Cloud Network and security Engineer
Job Summary:
A Cloud Network and Security Engineer plays a critical role in the creation, execution, and administration of cloud-based network systems, ensuring seamless integration of essential components such as virtual machines (VMs), load balancers, and networking elements. At Lawrence, our operations involve close collaboration with primary Cloud Service Providers, including AWS, Azure, and Google Cloud Platform (GCP).
We are in search of a competent Network and Security Engineer with proven expertise in any one of these CSPs (AWS, Azure, or GCP) and significant hands-on experience managing Palo Alto Firewalls. In this role, you will have the responsibility to design, implement, and sustain network infrastructures that guarantee optimal performance and high availability. Additionally, you will oversee the deployment and ongoing maintenance of services, while also managing network firewalls and their routing to ensure robust security and efficiency.
Responsibilities:
· Design, implement, and manage advanced network architectures using cloud network resources such as Virtual WAN, Transit Gateway, and Cloud WAN technologies.
· Configure and manage peering to ensure secure and efficient inter-network communication.
· Develop and maintain routing strategies to optimize network performance and reliability, leveraging VPC/VNET route tables.
· Implement and manage VPN connections to securely connect on-premises networks to cloud environments.
· Configure and manage network load balancers to ensure efficient traffic distribution and security.
· Design and implement hybrid connectivity solutions using Virtual WAN, integrating on-premises networks with cloud environments for seamless connectivity and performance.
· Monitor network performance and troubleshoot connectivity issues using network monitoring tools and solutions.
· Collaborate with cross-functional teams to design and implement hybrid cloud solutions, integrating on-premises networks with cloud environments.
· Configure and manage virtual networks, load balancers, and VPNs using Azure Virtual Network, AWS VPC, and tools like Palo Alto Networks for enhanced security.
· Configure and manage VPC/VNet peering to ensure secure and efficient inter-network communication.
· Ensure network security and compliance by implementing security groups, network access control lists (NACLs), and firewalls.
· Stay updated with the latest networking technologies and best practices to continuously improve network infrastructure.
Ideal Candidate Profile:
- Quality of Service: Takes pride in the quality of service delivered, recognizing the human element in technical problems.
- Organizational Skills: Exhibits excellent organizational skills with a logical approach to problem-solving.
- Network Implementation: Able to interpret network design documentation and implement the described solutions, including advanced network architectures using cloud networking technologies
- Knowledge Documentation: Capable of concisely capturing and documenting knowledge.
- Communication Skills: Confidently able to explain technical concepts to non-technical people.
- Incident Management: Calm and methodical in dealing with all incidents, particularly major incidents that impact services.
- Resourcefulness: Resourceful in approach while adhering to set procedures.
- Best Practices: Embraces a culture of best practices, process, compliance, and continuous improvement.
- Security Awareness: Exercises sound judgment in identifying and dealing with security incidents.
- Team Collaboration: Holds a proven track record of success in contributing to a team-oriented environment, collaborating across disciplines.
- Managed Services Experience: Has recent experience working in a Managed Services (public or hybrid cloud) or Hosting Provider environment.
- Technical Certifications: Holds current high-level technical certifications, particularly in Public Cloud (e.g., Azure, AWS, or GCP), and takes ownership of their own career development.
- Design Review: Confident in reviewing and changing designs to meet business requirements and governance when necessary.
- Network Management: Skilled in configuring and managing network components to ensure efficient traffic distribution and security.
- Hybrid Connectivity: Experienced in designing and implementing hybrid connectivity solutions, integrating on-premises networks with cloud environments for seamless connectivity and performance.
- Firewall Expertise: Proficient in configuring and managing firewalls to secure network infrastructure and ensure compliance with security policies.
Cloud Networking: Comprehensive understanding of cloud networking principles and practices, with hands-on experience in at least one major cloud service provider (e.g., Azure, AWS, or GCP).
Qualifications Required:
- 7 to 10 years of experience in Information technology and preferred active Cloud experience.
- Experience with using a broad range of Azure, AWS, and GCP network services, including Public IPs, Load Balancers, Virtual Networks, VPCs, GWLB, routable peering, VWAN, VPN gateways, cloud routers, and Palo Alto NGFW.
- Experience in Palo Alto firewall implementation in cloud environments and its configuration.
- Knowledge of Cloud Security best practices.
- Strong cloud knowledge in at least one of the major CSPs (Azure, AWS, or GCP).
- Infrastructure and Application monitoring across production and non-production platforms
- Working on Public clouds and working closely with the security team.
- Knowledge on hybrid public cloud design concepts
- Very good understanding of Cloud IaaS, PaaS services
- Good understanding of High Availability and Disaster Recovery concepts for infrastructure
- Familiarity with monitoring tools
- Problem Solving: Ability to analyze and resolve complex infrastructure resource and application deployment issues.
- Experience with Windows and Linux system
- Excellent communication skills, understanding customer needs, negotiations skills, Vendor management skills, people and managements.
Desired:
- Certified Cloud Solution Architect (Azure, AWS, or GCP).
- Experience in implementing various architectural designs and driving projects.
- Exposure to API architecture and development.
- Knowledge of Palo Alto firewalls or any standard security firewalls, including Check Point and FortiGate.