AWS Cloud Network Specialist, AVP
State Street
- Location
- Hyderabad
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- Posted
- 15h ago
Skills
About this role
Position
Overview We are seeking a highly skilled AWS Cloud Network Specialist to design, implement, and operate enterprise-grade cloud networking solutions on Amazon Web Services. This role sits at the intersection of network engineering, cloud architecture, and DevOps, requiring deep hands-on expertise across the full AWS networking stack, from core VPC constructs through global WAN fabrics, DNS, security, and observability. The ideal candidate holds multiple AWS certifications and brings a strong architectural mindset, the ability to work across multi-account environments, and a bias toward automation and infrastructure-as-code. Required AWS Certifications Candidates must hold the AWS Advanced Networking Specialty certification. One or more of the following are strongly preferred: AWS SAP-C02 Solutions Architect Professional AWS DVA-C02 Developer Associate AWS SOA-C02 SysOps Administrator Associate AWS SAA-C03 Solutions Architect Associate AWS SCS-002 Security Specialist AWS Certified Advanced Networking Specialty (ANS-C01) is mandatory. Other certifications listed above are valued and may be substituted to demonstrate breadth where the specialty is being actively pursued.
Core Responsibilities
Network Architecture & Design Architect and deploy scalable, highly available VPC topologies including multi-tier subnet designs, transit hub-and-spoke models, and full mesh connectivity patterns. Design and manage AWS Transit Gateway deployments with route tables, attachments (VPC, VPN, Direct Connect, peering), and multi-region routing. Implement AWS Cloud WAN to build, manage, and monitor a unified global network across multiple AWS Regions and on-premises sites from a single policy-driven control plane. Maintain and evolve the AWS Network Manager dashboard to centralize visibility of global network topology, including Transit Gateway and Cloud WAN resources. Design hybrid connectivity solutions using AWS Direct Connect (dedicated and hosted connections, virtual interfaces, LAGs) and AWS Site-to-Site VPN with redundant tunnels. Plan and manage IP address space using AWS VPC IP Address Manager (IPAM) including pool hierarchies, scope definitions, automated CIDR allocation, and cross-account visibility. DNS & Service Discovery Manage Amazon Route 53 hosted zones (public and private), record sets, health checks, and traffic policies (latency, geolocation, weighted, failover, multivalue answer). Deploy and operate Route 53 Resolver inbound and outbound endpoints to enable DNS resolution across hybrid environments. Configure Route 53 Resolver DNS Firewall rule groups to block or allow DNS queries based on domain lists. Implement AWS Cloud Map for service discovery within containerized and microservices architectures. Security & Access Control Design and enforce network segmentation using security groups, network ACLs, and VPC endpoint policies. Manage VPC endpoints (Interface and Gateway types) and AWS PrivateLink service configurations to eliminate public internet exposure for AWS service traffic. Integrate networking controls with AWS IAM, AWS Organizations SCPs, and AWS Control Tower guardrails. Observability & Troubleshooting Enable and analyze VPC Flow Logs, Route 53 Resolver query logs, and Network Firewall alert logs using Amazon CloudWatch, Amazon S3, and Amazon Athena. Use AWS Reachability Analyzer and Network Access Analyzer to validate and audit network path connectivity and security posture. Leverage Transit Gateway Network Manager and CloudWatch Network Monitor for end-to-end WAN performance visibility. Troubleshoot complex connectivity issues spanning VPCs, Transit Gateways, Direct Connect, and on-premises networks. Automation & Infrastructure as Code Codify all network infrastructure using Terraform; contribute reusable modules to shared IaC libraries. Automate network operations tasks using Python