Staff Cloud Network Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+21 more
Job description
Our client seeks a Staff Cloud Network Engineer to lead secure, resilient cloud and hybrid network architectures across AWS and Azure. You will design and implement hub-and-spoke patterns with centralized inspection, deploy Palo Alto firewalls, integrate cloud with data centers and offices, and automate infrastructure using Terraform and modern CI/CD practices. You will collaborate across Cloud, Platform, Infrastructure, Security, and application teams to standardize connectivity, improve performance and availability, and enhance observability and compliance for global enterprise and development environments., * Lead design, implementation, and evolution of secure, highly available network architectures across AWS and Azure, including government and commercial environments.
- Architect multi-region, multi-account, and multi-subscription connectivity using AWS Transit Gateway, Cloud WAN, Direct Connect, and Azure Virtual WAN, Virtual Hub, and ExpressRoute.
- Develop standardized designs for routing, segmentation, centralized inspection, internet egress, private connectivity, DNS, and hybrid connectivity.
- Design and deploy Palo Alto Networks Cloud NGFW and VM-Series firewalls with high availability, routing, load-balancer integration, centralized management, and symmetric traffic flows.
- Integrate public cloud networks with data centers, offices, and mission environments using resilient routing, VPN, private circuits, and hybrid connectivity patterns.
- Build reusable infrastructure as code with Terraform and develop network automation using Python, Ansible, or equivalent.
- Establish Git-based workflows and CI/CD for review, validation, testing, and deployment of network changes.
- Partner with engineering teams to deliver standardized network services, reusable modules, and self-service capabilities.
- Evaluate emerging cloud networking technologies and recommend improvements based on scalability, resiliency, security, operations, and cost.
- Lead complex cloud and hybrid network changes and provide advanced troubleshooting for routing, connectivity, firewall, DNS, performance, and application-access issues.
- Develop automated validation, monitoring, compliance, and observability to identify configuration, connectivity, reliability, performance, capacity, and security risks.
- Execute network and firewall changes aligned with security policies, change control, and engineering standards.
- Create and maintain architecture diagrams, standards, configuration documentation, runbooks, and troubleshooting procedures.
- Mentor engineers on cloud networking, infrastructure as code, automation, and advanced troubleshooting, and communicate recommendations, risks, and tradeoffs.
- Coordinate with vendors and participate in on-call rotations, maintenance windows, and emergency response when required.
- Lead lifecycle management for cloud connectivity, virtual network appliances, firewalls, and platforms, including upgrades, licensing, vulnerability remediation, and risk reduction.
- Identify manual processes and technical debt and replace them with scalable, supportable, automated solutions.
Requirements
Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance., * 8+ years designing, implementing, and supporting complex production network environments with significant cloud networking responsibilities.
- Advanced hands-on experience with AWS and Azure networking, with deep expertise in at least one.
- Design experience for multi-region, multi-account, or multi-subscription architectures and resilient hybrid connectivity using Direct Connect, ExpressRoute, Transit Gateway, Cloud WAN, Virtual WAN, and site-to-site VPN.
- Hands-on deployment and management of Palo Alto Networks firewalls in AWS and Azure, including Cloud NGFW or VM-Series and Panorama.
- Expert understanding of BGP, routing policy, segmentation, firewalls, VPNs, redundancy, and failure scenarios.
- Strong foundation in enterprise routing, switching, network security, and integration of cloud with data center and campus environments.
- Significant experience building and maintaining production infrastructure with Terraform.
- Experience developing network automation with Python, Ansible, or equivalent.
- Experience with Git-based workflows, peer review, automated testing, and CI/CD.
- Demonstrated ability to lead initiatives from architecture and design through implementation and operational handoff.
- Ability to evaluate technical approaches, influence direction, mentor engineers, and communicate recommendations, risks, and tradeoffs with strong analytical and troubleshooting skills.
- Preferred: cloud-native security, centralized inspection, private endpoints, DNS architecture, secure internet egress.
- Preferred: AWS GovCloud and Azure Government deployments of Palo Alto firewalls with load-balancer integration and symmetric flows.
- Preferred: reusable Terraform modules and network services for other teams.
- Preferred: Juniper routing and switching, wireless, NAC, or Zero Trust Network Access.
- Preferred: collaboration with Cloud, Platform, DevOps, Infrastructure, and Security teams.
- Preferred: certifications such as AWS Advanced Networking, Azure Network Engineer Associate, CCNP, JNCIP, PCNSE, or equivalent.
- Preferred: experience in regulated, classified, aerospace, defense, or mission-critical environments.
Education Requirements:
- Bachelor’s degree in a technical discipline or equivalent professional experience.
Benefits & conditions
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:
· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
About the company
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…