Location: Remote with occasional travel to the client site in DC.
Status: This position requires a
U.S. Citizen. The selected candidate will go through a Public Trust Clearance process.
Responsibilities:Cloud Architecture and Solutions EngineeringDesign and govern AWS infrastructure supporting the application portfolio, including:
- VPC design, subnet segmentation, routing, NAT gateways, and security groups
- IAM policy design aligned to least-privilege principles
- Solutions architecture for new applications, including deployment strategy, service selection, and integration patterns
- Infrastructure-as-code development and maintenance (CloudFormation, Terraform, AWS CDK)
- Environment management (development, staging, production)
- Integration with enterprise security controls (e.g., Palo Alto firewalls)
- Architectural documentation to support Authority to Operate (ATO) requirements
- Cloud cost governance and optimization
AWS Networking & Load Balancing- Deep expertise in AWS Gateway Load Balancer (GWLB) architecture, deployment, and configuration
- Proficient in designing and managing Gateway Load Balancer Endpoints (GWLBe) for traffic inspection
- Strong understanding of GWLB GENEVE protocol tunneling and packet encapsulation/decapsulation
- Experience integrating GWLB with third-party virtual appliances for inline traffic inspection
- Ability to design bump-in-the-wire traffic inspection architectures using GWLB
- Proficient in GWLB target groups, health checks, and flow stickiness configurations
- Experience with VPC endpoint services and consumer/provider models
- Understanding of east-west and north-south traffic inspection patterns using GWLB
AWS Cloud Infrastructure- Strong knowledge of AWS Landing Zone Accelerator (LZA) deployment and customization
- Experience managing AWS Control Tower and multi-account AWS Organizations structures
- Proficient in AWS CDK (Cloud Development Kit) using Python, TypeScript, or Java
- Skilled in writing and maintaining AWS CloudFormation templates (YAML/JSON)
- Experience with CDK Constructs, Stacks, and App lifecycle management
- Ability to convert CloudFormation templates to CDK and vice versa
- Proficient in CloudFormation StackSets for multi-account/multi-region deployments
- Familiarity with AWS Transit Gateway, VPC peering, and hybrid connectivity
- Knowledge of AWS Route 53, VPC DNS resolution, and private hosted zones
- Experience with AWS IAM, SCPs, and least-privilege security models
Linux (Red Hat Enterprise Linux - RHEL)- Expert-level proficiency in Red Hat Enterprise Linux (RHEL) administration
- Strong skills in systemd, service management, and process monitoring
- Proficient in networking configuration using nmcli, ip commands, and network scripts
- Experience with SELinux policy management and troubleshooting
- Skilled in firewalld/iptables rule management for host-based security
- Proficient in shell scripting (Bash) for automation and operational tasks
- Experience with RHEL subscription management, yum/dnf package management
- Knowledge of kernel tuning and performance optimization for network-heavy workloads
- Familiarity with Red Hat Satellite or Ansible for configuration management
- Experience with tcpdump, Wireshark, netstat, ss for network troubleshooting on Linux
Palo Alto Networks (Firewall & Security)- Expert knowledge of Palo Alto NGFW (Next-Generation Firewall) configuration and management
- Deep understanding of Security Policies, NAT Policies, and PBF (Policy-Based Forwarding)
- Proficient in App-ID, User-ID, and Content-ID technologies
- Experience deploying Palo Alto VM-Series firewalls in AWS environments
- Strong skills in Threat Prevention, Anti-Virus, Anti-Spyware, and Vulnerability Protection profiles
- Proficient in URL Filtering, DNS Security, and WildFire sandbox integration
- Experience with High Availability (HA) configurations (Active/Passive and Active/Active)
- Knowledge of Palo Alto bootstrapping in cloud environments (S3 bootstrap)
- Skilled in log forwarding, monitoring, and integration with SIEM platforms
- Familiarity with Decryption Policies (SSL/TLS inspection)
Panorama (Centralized Management)- Expert proficiency in Panorama centralized firewall management and administration
- Experience managing Device Groups, Templates, and Template Stacks in Panorama
- Skilled in policy hierarchy management (Pre-rules, Post-rules, and Default rules)
- Proficient in Panorama log collection and log forwarding configurations
- Experience with Panorama High Availability setup and failover
- Ability to onboard and manage large-scale Palo Alto firewall deployments via Panorama
- Knowledge of Panorama Plugins (e.g., AWS, Azure cloud plugins)
- Proficient in Software/Content updates and version management through Panorama
- Experience with role-based administration and admin account management in Panorama
Global Protect VPN- Expert knowledge of GlobalProtect VPN architecture (Gateways, Portals, and Agents)
- Experience designing and deploying large-scale GlobalProtect remote access solutions
- Proficient in pre-logon, user-logon, and on-demand connect methods
- Strong understanding of HIP (Host Information Profile) checks and endpoint compliance enforcement
- Experience integrating GlobalProtect with SAML, LDAP, RADIUS, and MFA authentication
- Knowledge of split tunneling and traffic steering configurations
- Skilled in GlobalProtect Clientless VPN for web-based remote access
- Experience troubleshooting GlobalProtect agent connectivity and gateway selection issues
- Familiarity with GlobalProtect Cloud Service (GPCS) and Prisma Access integration
Infrastructure as Code (IaC) & Automation- Strong proficiency in AWS CDK for defining cloud infrastructure programmatically
- Expert in AWS CloudFormation template development, nested stacks, and custom resources
- Experience with LZA (Landing Zone Accelerator) configuration files and customization pipeline
- Skilled in CI/CD pipeline integration (AWS CodePipeline, CodeBuild, GitHub Actions) for IaC deployments
- Proficient in Python and/or TypeScript for CDK and automation scripting
- Experience with AWS Systems Manager (SSM) Parameter Store and Secrets Manager integration
- Knowledge of infrastructure drift detection and remediation strategies
- Familiarity with Terraform as an additional IaC tool (complementary skill)
Network Security Architecture- Ability to design Zero Trust network architectures in AWS multi-account environments
- Experience with centralized egress/ingress inspection architectures using GWLB and Palo Alto
- Strong understanding of network segmentation, micro-segmentation, and security zones
- Knowledge of AWS Security Hub, GuardDuty, and CloudTrail for security monitoring
- Experience with distributed vs. centralized firewall deployment models
- Understanding of compliance frameworks (NIST, FedRAMP, HIPAA, PCI-DSS) as applied to cloud networking
Monitoring & Troubleshooting- Proficient in AWS VPC Flow Logs analysis for network traffic visibility
- Experience with AWS CloudWatch metrics, alarms, and dashboards for network monitoring
- Skilled in using Palo Alto Traffic Logs, Threat Logs, and System Logs for incident analysis
- Ability to troubleshoot GWLB traffic flow issues including GENEVE encapsulation problems
- Experience with packet capture tools both in AWS (Traffic Mirroring) and on Linux hosts
- Familiarity with network performance benchmarking and latency analysis tools
Soft Skills & Collaboration- Ability to document complex network architectures using tools like Visio, Lucidchart, or Draw.io
- Experience working in Agile/Scrum environments with infrastructure teams
- Strong written and verbal communication skills for cross-functional collaboration
- Ability to conduct architecture reviews and provide technical guidance to junior staff
- Experience with ticketing systems (ServiceNow, Jira) for change management and incident tracking
Certifications Recommended:- AWS Certified Advanced Networking - Specialty
- AWS Certified Solutions Architect - Professional
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- Red Hat Certified Engineer (RHCE)
- AWS Certified Security - Specialty