> Markdown version of [/jobs/ext/513112-senior-cloud-network-security-engineer](https://www.wearedevelopers.com/jobs/ext/513112-senior-cloud-network-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud Network Security Engineer - **Company:** Prospance inc - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $177,382.0 - $187,637.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cisco PIX, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Computer Networks, Identity and Access Management, Internet Protocol Security (IP SEC), Intrusion Detection Systems, IP Routing, Subnetting, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Network Layer, Network Architecture, PCI Data Security Standards, Windows PowerShell, Cloud Services, Zero Trust Network Access, Runbook, Security Information and Event Management, Wide Area Networks, Network Switches, Cloud-native Network Functions (CNF), Pulumi, Scripting, Google Cloud, Cloud Platform System, Istio, Multi-Cloud, Firewalls (Computer Science), Amazon Virtual Private Cloud (VPC), Cloudformation, Kubernetes, Information Technology, CIS Benchmarks, Terraform, Prisma Cloud Platform, Splunk, Devsecops, Vulnerability Analysis - **Published:** June 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=684618f15f4d62bd ## About the Role Do you have experience in Tooling?, Do you have a Bachelor's degree?, * Bachelor's or Master's degree in Computer Science, Information Security, or a related field (or equivalent experience). * 7+ years of experience in network security engineering, with a meaningful portion in cloud environments. * Hands-on production experience securing at least one of AWS, Azure, or GCP - VPCs/VNets, IAM, security groups/NSGs, cloud firewalls, encryption. * Working proficiency with at least one scripting language (Python, Bash, PowerShell) and willingness to use it daily. * Experience with network security tooling: firewalls, VPNs, IDS/IPS, DLP, encryption. * Strong written and verbal communication skills. Preferred QualificationsCloud-Native Depth * Deep expertise in one cloud and working knowledge of a second (multi-cloud is a strong plus). * Infrastructure-as-Code experience: Terraform (preferred), CloudFormation, or Pulumi. * Container and Kubernetes networking security (network policies, service mesh, EKS/AKS/GKE)., * Zero Trust, SASE, and microsegmentation in cloud or hybrid contexts. * Cloud-native security platforms: AWS Security Hub, Azure Sentinel, GCP Security Command Center, Wiz, Prisma Cloud. * DevSecOps practices and security integration in CI/CD pipelines. Compliance & Industry * Prior experience in healthcare, finance, or government - HIPAA, PCI-DSS, SOX, or HITRUST. * Familiarity with NIST CSF, CIS Controls, or similar frameworks. Certifications * AWS Certified Advanced Networking - Specialty, AWS Security Specialty, Azure Security Engineer Associate, or GCP Professional Cloud Security Engineer. * CISSP, CCNP Security, or CCSP (any of these is a plus, none is required if the hands-on experience is strong). Red Flags - Pass on Candidates Who… * List AWS/Azure/GCP only in a skills matrix but describe only on-prem firewall, SD-WAN, or SASE work in their actual job bullets. * Have heavy Check Point / Palo Alto / Cisco ASA depth but no clear Terraform, Python, or cloud-native automation experience. * Are pure SOC/SIEM operators with no network architecture ownership. * Cannot articulate, in a screening call, how a VPC route table differs from a security group, or when you'd use PrivateLink vs. a VPC peering. * Are looking for a management-only role - this is a hands-on senior IC. Positive Signals - Prioritize Candidates Who… * Have led a cloud network security project end-to-end - design, IaC, deployment, monitoring. * Can point to specific Terraform modules or automation scripts they've authored. * Have a healthcare, fintech, or regulated SaaS background with HIPAA or equivalent compliance exposure. * Talk fluently about both the network layer AND the cloud control plane (IAM, KMS, organization policies). * Have done a real cloud migration or greenfield cloud network buildout, not just a lift-and-shift. ## Description seeking a Cloud Network Security Engineer With DLP to lead the design, implementation, and operation of network security across its multi-cloud environment. This is a hands-on senior IC role with technical leadership responsibilities. The engineer will own how traffic flows, segments, and is inspected across AWS, Azure, and/or GCP - and will work closely with cloud engineering, DevSecOps, and platform teams to embed security into infrastructure-as-code, CI/CD pipelines, and cloud-native deployments.This is not a traditional firewall-administration role. The center of gravity is cloud networking primitives - VPCs, subnets, route tables, security groups, NSGs, cloud-native firewalls, PrivateLink/Private Endpoints, Transit Gateways - combined with the automation and scripting needed to manage them at scale in a regulated healthcare environment.Primary ResponsibilitiesCloud Network Security Architecture * Design, implement, and operate secure cloud network architectures in AWS, Azure, and/or GCP - including VPCs/VNets, subnets, route tables, security groups, NSGs, NAT gateways, Transit Gateways, and PrivateLink/Private Endpoints. * Configure and harden cloud-native firewalls and security services (AWS Network Firewall, Azure Firewall, GCP Cloud Armor, Security Hub, Sentinel, Security Command Center). * Implement secure hybrid connectivity using Direct Connect, ExpressRoute, Cloud Interconnect, IPsec VPNs, and SD-WAN where applicable. * Build and maintain Zero Trust and microsegmentation strategies for cloud workloads, including identity-aware access and least-privilege network policies. Automation & Infrastructure-as-Code * Author and maintain Terraform (or CloudFormation) modules for network security infrastructure - making secure network configurations the default, not the exception. * Automate network security tasks using Python, Bash, or PowerShell - including policy validation, drift detection, scan orchestration, and incident response actions. * Integrate network security controls into CI/CD pipelines so changes are reviewed, tested, and deployed safely. Monitoring, Detection & Incident Response * Operate cloud network monitoring and detection - VPC Flow Logs, GuardDuty, Defender for Cloud, traffic mirroring - and feed signals into SIEM (Sentinel, Splunk, or equivalent). * Lead investigation and forensic analysis for network-related security incidents in cloud environments. * Conduct regular network security assessments, including penetration testing support and vulnerability scans, in cloud-native environments. Governance, Compliance & Collaboration * Develop and enforce network security policies, standards, and guidelines aligned with HIPAA and applicable healthcare compliance requirements. * Partner with cloud engineering, DevSecOps, and application teams to embed security best practices into cloud deployments. * Maintain up-to-date documentation of network security architectures, configurations, and runbooks. * Provide technical leadership and coach junior members of the security team. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Why segmenting your infrastructure into tiers makes your infrastructure design better](https://www.wearedevelopers.com/videos/1960-why-segmenting-your-infrastructure-into-tiers-makes-your-infrastructure-design-better) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Seriously gaming your cloud expertise: from cloud tourist to cloud native](https://www.wearedevelopers.com/videos/373-seriously-gaming-your-cloud-expertise-from-cloud-tourist-to-cloud-native) - [Unleashing Potential Across Teams: The Power of Infrastructure as Code](https://www.wearedevelopers.com/videos/930-unleashing-potential-across-teams-the-power-of-infrastructure-as-code) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)