Subway

Cloud Engineer - Network

Subway$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7-10 years of enterprise network engineering experience.
  • Hands-on expertise with Palo Alto Networks firewalls and GlobalProtect VPN.
  • Production experience with Silver Peak/Aruba EdgeConnect SD-WAN.
  • Proficient in enterprise routing and switching using Juniper and/or Cisco technologies.
  • Strong understanding of Azure and AWS networking architectures.
  • Experience building and maintaining Terraform modules for network infrastructure.
  • Knowledge of identity and authentication integrations including SAML and RADIUS.

Responsibilities

  • Design and maintain enterprise network security infrastructure using Palo Alto Networks.
  • Manage Silver Peak SD-WAN infrastructure and optimize network performance.
  • Architect cloud networking for Azure and AWS services, ensuring security and access control.
  • Build Terraform modules to drive Infrastructure-as-Code adoption.
  • Evaluate AI-driven tools for network monitoring and operational efficiency.
  • Execute change management for network changes and serve as an escalation point for incidents.
  • Monitor health and performance of network platforms using observability tools.

Benefits

  • Insurance Plans (Medical, Life)
  • Pension/401K/RSP (country specific)
  • Competitive Bonus
  • Mobility Allowance
  • Tuition Reimbursement
  • Company Holidays
  • Volunteering time
Full Job Description
Cloud Engineer, Network

Franchise World Headquarters, LLC

Position Overview

We are seeking a Cloud Engineer, Network to design, implement, and support enterprise network and cloud connectivity infrastructure across on-premises, multi-cloud, and hybrid environments. This role is critical as Subway transitions network operations from managed services to an in-house engineering team, requiring deep hands-on expertise across next-generation firewalls, SD-WAN, cloud networking architectures, and infrastructure automation. This is a key build-out hire that directly enables a stronger, more responsive in-house network engineering capability.

Responsibilities
• Design, deploy, and maintain enterprise network security infrastructure using Palo Alto Networks (PAN-OS, Panorama); administer and troubleshoot GlobalProtect VPN including portal/gateway configuration, authentication flows, certificates, HIP checks, and user access issues.
• Manage and optimize Silver Peak (Aruba EdgeConnect) SD-WAN infrastructure across distributed sites, including overlay design, path conditioning, and QoS; design, configure, and support enterprise routing, switching, wireless, and campus/data center network infrastructure using Juniper, including Juniper Mist Wireless management, RF optimization, and AIOps-assisted diagnostics.
• Architect and support cloud networking across Azure (VNets, VNet Peering, Azure Firewall, ExpressRoute, VPN Gateways) and AWS (Transit Gateway, VPC design, Direct Connect, VPN connections); design and manage ACLs and security group policies across cloud and on-premises environments to enforce least-privilege network access.
• Build and maintain Terraform modules for network provisioning, driving Infrastructure-as-Code adoption across the network estate and reducing manual configuration drift; implement and manage microsegmentation strategies to enforce zero-trust principles and reduce lateral movement risk.
• Evaluate and integrate AI-driven tools for network monitoring, anomaly detection, and operational efficiency; support identity and authentication integrations including SAML, RADIUS, MFA, certificate-based authentication, and identity-aware access policies for VPN, wireless, and network access control use cases.
• Execute formal change management practices for firewall, SD-WAN, VPN, wireless, and LAN/WAN changes - including risk assessment, implementation planning, validation, rollback planning, and post-change documentation; serve as an escalation point for complex network incidents, performing root-cause analysis and driving remediation.
• Monitor platform health and performance using observability platforms; analyze firewall traffic, review VPN usage, validate SD-WAN path health, and troubleshoot wireless performance proactively.
• Partner with Cloud Engineering, Cyber Security, and Infrastructure Architecture teams on network segmentation, secure connectivity, and disaster recovery design; develop and maintain network documentation, topology diagrams, and standard operating procedures; participate in on-call rotation for critical network incidents.

Qualifications
• 7-10 years of enterprise network engineering experience.
• Hands-on expertise administering Palo Alto Networks firewalls (PAN-OS, Panorama) and supporting enterprise GlobalProtect VPN environments, including user troubleshooting, authentication, certificates, and security policy enforcement.
• Production experience with Silver Peak / Aruba EdgeConnect SD-WAN.
• Hands-on expertise with enterprise routing and switching using Juniper (Junos) and/or Cisco (IOS, IOS-XE, NX-OS); experience operating Juniper Mist Wireless environments including WLAN configuration, RF/client troubleshooting, and AIOps-assisted diagnostics.
• Strong working knowledge of Azure networking (VNets, Gateways, ExpressRoute, NSGs) and AWS networking (Transit Gateway, VPCs, VPNs, Direct Connect).
• Demonstrated hands-on experience building and maintaining Terraform modules for network infrastructure, including state management, module design, and CI/CD-integrated provisioning.
• Working knowledge of AI-driven network tools (AIOps, anomaly detection, automated remediation) and interest in applying AI to network operations.
• Experience with SAML, RADIUS, MFA, certificate-based authentication, and identity-aware access policies.
• Strong understanding of BGP, OSPF, IPsec VPN, NAT, QoS, VLANs, STP, route redistribution, failover, and traffic engineering.
• Experience troubleshooting complex, multi-site network and connectivity issues.

Preferred Qualifications
• Microsegmentation experience with platforms such as Guardicore/Akamai Guardicore, Illumio, or similar.
• Relevant certifications: PCNSE/PCCET, JNCIS-ENT/JNCIP-ENT, Juniper Mist AI, CCNP Enterprise, Aruba EdgeConnect/Silver Peak, AWS Advanced Networking Specialty, Azure Network Engineer Associate, or HashiCorp Terraform Associate.
• Experience with additional automation tooling such as Ansible or Python scripting.
• Familiarity with SASE and zero-trust network architectures.
• Prior experience transitioning managed or outsourced network functions to an in-house engineering team.

What do we offer?
• Insurance Plans (Medical, Life)
• Pension/401K/RSP (country specific)
• Competitive Bonus
• Mobility Allowance
• Tuition Reimbursement
• Company Holidays
• Volunteering time
• And More.....

About Subway

Subway is a fast food restaurant chain that specializes in submarine sandwiches and salads. The company was founded in 1965 by Fred DeLuca and Peter Buck and is headquartered in Milford, Connecticut. Subway has over 44,000 locations in more than 100 countries, making it the largest fast food chain in the world by number of locations. The company is known for its customizable sandwiches and healthy options, such as its Fresh Fit menu. Subway is a privately held company and does not disclose its financial information.
Learn more about Subway
Size
450,000 employees
Industry
Founded
2007

Similar Jobs

More Jobs at Subway

More Information Technology Jobs

Find similar Cloud Engineer - Network jobs: