Cloud Engineer, Network
Franchise World Headquarters, LLC
Position Overview
We are seeking a Cloud Engineer, Network to design, implement, and support enterprise network and cloud connectivity infrastructure across on-premises, multi-cloud, and hybrid environments. This role is critical as Subway transitions network operations from managed services to an in-house engineering team, requiring deep hands-on expertise across next-generation firewalls, SD-WAN, cloud networking architectures, and infrastructure automation. This is a key build-out hire that directly enables a stronger, more responsive in-house network engineering capability.
Responsibilities
• Design, deploy, and maintain enterprise network security infrastructure using Palo Alto Networks (PAN-OS, Panorama); administer and troubleshoot GlobalProtect VPN including portal/gateway configuration, authentication flows, certificates, HIP checks, and user access issues.
• Manage and optimize Silver Peak (Aruba EdgeConnect) SD-WAN infrastructure across distributed sites, including overlay design, path conditioning, and QoS; design, configure, and support enterprise routing, switching, wireless, and campus/data center network infrastructure using Juniper, including Juniper Mist Wireless management, RF optimization, and AIOps-assisted diagnostics.
• Architect and support cloud networking across Azure (VNets, VNet Peering, Azure Firewall, ExpressRoute, VPN Gateways) and AWS (Transit Gateway, VPC design, Direct Connect, VPN connections); design and manage ACLs and security group policies across cloud and on-premises environments to enforce least-privilege network access.
• Build and maintain Terraform modules for network provisioning, driving Infrastructure-as-Code adoption across the network estate and reducing manual configuration drift; implement and manage microsegmentation strategies to enforce zero-trust principles and reduce lateral movement risk.
• Evaluate and integrate AI-driven tools for network monitoring, anomaly detection, and operational efficiency; support identity and authentication integrations including SAML, RADIUS, MFA, certificate-based authentication, and identity-aware access policies for VPN, wireless, and network access control use cases.
• Execute formal change management practices for firewall, SD-WAN, VPN, wireless, and LAN/WAN changes - including risk assessment, implementation planning, validation, rollback planning, and post-change documentation; serve as an escalation point for complex network incidents, performing root-cause analysis and driving remediation.
• Monitor platform health and performance using observability platforms; analyze firewall traffic, review VPN usage, validate SD-WAN path health, and troubleshoot wireless performance proactively.
• Partner with Cloud Engineering, Cyber Security, and Infrastructure Architecture teams on network segmentation, secure connectivity, and disaster recovery design; develop and maintain network documentation, topology diagrams, and standard operating procedures; participate in on-call rotation for critical network incidents.
Qualifications
• 7-10 years of enterprise network engineering experience.
• Hands-on expertise administering Palo Alto Networks firewalls (PAN-OS, Panorama) and supporting enterprise GlobalProtect VPN environments, including user troubleshooting, authentication, certificates, and security policy enforcement.
• Production experience with Silver Peak / Aruba EdgeConnect SD-WAN.
• Hands-on expertise with enterprise routing and switching using Juniper (Junos) and/or Cisco (IOS, IOS-XE, NX-OS); experience operating Juniper Mist Wireless environments including WLAN configuration, RF/client troubleshooting, and AIOps-assisted diagnostics.
• Strong working knowledge of Azure networking (VNets, Gateways, ExpressRoute, NSGs) and AWS networking (Transit Gateway, VPCs, VPNs, Direct Connect).
• Demonstrated hands-on experience building and maintaining Terraform modules for network infrastructure, including state management, module design, and CI/CD-integrated provisioning.
• Working knowledge of AI-driven network tools (AIOps, anomaly detection, automated remediation) and interest in applying AI to network operations.
• Experience with SAML, RADIUS, MFA, certificate-based authentication, and identity-aware access policies.
• Strong understanding of BGP, OSPF, IPsec VPN, NAT, QoS, VLANs, STP, route redistribution, failover, and traffic engineering.
• Experience troubleshooting complex, multi-site network and connectivity issues.
Preferred Qualifications
• Microsegmentation experience with platforms such as Guardicore/Akamai Guardicore, Illumio, or similar.
• Relevant certifications: PCNSE/PCCET, JNCIS-ENT/JNCIP-ENT, Juniper Mist AI, CCNP Enterprise, Aruba EdgeConnect/Silver Peak, AWS Advanced Networking Specialty, Azure Network Engineer Associate, or HashiCorp Terraform Associate.
• Experience with additional automation tooling such as Ansible or Python scripting.
• Familiarity with SASE and zero-trust network architectures.
• Prior experience transitioning managed or outsourced network functions to an in-house engineering team.
What do we offer?
• Insurance Plans (Medical, Life)
• Pension/401K/RSP (country specific)
• Competitive Bonus
• Mobility Allowance
• Tuition Reimbursement
• Company Holidays
• Volunteering time
• And More.....