Welcome to the team:
Network & Cloud Security Engineer (CommerzReal) (m/f/diverse)

    Your tasks

    • Providing 2nd and 3rd level support for hybrid network, connectivity and firewall services in production environments;
    • Operating and troubleshooting connectivity between international office locations, central network hubs, Microsoft Azure and external partner environments;
    • Handling Incidents, Service Requests, Change Requests and Problems in accordance with the applicable ITSM processes;
    • Configuring and troubleshooting BGP, IPsec Site-to-Site VPNs, route propagation, user-defined routes, NAT, network segmentation and high-availability concepts;
    • Operating and troubleshooting Azure Virtual WAN, Virtual Hubs, VPN Gateways, Virtual Networks, subnets, peering and Virtual Network Connections;
    • Supporting firewall services based on Azure Firewall Premium and Palo Alto, including policies, network and application rules, NAT, logging and connectivity analysis;
    • Troubleshooting end-to-end application traffic involving Application Gateway, firewalls, DNS/shared services and application Virtual Networks;
    • Monitoring network availability, performance, routing and security events and carrying out structured root cause analyses;
    • Maintaining network diagrams, configuration documentation, operational runbooks and relevant CMDB information;
    • Coordinating technical activities with internal teams, cloud and application teams, carriers, external service providers and vendors;
    • Supporting network migrations, cloud transformation activities and the transition of new services into regular operations;
    • Supporting network automation and Infrastructure-as-Code activities where applicable.

    Your Profile

    • Professional experience in enterprise networking and 2nd/3rd level operations;
    • Proven hands-on experience in hybrid network environments combining on-premises infrastructure and Microsoft Azure;
    • Strong knowledge of TCP/IP, BGP, IPsec/IKEv2, NAT, routing, network segmentation and high-availability concepts;
    • Strong knowledge of Azure Virtual WAN, Virtual Hubs, VPN Gateway, Virtual Networks, subnets, peering and Virtual Network Connections;
    • Experience with Azure routing concepts, including route propagation, user-defined routes and traffic steering through central firewalls;
    • Experience with Azure Firewall Premium and/or Palo Alto firewalls in Microsoft Azure;
    • Good understanding of Application Gateway, DNS and end-to-end application traffic flows in hub-and-spoke environments;
    • Good knowledge of Cisco-based LAN and WAN environments and Layer-2 network technologies;
    • Experience with external partner connections, carrier services and Site-to-Site VPN connectivity;
    • Experience with network monitoring and logging technologies such as SNMP, Syslog and NetFlow as well as Azure-native monitoring capabilities;
    • Experience in structured incident, change and problem handling, root cause analysis and operational documentation;
    • Fluency in English – both written and spoken;
    • University degree in IT or relevant.

    In return, we offer:

    • Good work-life balance, including 25 days annual paid leave (increasing with 1 day per year up to 31 in total), flexible working hours, work-from-home and work from abroad opportunities;
    • Luxury package of additional health and dental insurance;
    • Food vouchers in the amount of EUR 80 monthly;
    • 6 additional annual days off for exceptional circumstances;
    • Employee assistance program for psychological, financial, and legal consultations;
    • Multisport card;
    • Annual contribution of EUR 153.39 net per child for a summer camp/school/kindergarten for children up to age of 15;
    • Possibilities for building career-advancing skills by covering training/certification courses and conferences based on individual learning and development needs, access to an online learning platform;
    • Opportunities for long-term professional development in a stable, 150-year-old company while contributing to the vision of a new, just starting Digital Technology Center;
    • Friendly and supportive multicultural environment, open to new opinions and ideas.

    Commerzbank is proud to be an equal opportunity employer, committed to creating a diverse environment. All qualified applicants will receive consideration for employment without regard to gender, race, color, national origin, religion, gender identity or expression, sexual orientation, genetics, disability, age, or any other characteristics.

    Our Benefits

    • Learning Platforms
    • Children Summer Camp Contribution
    • Employee assistance program
    • Food vouchers
    • 6 Exceptional Days Off
    • 25 up to 31 annual paid leave
    • Multisport Card
    • Health& Dental Insurance
    • Work-life balance
    • Work internationally

    Learning Platforms; Children Summer Camp Contribution; Employee assistance program; Food vouchers; 6 Exceptional Days Off; 25 up to 31 annual paid leave; Multisport Card; Health& Dental Insurance; Work-life balance; Work internationally

    The company

    Commerzbank is a leading international commercial bank with branches and offices in almost 50 countries. The world is changing, becoming digital, and so are we. We are leaving the traditional bank behind us and we are choosing to move forward as a digital enterprise.

    As part of this strategy, Commerzbank continues the expansion of its Digital Technology Center in Sofia, Bulgaria. We need motivated people who will join us on this journey and we are looking for a Network & Cloud Security Engineer in our CommerzReal team.

    In CommerzReal we design and are responsible for a modern, highly scalable and sustainable IT landscape. Jointly with the business departments, we develop innovative and secure digital solutions for our operating model and for our customers. We strive for strategic partnerships with service providers and prop techs that we connect to our IT landscape.

    Contact

    Apply now with your up-to-date CV in English!

    Due to the high volume of applications, we contact only the candidates who best match the role requirements. If you do not hear from us within 14 days, please consider that we won't proceed with your application at this stage.