped addressing
- Experience designing and executing Google Cloud networking migrations (project/folder re-parenting, static IP/forwarding rule relocation, load balancer cutovers, egress path changes, PSC adoption) with defined rollback plans
- Strong troubleshooting ability using VPC Flow Logs, Firewall Rules Logging, Connectivity Tests and Packet Mirroring for packet-level and log-based root cause analysis
- Experience with Cloud Load Balancing (internal and passthrough patterns), Cloud Armor policy mapping and migration, Cloud DNS (private zones, DNS peering/forwarding) and Cloud NAT behavior
- Ability to read and audit site-to-site IPsec VPN configurations (HA VPN gateways, tunnels, IKE, traffic selectors) and distinguish active tunnels from stale ones
- Working understanding of FortiGate and Palo Alto as GCP-hosted NVAs (DNAT/SNAT, appliance-as-next-hop, ILB fronting, HA patterns) and ability to specify precise NAT, route and rule requirements to the firewall team (administration not required)