Senior Network Engineer - Fedramp

Rubrik Rubrik · Enterprise · Palo Alto, CA · Information Technology & Services

Senior Cloud Network Engineer responsible for designing, implementing, and operating secure and scalable networking solutions across a hybrid multi-cloud environment, with a specific focus on FedRAMP-compliant infrastructure for federal and public sector offerings. This includes network segmentation, traffic isolation, security controls, and collaboration with compliance teams to maintain authorization.

What you'd actually do

  1. Support and maintain FedRAMP authorization boundaries, including network segmentation, traffic isolation, and control documentation aligned with NIST SP 800-53.
  2. Collaborate with the GRC and FedRAMP compliance team to support continuous monitoring, POA&M remediation, and ATO (Authority to Operate) maintenance.
  3. Design and implement cloud networking solutions across GCP, AWS, Azure, and OCI.
  4. Build and maintain hybrid multi-cloud connectivity, including VPC/VNet design, peering, transit gateways, interconnects, ExpressRoute, Direct Connect, and secure tunneling.
  5. Implement network security controls including micro-segmentation, zero trust network access (ZTNA), identity-aware routing, firewall policies, and encryption in transit — mapped to FedRAMP and NIST 800-53 baselines.

Skills

Required

  • 5+ years of experience in network engineering
  • hands-on experience in multi-cloud networking
  • managing Palo Alto Network VM Series firewalls
  • Palo Alto Prisma
  • Arista and Cisco Network Devices
  • EVPN-VxLan
  • Arista AVD
  • CVP
  • GitOps workflows
  • cloud-native networking concepts across major CSPs: AWS (VPC, TGW, Direct Connect, GovCloud), GCP (VPC, Interconnect), Azure (VNet, ExpressRoute, Azure Government), OCI
  • designing and operating hybrid/multi-cloud environments with high availability and low latency
  • load balancing
  • DNS
  • NAT
  • TLS termination
  • L7 routing
  • HTTP/1.1–HTTP/3
  • protocol translation
  • architecting or supporting FedRAMP Moderate or High environments
  • network boundary definition
  • segmentation
  • NIST SP 800-53 control implementation
  • zero trust networking
  • modern network security design
  • IaC tools such as Terraform, CloudFormation, or Pulumi
  • scripting skills (Python, Bash, or similar) for automation
  • observability and telemetry tools (OpenTelemetry, FluentBit, Prometheus, Grafana, Datadog)
  • Excellent communication and leadership skills
  • collaborate and influence across engineering and infrastructure teams

Nice to have

  • Cloud networking certifications (e.g., AWS Advanced Networking, GCP Professional Cloud Network Engineer, Azure Network Engineer Associate)
  • Familiarity with FedRAMP authorization processes
  • System Security Plans (SSPs)
  • continuous monitoring frameworks
  • service mesh technologies (e.g., Istio, Consul, Linkerd)
  • HAProxy
  • NGINX
  • Envoy
  • L7 proxies/load balancers
  • compliance-driven or regulated environments, particularly FedRAMP, DoD IL2/IL4, or StateRAMP

What the JD emphasized

  • FedRAMP authorization boundaries
  • network segmentation
  • traffic isolation
  • NIST SP 800-53
  • continuous monitoring
  • ATO (Authority to Operate) maintenance