Senior Cloud Network Security Engineer

Prospance inc
United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$177,382.0 - $187,637.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Cisco PIX Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Computer Networks Identity and Access Management
+35 more
Internet Protocol Security (IP SEC) Intrusion Detection Systems IP Routing Subnetting Virtual Private Networks (VPN) Python (Programming Language) Network Security Network Layer Network Architecture PCI Data Security Standards Windows PowerShell Cloud Services Zero Trust Network Access Runbook Security Information and Event Management Wide Area Networks Network Switches Cloud-native Network Functions (CNF) Pulumi Scripting Google Cloud Cloud Platform System Istio Multi-Cloud Firewalls (Computer Science) Amazon Virtual Private Cloud (VPC) Cloudformation Kubernetes Information Technology CIS Benchmarks Terraform Prisma Cloud Platform Splunk Devsecops Vulnerability Analysis

Job description

seeking a Cloud Network Security Engineer With DLP to lead the design, implementation, and operation of network security across its multi-cloud environment. This is a hands-on senior IC role with technical leadership responsibilities. The engineer will own how traffic flows, segments, and is inspected across AWS, Azure, and/or GCP - and will work closely with cloud engineering, DevSecOps, and platform teams to embed security into infrastructure-as-code, CI/CD pipelines, and cloud-native deployments.This is not a traditional firewall-administration role. The center of gravity is cloud networking primitives - VPCs, subnets, route tables, security groups, NSGs, cloud-native firewalls, PrivateLink/Private Endpoints, Transit Gateways - combined with the automation and scripting needed to manage them at scale in a regulated healthcare environment.Primary ResponsibilitiesCloud Network Security Architecture

  • Design, implement, and operate secure cloud network architectures in AWS, Azure, and/or GCP - including VPCs/VNets, subnets, route tables, security groups, NSGs, NAT gateways, Transit Gateways, and PrivateLink/Private Endpoints.
  • Configure and harden cloud-native firewalls and security services (AWS Network Firewall, Azure Firewall, GCP Cloud Armor, Security Hub, Sentinel, Security Command Center).
  • Implement secure hybrid connectivity using Direct Connect, ExpressRoute, Cloud Interconnect, IPsec VPNs, and SD-WAN where applicable.
  • Build and maintain Zero Trust and microsegmentation strategies for cloud workloads, including identity-aware access and least-privilege network policies.

Automation & Infrastructure-as-Code

  • Author and maintain Terraform (or CloudFormation) modules for network security infrastructure - making secure network configurations the default, not the exception.
  • Automate network security tasks using Python, Bash, or PowerShell - including policy validation, drift detection, scan orchestration, and incident response actions.
  • Integrate network security controls into CI/CD pipelines so changes are reviewed, tested, and deployed safely.

Monitoring, Detection & Incident Response

  • Operate cloud network monitoring and detection - VPC Flow Logs, GuardDuty, Defender for Cloud, traffic mirroring - and feed signals into SIEM (Sentinel, Splunk, or equivalent).
  • Lead investigation and forensic analysis for network-related security incidents in cloud environments.
  • Conduct regular network security assessments, including penetration testing support and vulnerability scans, in cloud-native environments.

Governance, Compliance & Collaboration

  • Develop and enforce network security policies, standards, and guidelines aligned with HIPAA and applicable healthcare compliance requirements.
  • Partner with cloud engineering, DevSecOps, and application teams to embed security best practices into cloud deployments.
  • Maintain up-to-date documentation of network security architectures, configurations, and runbooks.
  • Provide technical leadership and coach junior members of the security team.

Requirements

Do you have experience in Tooling?, Do you have a Bachelor’s degree?, * Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field (or equivalent experience).

  • 7+ years of experience in network security engineering, with a meaningful portion in cloud environments.
  • Hands-on production experience securing at least one of AWS, Azure, or GCP - VPCs/VNets, IAM, security groups/NSGs, cloud firewalls, encryption.
  • Working proficiency with at least one scripting language (Python, Bash, PowerShell) and willingness to use it daily.
  • Experience with network security tooling: firewalls, VPNs, IDS/IPS, DLP, encryption.
  • Strong written and verbal communication skills.

Preferred QualificationsCloud-Native Depth

  • Deep expertise in one cloud and working knowledge of a second (multi-cloud is a strong plus).
  • Infrastructure-as-Code experience: Terraform (preferred), CloudFormation, or Pulumi.
  • Container and Kubernetes networking security (network policies, service mesh, EKS/AKS/GKE)., * Zero Trust, SASE, and microsegmentation in cloud or hybrid contexts.
  • Cloud-native security platforms: AWS Security Hub, Azure Sentinel, GCP Security Command Center, Wiz, Prisma Cloud.
  • DevSecOps practices and security integration in CI/CD pipelines.

Compliance & Industry

  • Prior experience in healthcare, finance, or government - HIPAA, PCI-DSS, SOX, or HITRUST.
  • Familiarity with NIST CSF, CIS Controls, or similar frameworks.

Certifications

  • AWS Certified Advanced Networking - Specialty, AWS Security Specialty, Azure Security Engineer Associate, or GCP Professional Cloud Security Engineer.
  • CISSP, CCNP Security, or CCSP (any of these is a plus, none is required if the hands-on experience is strong).

Red Flags - Pass on Candidates Who…

  • List AWS/Azure/GCP only in a skills matrix but describe only on-prem firewall, SD-WAN, or SASE work in their actual job bullets.
  • Have heavy Check Point / Palo Alto / Cisco ASA depth but no clear Terraform, Python, or cloud-native automation experience.
  • Are pure SOC/SIEM operators with no network architecture ownership.
  • Cannot articulate, in a screening call, how a VPC route table differs from a security group, or when you’d use PrivateLink vs. a VPC peering.
  • Are looking for a management-only role - this is a hands-on senior IC.

Positive Signals - Prioritize Candidates Who…

  • Have led a cloud network security project end-to-end - design, IaC, deployment, monitoring.
  • Can point to specific Terraform modules or automation scripts they’ve authored.
  • Have a healthcare, fintech, or regulated SaaS background with HIPAA or equivalent compliance exposure.
  • Talk fluently about both the network layer AND the cloud control plane (IAM, KMS, organization policies).
  • Have done a real cloud migration or greenfield cloud network buildout, not just a lift-and-shift.

Benefits & conditions

$85.28 - $90.21 an hour - Full-time, Contract, Pulled from the full job description

  • 401(k)
  • Dental insurance, * 401(k)
  • Dental insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:55 min

Contrasting Terraform with Pulumi and cloud-specific tools

Devlin Duldulao · LIVE

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all