Jobs and Careers
BL

Cloud Network Security Engineer

BlackRock
New York City, United StatesRemotefull_timeVerifiedPosted 7 Jul 2026
💰 $200,000/yr($162,000/yr$200,000/yr)

About the role

About this role

YOUR TEAM 

Aladdin Platform Engineering powers the technology foundation behind BlackRock’s Aladdin platform - a unified system that connects risk, portfolio management, trading, and operations for investors globally. We build the mission critical hosting platform that enable engineers to develop products and operators to run the platform at scale.  

Our teams sit at the center of how Aladdin evolves - partnering across product, data, and engineering to deliver scalable infrastructure that support mission-critical workflows for clients worldwide. We develop AI-first engineering capabilities, using a suite of tools across the development lifecycle to improve developer productivity and reduce friction at scale. 

YOUR ROLE AND IMPACT 

The Cloud Network Security Engineer is responsible for automating, designing, implementing, and maintaining secure networking environments across public, private, and hybrid cloud platforms. This role ensures confidentiality, integrity, and availability of data and services by applying advanced security principles, and compliance standards.
 

You’ll pair strong engineering fundamentals with an AI-driven approach to solving problems—leveraging automation, intelligent tooling, and emerging AI capabilities to reduce operational toil, accelerate delivery, and enhance the developer experience. As a technical leader, you will help shape platform strategy, influence architectural direction, mentor engineers, and drive the adoption of next-generation engineering practices that define the future of Aladdin. 

YOUR RESPONSIBILITIES 
Architecture & Design
Develop secure network architectures for hybrid & multi cloud environments (AWS, Azure, GCP).

  • Architect robust security solutions for containerized applications.
    Implement network segmentation, micro-segmentation, and zero-trust principles.
    Design end-to-end encrypted connectivity patterns.
    Design secure network architecture for containerized environments i.e. Open Container Initiative (OCI) container packaging and runtime
    Design scalable / dynamic security patterns, leveraging tag & identity-based attributes.

Security Implementation

  • Configure and manage cloud-native firewalls, security groups, network ACLs and network security appliances.

  • Deploy intrusion detection/prevention systems and threat monitoring tools.

 Operations & Monitoring

  • Monitor cloud network traffic for anomalies and potential breaches.

  • Remediate vulnerability assessments and penetration testing on cloud networks.

  • Respond to and investigate cloud security incidents.

  • Automation & Optimization

  • Strong understanding of Infrastructure as Code (IaC) tools and CI/CD pipelines for secure deployments.

  • Automate security policy enforcement and configuration management.

  • Proficient in scripting with Python to automate network tasks, build integrations, and manage workflows.

YOU HAVE… 

Required Skills & Qualifications

  • Excellent collaboration skills to work effectively across teams, along with strong verbal and written communication abilities.

  • Expertise in network security protocols (IPSec, TLS, MacSec, etc.) and encryption standards.

  • Experience with cloud networking services: VPC, VNets, Subnets, Load Balancers.

  • Proficiency with IaC Tools and Frameworks: Comfortable working with tools such as Terraform, Ansible to automate infrastructure provisioning and security configuration

  • Proficient in AI tooling & innovation

  • Preferred Tools & Technologies

  • Infrastructure as Code (IaC) tools for provisioning cloud resources., Automation tools for configuration management and deployment, Python scripting.

  • Git/GitHub/GitLab for version control.

  • SIEM tools (Splunk) for monitoring.

  • Ensure compliance with regulatory frameworks (ISO 27001, SOC2, GDPR).

  • Cloud-Native distributed containerized microservice orchestration Network Policies, Istio, Calico.

  • Strong knowledge of networking protocols (BGP, OSPF).

  • Understanding of Open Container Initiative (OCI) container image packaging and runtime/Netconf-yang/Linux/ API programming /JSON /XML /GitHub.

Certifications preferred:

AWS Certified Security Specialty, Azure Security Engineer Associate, Certified Enterprise-grade container orchestration platform supporting declarative infrastructure and horizontal scaling Security Specialist (CKS), CISSP or CCSP.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

BlackRock

View company profile →