Cloud Engineer - Network
Subway · Shelton, CT · 1 wk ago
EngineeringFull-time
About the role
We are seeking a Cloud Engineer, Network to design, implement, and support enterprise network and cloud connectivity infrastructure across on-premises, multi-cloud, and hybrid environments. This role is critical as Subway transitions network operations from managed services to an in-house engineering team, requiring deep hands-on expertise across next-generation firewalls, SD-WAN, cloud networking architectures, and infrastructure automation. This is a key build-out hire that directly enables a stronger, more responsive in-house network engineering capability.
Responsibilities
- Design, deploy, and maintain enterprise network security infrastructure using Palo Alto Networks (PAN-OS, Panorama); administer and troubleshoot GlobalProtect VPN including portal/gateway configuration, authentication flows, certificates, HIP checks, and user access issues.
- Manage and optimize Silver Peak (Aruba EdgeConnect) SD-WAN infrastructure across distributed sites, including overlay design, path conditioning, and QoS; design, configure, and support enterprise routing, switching, wireless, and campus/data center network infrastructure using Juniper, including Juniper Mist Wireless management, RF optimization, and AIOps-assisted diagnostics.
- Architect and support cloud networking across Azure (VNets, VNet Peering, Azure Firewall, ExpressRoute, VPN Gateways) and AWS (Transit Gateway, VPC design, Direct Connect, VPN connections); design and manage ACLs and security group policies across cloud and on-premises environments to enforce least-privilege network access.
- Build and maintain Terraform modules for network provisioning, driving Infrastructure-as-Code adoption across the network estate and reducing manual configuration drift; implement and manage microsegmentation strategies to enforce zero-trust principles and reduce lateral movement risk.
- Evaluate and integrate AI-driven tools for network monitoring, anomaly detection, and operational efficiency; support identity and authentication integrations including SAML, RADIUS, MFA, certificate-based authentication, and identity-aware access policies for VPN, wireless, and network access control use cases.
- Execute formal change management practices for firewall, SD-WAN, VPN, wireless, and LAN/WAN changes — including risk assessment, implementation planning, validation, rollback planning, and post-change documentation; serve as an escalation point for complex network incidents, performing root-cause analysis and driving remediation.
- Monitor platform health and performance using observability platforms; analyze firewall traffic, review VPN usage, validate SD-WAN path health, and troubleshoot wireless performance proactively.
- Partner with Cloud Engineering, Cyber Security, and Infrastructure Architecture teams on network segmentation, secure connectivity, and disaster recovery design; develop and maintain network documentation, topology diagrams, and standard operating procedures; participate in on-call rotation for critical network incidents.
Qualifications
- 7–10 years of enterprise network engineering experience.
- Hands-on expertise administering Palo Alto Networks firewalls (PAN-OS, Panorama) and supporting enterprise GlobalProtect VPN environments, including user troubleshooting, authentication, certificates, and security policy enforcement.
- Production experience with Silver Peak / Aruba EdgeConnect SD-WAN.
- Hands-on expertise with enterprise routing and switching using Juniper (Junos) and/or Cisco (IOS, IOS-XE, NX-OS); experience operating Juniper Mist Wireless environments including WLAN configuration, RF/client troubleshooting, and AIOps-assisted diagnostics.
- Strong working knowledge of Azure networking (VNets, Gateways, ExpressRoute, NSGs) and AWS networking (Transit Gateway, VPCs, VPNs, Direct Connect).
- Demonstrated hands-on experience building and maintaining Terraform modules for network infrastructure, including state management, module design, and CI/CD-integrated provisioning.
- Working knowledge of AI-driven network tools (AIOps, anomaly detection, automated remediation) and interest in applying AI to network operations.
- Experience with SAML, RADIUS, MFA, certificate-based authentication, and identity-aware access policies.
- Strong understanding of BGP, OSPF, IPsec VPN, NAT, QoS, VLANs, STP, route redistribution, failover, and traffic engineering.
- Experience troubleshooting complex, multi-site network and connectivity issues.
Preferred Qualifications
- Microsegmentation experience with platforms such as Guardicore/Akamai Guardicore, Illumio, or similar.
- Relevant certifications: PCNSE/PCCET, JNCIS-ENT/JNCIP-ENT, Juniper Mist AI, CCNP Enterprise, Aruba EdgeConnect/Silver Peak, AWS Advanced Networking Specialty, Azure Network Engineer Associate, or HashiCorp Terraform Associate.
- Experience with additional automation tooling such as Ansible or Python scripting.
- Familiarity with SASE and zero-trust network architectures.
- Prior experience transitioning managed or outsourced network functions to an in-house engineering team.
Benefits
- Insurance Plans (Medical, Life)
- Pension/401K/RSP (country specific)
- Competitive Bonus
- Mobility Allowance
- Tuition Reimbursement
- Company Holidays
- Volunteering time
- And More…