Description
Remote
Our client seeks a Staff Cloud Network Engineer to lead secure, resilient cloud and hybrid network architectures across AWS and Azure. You will design and implement hub-and-spoke patterns with centralized inspection, deploy Palo Alto firewalls, integrate cloud with data centers and offices, and automate infrastructure using Terraform and modern CI/CD practices. You will collaborate across Cloud, Platform, Infrastructure, Security, and application teams to standardize connectivity, improve performance and availability, and enhance observability and compliance for global enterprise and development environments.
Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $60.00 to $90.00/hr. w2
Responsibilities
- Lead design, implementation, and evolution of secure, highly available network architectures across AWS and Azure, including government and commercial environments.
- Architect multi-region, multi-account, and multi-subscription connectivity using AWS Transit Gateway, Cloud WAN, Direct Connect, and Azure Virtual WAN, Virtual Hub, and ExpressRoute.
- Develop standardized designs for routing, segmentation, centralized inspection, internet egress, private connectivity, DNS, and hybrid connectivity.
- Design and deploy Palo Alto Networks Cloud NGFW and VM-Series firewalls with high availability, routing, load-balancer integration, centralized management, and symmetric traffic flows.
- Integrate public cloud networks with data centers, offices, and mission environments using resilient routing, VPN, private circuits, and hybrid connectivity patterns.
- Build reusable infrastructure as code with Terraform and develop network automation using Python, Ansible, or equivalent.
- Establish Git-based workflows and CI/CD for review, validation, testing, and deployment of network changes.
- Partner with engineering teams to deliver standardized network services, reusable modules, and self-service capabilities.
- Evaluate emerging cloud networking technologies and recommend improvements based on scalability, resiliency, security, operations, and cost.
- Lead complex cloud and hybrid network changes and provide advanced troubleshooting for routing, connectivity, firewall, DNS, performance, and application-access issues.
- Develop automated validation, monitoring, compliance, and observability to identify configuration, connectivity, reliability, performance, capacity, and security risks.
- Execute network and firewall changes aligned with security policies, change control, and engineering standards.
- Create and maintain architecture diagrams, standards, configuration documentation, runbooks, and troubleshooting procedures.
- Mentor engineers on cloud networking, infrastructure as code, automation, and advanced troubleshooting, and communicate recommendations, risks, and tradeoffs.
- Coordinate with vendors and participate in on-call rotations, maintenance windows, and emergency response when required.
- Lead lifecycle management for cloud connectivity, virtual network appliances, firewalls, and platforms, including upgrades, licensing, vulnerability remediation, and risk reduction.
- Identify manual processes and technical debt and replace them with scalable, supportable, automated solutions.
Experience Requirements
- 8+ years designing, implementing, and supporting complex production network environments with significant cloud networking responsibilities.
- Advanced hands-on experience with AWS and Azure networking, with deep expertise in at least one.
- Design experience for multi-region, multi-account, or multi-subscription architectures and resilient hybrid connectivity using Direct Connect, ExpressRoute, Transit Gateway, Cloud WAN, Virtual WAN, and site-to-site VPN.
- Hands-on deployment and management of Palo Alto Networks firewalls in AWS and Azure, including Cloud NGFW or VM-Series and Panorama.
- Expert understanding of BGP, routing policy, segmentation, firewalls, VPNs, redundancy, and failure scenarios.
- Strong foundation in enterprise routing, switching, network security, and integration of cloud with data center and campus environments.
- Significant experience building and maintaining production infrastructure with Terraform.
- Experience developing network automation with Python, Ansible, or equivalent.
- Experience with Git-based workflows, peer review, automated testing, and CI/CD.
- Demonstrated ability to lead initiatives from architecture and design through implementation and operational handoff.
- Ability to evaluate technical approaches, influence direction, mentor engineers, and communicate recommendations, risks, and tradeoffs with strong analytical and troubleshooting skills.
- Preferred: cloud-native security, centralized inspection, private endpoints, DNS architecture, secure internet egress.
- Preferred: AWS GovCloud and Azure Government deployments of Palo Alto firewalls with load-balancer integration and symmetric flows.
- Preferred: reusable Terraform modules and network services for other teams.
- Preferred: Juniper routing and switching, wireless, NAC, or Zero Trust Network Access.
- Preferred: collaboration with Cloud, Platform, DevOps, Infrastructure, and Security teams.
- Preferred: certifications such as AWS Advanced Networking, Azure Network Engineer Associate, CCNP, JNCIP, PCNSE, or equivalent.
- Preferred: experience in regulated, classified, aerospace, defense, or mission-critical environments.
Education Requirements
- Bachelor's degree in a technical discipline or equivalent professional experience.