Senior Cloud Network Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+35 more
Job description
seeking a Cloud Network Security Engineer With DLP to lead the design, implementation, and operation of network security across its multi-cloud environment. This is a hands-on senior IC role with technical leadership responsibilities. The engineer will own how traffic flows, segments, and is inspected across AWS, Azure, and/or GCP - and will work closely with cloud engineering, DevSecOps, and platform teams to embed security into infrastructure-as-code, CI/CD pipelines, and cloud-native deployments.This is not a traditional firewall-administration role. The center of gravity is cloud networking primitives - VPCs, subnets, route tables, security groups, NSGs, cloud-native firewalls, PrivateLink/Private Endpoints, Transit Gateways - combined with the automation and scripting needed to manage them at scale in a regulated healthcare environment.Primary ResponsibilitiesCloud Network Security Architecture
- Design, implement, and operate secure cloud network architectures in AWS, Azure, and/or GCP - including VPCs/VNets, subnets, route tables, security groups, NSGs, NAT gateways, Transit Gateways, and PrivateLink/Private Endpoints.
- Configure and harden cloud-native firewalls and security services (AWS Network Firewall, Azure Firewall, GCP Cloud Armor, Security Hub, Sentinel, Security Command Center).
- Implement secure hybrid connectivity using Direct Connect, ExpressRoute, Cloud Interconnect, IPsec VPNs, and SD-WAN where applicable.
- Build and maintain Zero Trust and microsegmentation strategies for cloud workloads, including identity-aware access and least-privilege network policies.
Automation & Infrastructure-as-Code
- Author and maintain Terraform (or CloudFormation) modules for network security infrastructure - making secure network configurations the default, not the exception.
- Automate network security tasks using Python, Bash, or PowerShell - including policy validation, drift detection, scan orchestration, and incident response actions.
- Integrate network security controls into CI/CD pipelines so changes are reviewed, tested, and deployed safely.
Monitoring, Detection & Incident Response
- Operate cloud network monitoring and detection - VPC Flow Logs, GuardDuty, Defender for Cloud, traffic mirroring - and feed signals into SIEM (Sentinel, Splunk, or equivalent).
- Lead investigation and forensic analysis for network-related security incidents in cloud environments.
- Conduct regular network security assessments, including penetration testing support and vulnerability scans, in cloud-native environments.
Governance, Compliance & Collaboration
- Develop and enforce network security policies, standards, and guidelines aligned with HIPAA and applicable healthcare compliance requirements.
- Partner with cloud engineering, DevSecOps, and application teams to embed security best practices into cloud deployments.
- Maintain up-to-date documentation of network security architectures, configurations, and runbooks.
- Provide technical leadership and coach junior members of the security team.
Requirements
Do you have experience in Tooling?, Do you have a Bachelor’s degree?, * Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 7+ years of experience in network security engineering, with a meaningful portion in cloud environments.
- Hands-on production experience securing at least one of AWS, Azure, or GCP - VPCs/VNets, IAM, security groups/NSGs, cloud firewalls, encryption.
- Working proficiency with at least one scripting language (Python, Bash, PowerShell) and willingness to use it daily.
- Experience with network security tooling: firewalls, VPNs, IDS/IPS, DLP, encryption.
- Strong written and verbal communication skills.
Preferred QualificationsCloud-Native Depth
- Deep expertise in one cloud and working knowledge of a second (multi-cloud is a strong plus).
- Infrastructure-as-Code experience: Terraform (preferred), CloudFormation, or Pulumi.
- Container and Kubernetes networking security (network policies, service mesh, EKS/AKS/GKE)., * Zero Trust, SASE, and microsegmentation in cloud or hybrid contexts.
- Cloud-native security platforms: AWS Security Hub, Azure Sentinel, GCP Security Command Center, Wiz, Prisma Cloud.
- DevSecOps practices and security integration in CI/CD pipelines.
Compliance & Industry
- Prior experience in healthcare, finance, or government - HIPAA, PCI-DSS, SOX, or HITRUST.
- Familiarity with NIST CSF, CIS Controls, or similar frameworks.
Certifications
- AWS Certified Advanced Networking - Specialty, AWS Security Specialty, Azure Security Engineer Associate, or GCP Professional Cloud Security Engineer.
- CISSP, CCNP Security, or CCSP (any of these is a plus, none is required if the hands-on experience is strong).
Red Flags - Pass on Candidates Who…
- List AWS/Azure/GCP only in a skills matrix but describe only on-prem firewall, SD-WAN, or SASE work in their actual job bullets.
- Have heavy Check Point / Palo Alto / Cisco ASA depth but no clear Terraform, Python, or cloud-native automation experience.
- Are pure SOC/SIEM operators with no network architecture ownership.
- Cannot articulate, in a screening call, how a VPC route table differs from a security group, or when you’d use PrivateLink vs. a VPC peering.
- Are looking for a management-only role - this is a hands-on senior IC.
Positive Signals - Prioritize Candidates Who…
- Have led a cloud network security project end-to-end - design, IaC, deployment, monitoring.
- Can point to specific Terraform modules or automation scripts they’ve authored.
- Have a healthcare, fintech, or regulated SaaS background with HIPAA or equivalent compliance exposure.
- Talk fluently about both the network layer AND the cloud control plane (IAM, KMS, organization policies).
- Have done a real cloud migration or greenfield cloud network buildout, not just a lift-and-shift.
Benefits & conditions
$85.28 - $90.21 an hour - Full-time, Contract, Pulled from the full job description
- 401(k)
- Dental insurance, * 401(k)
- Dental insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
7 Cloud Computing Trends Coming in 2025 for Developers
Is Software Engineering Over-Saturated?
Why Upskilling And Reskilling is Important For Developers
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.