> Markdown version of [/jobs/ext/564486-cloud-network-security-architect-aws-zero-trust](https://www.wearedevelopers.com/jobs/ext/564486-cloud-network-security-architect-aws-zero-trust). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Network Security Architect - AWS / Zero Trust - **Company:** Capgemini - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $94,248.0 - $215,050.0 - **Contract:** Permanent contract - **Skills:** Access Network, Amazon Web Services, Microsoft Azure, Border Gateway Protocol, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Network Address Translation, Domain Name System (DNS), Internet Protocol Security (IP SEC), Intrusion Detection Systems, IP Routing, Subnetting, Information Systems Security Architecture Professional, Network Security, Network Architecture, Wireless Security, Routing, Network Segmentation, Peering, Ansible, Zero Trust Network Access, Security Information and Event Management, Data Streaming, Systems Integration, TCP/IP, Cloud-native Network Functions (CNF), Transport Layer Security, Load Balancing, Multi-Cloud, Firewalls (Computer Science), Amazon Virtual Private Cloud (VPC), Cloudformation, Firewall Services Module, Terraform, Ddos, Devsecops - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=37b34bed46e5bedd ## About the Role Do you have experience in WAF?, * 10+ years of experience in network and security architecture, with strong focus on cloud platforms. * Deep expertise in cloud networking concepts: routing, DNS, load balancing, NAT, private connectivity, and network segmentation. * Hands-on experience securing AWS and/or Azure networking services (VPC/VNet, Gateway, Firewall, Private Link, NSGs, Route Tables). * Strong understanding of network security technologies: firewalls, WAF, IDS/IPS, DDoS, proxy, and micro-segmentation. * Experience implementing zero-trust and identity-centric network access models. * Proficiency with Infrastructure as Code and automation tools (Terraform, Ansible, CloudFormation). * Solid understanding of TCP/IP, BGP, IPSec, TLS, and network encryption mechanisms. * Experience working in regulated and compliance-driven environments. * Cloud certifications (AWS Certified Security - Specialty, Azure Security Engineer, CCSP). * Experience with multi-cloud or large-scale cloud migration programs. * Knowledge of SASE, CASB, and secure access service edge architectures. * Familiarity with SIEM/SOAR and security monitoring integrations. * Experience supporting DevSecOps and CI/CD security integration. ## Description The Cloud Network Security Architect is responsible for designing, implementing, and governing secure cloud network architectures across hybrid and multi-cloud environments. This role ensures the confidentiality, integrity, and availability of enterprise systems by defining security-by-design network frameworks aligned with business, compliance, and risk management objectives., * Enterprise Zero Trust Network Architect: implement Zero Trust network architecture, including segmentation, least-privilege access, and consistent policy enforcement across users, workloads, and services in hybrid environments. * Network Security Design: Design and validate secure on-prem and cloud networking patterns (VPC/VNet, subnets, routing, TGW/peering, ingress/egress) using cloud-native controls and enterprise platforms. * Cross-Functional Requirements & Architecture Translation: Partner with application/platform/infrastructure teams to capture connectivity and security requirements (ports/protocols, data flows, trust boundaries) and translate them into actionable security architectures. * Firewall & Segmentation Strategy Owner: Define and standardize firewall policies and segmentation models, providing clear guidance on use of Palo Alto/Prisma vs. cloud-native mechanisms (SG/NSG, NACLs, route controls). * Architecture Governance & Adoption : Lead design reviews, threat modeling, and exception handling; produce and maintain standards, reference designs, and architecture decision records to drive secure-by-design outcomes. * Operational Enablement & Continuous Improvement: Collaborate with perimeter defense/SecOps to streamline rule discovery, risk review, approvals, and deployments (including automation); support troubleshooting and optimization for performance and resiliency. ## Related Videos - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) - [Embracing the Hybrid Cloud: Unlocking Success with Ansible](https://www.wearedevelopers.com/videos/932-embracing-the-hybrid-cloud-unlocking-success-with-ansible) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)