Network Security Cloud Engineering
About the role
Design, develop, and implement cloud network security capabilities across public and private cloud platforms. Engineer and automate network security controls including on-premises firewalls, cloud firewalls, security groups, network ACLs, and cloud-native security services. Build and maintain Infrastructure-as-Code (Terraform, CloudFormation, or similar) to deploy secure cloud networking environments. Collaborate with Cloud Engineering, Network Engineering, and Security Architecture teams to implement secure hybrid connectivity between on-premises and cloud environments. Support secure connectivity solutions including VPN, Direct Connect, ExpressRoute, Transit Gateway, VPC/VNet peering, Private Link, and service mesh technologies. Conduct proof-of-concept evaluations of emerging cloud networking and security technologies. Partner with Security Operations and Incident Response teams to improve network visibility, logging, monitoring, and threat detection. Participate in architecture reviews to ensure cloud applications and infrastructure comply with enterprise security standards. Identify opportunities to improve operational efficiency through automation and security orchestration.
Responsibilities
- Design, develop, and implement cloud network security capabilities across public and private cloud platforms.
- Engineer and automate network security controls including on-premises firewalls, cloud firewalls, security groups, network ACLs, and cloud-native security services.
- Build and maintain Infrastructure-as-Code (Terraform, CloudFormation, or similar) to deploy secure cloud networking environments.
- Collaborate with Cloud Engineering, Network Engineering, and Security Architecture teams to implement secure hybrid connectivity between on-premises and cloud environments.
- Support secure connectivity solutions including VPN, Direct Connect, ExpressRoute, Transit Gateway, VPC/VNet peering, Private Link, and service mesh technologies.
- Conduct proof-of-concept evaluations of emerging cloud networking and security technologies.
- Partner with Security Operations and Incident Response teams to improve network visibility, logging, monitoring, and threat detection.
- Participate in architecture reviews to ensure cloud applications and infrastructure comply with enterprise security standards.
- Identify opportunities to improve operational efficiency through automation and security orchestration.
Requirements
- 5+ years of experience in Network Security, Cloud Security, or Infrastructure Security engineering.
- Experience designing and securing networking in AWS, Azure, Google, or Oracle Cloud Platform.
- Strong understanding of core cloud-native networking and security concepts, including VPCs and VNets, routing, segmentation, load balancing, private connectivity, identity-aware access, encryption, and network policy enforcement.
- Experience leveraging AI tools to enhance productivity, automate engineering tasks, and accelerate the delivery of secure cloud networking solutions.
- Experience with Infrastructure-as-Code tools such as Terraform or CloudFormation.
- Familiarity with security monitoring, SIEM integration, logging, and network telemetry.
- Familiarity with enterprise network security technologies such as next-generation firewalls, web application firewalls, secure web gateways, DNS security, IDS/IPS, network segmentation, and zero trust network access.
- Experience designing, securing, and supporting Software-as-a-Service (SaaS) environments and integrations, including secure connectivity, identity-aware access, API security, and SaaS security best practices.
- Familiarity with SaaS security solutions such as CASB, Secure Service Edge (SSE), Secure Access Service Edge (SASE), and Zero Trust Network Access (ZTNA) to protect enterprise users and cloud-based applications.
- Experience integrating SaaS platforms with enterprise identity providers (Azure AD/Entra ID, Okta, Ping Identity, or similar) using SAML, OAuth, and OpenID Connect (OIDC).
- Experience securing access to enterprise SaaS applications through conditional access policies, network segmentation, and cloud-native security controls.
- Experience supporting large-scale enterprise cloud migrations.
Qualifications
Generic Managerial Skills, If any
Skills
- Experience with Infrastructure-as-Code tools such as Terraform or CloudFormation.
- Familiarity with security monitoring, SIEM integration, logging, and network telemetry.
- Familiarity with enterprise network security technologies such as next-generation firewalls, web application firewalls, secure web gateways, DNS security, IDS/IPS, network segmentation, and zero trust network access.
- Experience with SaaS security solutions such as CASB, Secure Service Edge (SSE), Secure Access Service Edge (SASE), and Zero Trust Network Access (ZTNA) to protect enterprise users and cloud-based applications.
- Experience with SAML, OAuth, and OpenID Connect (OIDC).
- Experience with conditional access policies, network segmentation, and cloud-native security controls.
- Experience supporting large-scale enterprise cloud migrations.
Benefits
N/A
Pay
$130,000-$135,000 a year
Schedule
N/A