
Network Engineer
- London
- Permanent
- Full-time
- Design, manage, and evolve the network architecture across multi-account, multi-region AWS environments.
- Implement and support partner integrations through mTLS, IPSec, Privatelink.
- Support centralized network servicessuch as DNS &RADIUS.
- Maintain network security controls using Palo Alto Cloud NGFW (or AWS Network Firewall), Network ACLs, Security Groups.
- Implement and maintaininfrastructure codebase and CI/CD pipelines.
- Ensure robust monitoring and alerting using Prometheus, Grafana, CloudWatch, and other observability tools.
- Collaborate on production incident response, provide network level visibility and troubleshooting support
- Support the security, performance, and resilience of inter-service communication across all Zopa's cloud & SaaS providers
- Provide input into broader platform strategy, architecture reviews, and engineering best practices.
- Proven experience designing and managing AWS networking: VPCs, Transit Gateways, Route53, PrivateLink, NAT gateways, security groups, etc.
- Practical knowledge of Palo Alto Cloud NGFW and cloud-native firewalling/security principles.
- Familiarity with Azure networking constructs.
- Strong hands-on experience with Terraform as the core IaC tool.
- Proficient in GitHub Actions for infrastructure CI/CD.
- Strong troubleshooting skills, including low-level tools like tcpdump and Wireshark.
- Understanding of TLS protocols, public/private key infrastructure, and
- Working knowledge of Kubernetes (specifically EKS) including ingress-controllers, ALBs and request handling with external CDN.
- Experience with Prometheus, Grafana, AWS CloudWatch, and centralized logging (e.g. Splunk or similar).
- Ability to set up effective monitoring and alerting for network and connectivity issues.
- AWS Certified Advanced Networking - Specialty
- AWS Certified Solutions Architect - Associate
- HashiCorp Certified: Terraform Associate