The Role
Build, automate, and maintain secure multi-cloud network infrastructure using Terraform. Deploy and autoscale Palo Alto VM-Series firewalls, standardize AWS and Azure networking, enforce security policies, implement compliance-as-code and automated remediation, and create guardrails with SCPs and IAM boundaries. Perform Tier-3 troubleshooting using packet analysis and cloud observability tools, document network standards and procedures, and mentor teammates on infrastructure-as-code practices.
Summary Generated by Built In
Role Purpose
==============
We are seeking a Senior Cloud Network Engineer to build, automate, and maintain secure network infrastructure. This is a high-execution role focused on "Infrastructure as Code." You will be responsible for the actual delivery and lifecycle of cloud networking and security components using Terraform.
Key Responsibilities
=============
Responsibilities include, but are not limited to:
Write and Maintain Production-Grade IaC: Develop and maintain modular Terraform code to manage the entire networking lifecycle, including cloud-native constructs (VPCs/VNets, TGW, DirectConnect/ExpressRoute, Route Tables, NACLs/NSGs/SGs) and third-party appliance deployment.
Palo Alto VM-Series Automation: Hands-on responsibility for the automated bootstrapping and deployment of VM-Series firewalls (managing init-cfg, licenses, and software versions via S3/Azure Storage).
Autoscaling & Resilience: Implement and manage Auto Scaling Groups (AWS) or Scale Sets (Azure) for firewalls, including integration with Gateway Load Balancer (GWLB) and managing lifecycle hooks.
Multi-Cloud Expansion: Standardize networking patterns across AWS/Azure, with the opportunity to apply these skills to GCP, OCI, and Ali Cloud environments.
Automated Policy Enforcement: Use cloud native tooling (AWS Firewall Manager/Azure Policy/Security Center) to centrally manage and enforce network security policies across all accounts and VPCs/VNets, ensuring consistent security group rules and WAF configurations.
Compliance-as-Code & Monitoring: Implement and manage AWS Config Rules and Custom Lambda Checks to continuously monitor network state. You will be responsible for building automated remediation for non-compliant resources (e.g., auto-applying default SG to ALBs).
Guardrail Implementation: Develop and deploy Service Control Policies (SCPs) and IAM boundaries to prevent "shadow networking" and ensure all deployments adhere to the organizational security baseline.
Documentation: Create and maintain detailed network documentation, including topology diagrams, configuration standards, and operational procedures.
Tier-3 Forensic Troubleshooting: Act as the final escalation point for complex cloud/hybrid network failures. You must be able to perform deep-packet analysis (TCPDump/Wireshark) and use cloud-native observability (Flow Logs, Reachability Analyzer) to conduct data-driven Root Cause Analysis (RCA).
Person Specification/Requirements
Education & Experience
8+ Years Engineering: Must have a background in heavy-duty network engineering, with the last 3+ years dedicated to writing IaC (Terraform/HCL).
Technical Skills
Strong Terraform/IaC proficiency: Ability to write reusable, dry, and version-controlled modules. Deep understanding of state management and providers.
Automated Firewall Specialist: Proven experience bootstrapping virtual appliances and managing stateful firewall clusters in an autoscaling environment.
Python/Scripting: Proficiency in Python for interacting with Cloud APIs (Boto3) and automating tasks that IaC cannot handle alone.
Cloud Fluency: Deep expertise in AWS and Azure; experience with GCP, OCI, or Ali Cloud is a significant plus.
Version Control Proficiency: Comfortable using Git for daily work. You should understand how to manage your own branches, commit clean code, and participate in the Pull Request (PR) process for peer reviews.
Collaborative Automation: Experience working in a team environment where network changes are tracked in a repository rather than performed manually in a console.
Compliance Tooling: Hands-on experience with AWS Config, AWS Firewall Manager, and AWS Security Hub (or Azure equivalents like Azure Policy and Microsoft Defender for Cloud).
Automated Remediation: Ability to write Python/Lambda functions or use Systems Manager (SSM) documents to automatically fix out-of-compliance network resources.
Policy Auditing: Experience translating regulatory requirements (e.g., NIST) into automated technical checks within a cloud environment.
Soft Skills
Automate-First Mindset: A strong aversion to manual "point-and-click" configuration (ClickOps). You naturally look for ways to turn repetitive tasks into code.
Engineering Rigor: A disciplined approach to changes. You believe that if a change isn't in Git, it didn't happen. You value peer code reviews and understand that "done" includes testing and documentation.
Operational Empathy: You write code and documentation that your future self (and your teammates) can understand at 3:00 AM during a production incident.
Pragmatic Problem Solving: The ability to balance "perfect" automation with the immediate needs of the business, knowing when to build a robust module versus a quick remediation script.
Collaborative Mindset: Willingness to mentor others in IaC best practices and participate in a "blameless" post-mortem culture when automation fails.
Certifications (Preferred)
AWS Certified Advanced Networking – Specialty
Azure Network Engineer Associate
Google Professional Cloud Network Engineer
OCI Cloud Operations Associate
ACP Cloud Networking
CCNP/CCIE
Palo Alto Network Security Professional
Terraform Associate
Skills Required
- 8+ years of engineering experience with a strong network engineering background
- At least 3 years writing infrastructure as code with Terraform and HCL
- Strong proficiency writing reusable, version-controlled Terraform modules and managing state and providers
- Experience automating virtual firewall appliance bootstrapping and stateful firewall clusters in autoscaling environments
- Proficiency in Python and Boto3 for cloud API automation
- Deep expertise in AWS and Azure
- Experience with Git, branching, clean commits, pull requests, and peer reviews
- Experience managing network changes through collaborative repository-based automation
- Hands-on experience with AWS Config, AWS Firewall Manager, AWS Security Hub, or Azure equivalents
- Ability to write Python or Lambda remediation functions or use AWS Systems Manager documents
- Experience translating regulatory requirements such as NIST into automated cloud technical checks
- AWS Certified Advanced Networking Specialty
- Azure Network Engineer Associate certification
- Google Professional Cloud Network Engineer certification
- OCI Cloud Operations Associate certification
- ACP Cloud Networking certification
- CCNP or CCIE certification
- Palo Alto Network Security Professional certification
- Terraform Associate certification
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Anblicks is a Cloud Data Analytics Company based out of Dallas, TX, with offices in USA, India, and Australia. Since 2004, Anblicks has been helping customers by bringing value to their data and implementing modern data architecture and advanced analytics solutions in the cloud.









