Cloud Engineer - Network

Subway

Shelton (CT)

On-site

USD 140,000 - 190,000

Full time

15 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Insurance Plans (Medical, Life)
Pension/401K/RSP
Competitive Bonus
Mobility Allowance
Tuition Reimbursement
Company Holidays
Volunteering time

Job summary

Subway is seeking a Cloud Engineer, Network to design, implement, and support enterprise network and cloud connectivity across on-premises, multi-cloud, and hybrid environments. This role is critical as Subway shifts network operations in-house, requiring hands-on expertise with next‑gen firewalls, SD‑WAN, cloud networking, and infrastructure automation.

You'll architect secure connectivity across Azure and AWS, build Terraform modules, and collaborate with Cloud Engineering, Cyber Security, and

Qualifications

  • Extensive enterprise network engineering experience (7–10 years).
  • Strong hands-on with PAN-OS, Panorama, and GlobalProtect VPN.
  • Production experience with Silver Peak / Aruba EdgeConnect SD-WAN.
  • Proficient in Juniper (Junos) and/or Cisco IOS-XE/NX-OS routing/switching.
  • Deep Azure networking and AWS VPC/Transit Gateway know-how.
  • Terraform module development for IaC and CI/CD integration.
  • Familiar with SAML, RADIUS, MFA, and identity-aware access policies.
  • Knowledge of BGP, OSPF, IPsec, NAT, QoS, and VLANs.

Responsibilities

  • Design, deploy, and secure enterprise network infrastructure and cloud connectivity.
  • Manage and optimize SD-WAN across distributed sites.
  • Architect cloud networking across Azure and AWS with secure policy enforcement.
  • Build Terraform modules for network provisioning and reduce drift.
  • Integrate AI-driven tools for monitoring and remediation.
  • Lead change management for firewall, VPN, wireless, and LAN/WAN changes.
  • Collaborate with Cloud Security and Infra teams on segmentation and disaster recovery.
  • Maintain network docs, topology diagrams, and SOPs.

Skills

Palo Alto Firewalls
GlobalProtect VPN
SD-WAN
Azure networking
AWS networking
Terraform
SAML/RADIUS/MFA
BGP/OSPF
Zero-trust / microsegmentation

Tools

Terraform
Ansible
Python scripting
Junos/Cisco IOS

Job description

Why Join Subway?

At Subway, we are not standing still. We are building.

Cloud Engineer, Network

Franchise World Headquarters, LLC

Why Join Subway?

At Subway, we are not standing still. We are building. This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact. You will not just do the work. You will shape it. We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world. If you bring energy, accountability and a bias for action, you will fit right in. We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day. This is your chance to be part of what's next.

Position Overview

We are seeking a Cloud Engineer, Network to design, implement, and support enterprise network and cloud connectivity infrastructure across on-premises, multi-cloud, and hybrid environments. This role is critical as Subway transitions network operations from managed services to an in-house engineering team, requiring deep hands-on expertise across next-generation firewalls, SD-WAN, cloud networking architectures, and infrastructure automation. This is a key build-out hire that directly enables a stronger, more responsive in-house network engineering capability.

Responsibilities
  • Design, deploy, and maintain enterprise network security infrastructure using Palo Alto Networks (PAN-OS, Panorama); administer and troubleshoot GlobalProtect VPN including portal/gateway configuration, authentication flows, certificates, HIP checks, and user access issues.
  • Manage and optimize Silver Peak (Aruba EdgeConnect) SD-WAN infrastructure across distributed sites, including overlay design, path conditioning, and QoS; design, configure, and support enterprise routing, switching, wireless, and campus/data center network infrastructure using Juniper, including Juniper Mist Wireless management, RF optimization, and AIOps-assisted diagnostics.
  • Architect and support cloud networking across Azure (VNets, VNet Peering, Azure Firewall, ExpressRoute, VPN Gateways) and AWS (Transit Gateway, VPC design, Direct Connect, VPN connections); design and manage ACLs and security group policies across cloud and on-premises environments to enforce least-privilege network access.
  • Build and maintain Terraform modules for network provisioning, driving Infrastructure-as-Code adoption across the network estate and reducing manual configuration drift; implement and manage microsegmentation strategies to enforce zero-trust principles and reduce lateral movement risk.
  • Evaluate and integrate AI-driven tools for network monitoring, anomaly detection, and operational efficiency; support identity and authentication integrations including SAML, RADIUS, MFA, certificate-based authentication, and identity-aware access policies for VPN, wireless, and network access control use cases.
  • Execute formal change management practices for firewall, SD-WAN, VPN, wireless, and LAN/WAN changes – including risk assessment, implementation planning, validation, rollback planning, and post-change documentation; serve as an escalation point for complex network incidents, performing root-cause analysis and driving remediation.
  • Monitor platform health and performance using observability platforms; analyze firewall traffic, review VPN usage, validate SD-WAN path health, and troubleshoot wireless performance proactively.
  • Partner with Cloud Engineering, Cyber Security, and Infrastructure Architecture teams on network segmentation, secure connectivity, and disaster recovery design; develop and maintain network documentation, topology diagrams, and standard operating procedures; participate in on-call rotation for critical network incidents.
Qualifications
  • 7-10 years of enterprise network engineering experience.
  • Hands-on expertise administering Palo Alto Networks firewalls (PAN-OS, Panorama) and supporting enterprise GlobalProtect VPN environments, including user troubleshooting, authentication, certificates, and security policy enforcement.
  • Production experience with Silver Peak / Aruba EdgeConnect SD-WAN.
  • Hands-on expertise with enterprise routing and switching using Juniper (Junos) and/or Cisco (IOS, IOS-XE, NX-OS); experience operating Juniper Mist Wireless environments including WLAN configuration, RF/client troubleshooting, and AIOps-assisted diagnostics.
  • Strong working knowledge of Azure networking (VNets, Gateways, ExpressRoute, NSGs) and AWS networking (Transit Gateway, VPCs, VPNs, Direct Connect).
  • Demonstrated hands-on experience building and maintaining Terraform modules for network infrastructure, including state management, module design, and CI/CD-integrated provisioning.
  • Working knowledge of AI-driven network tools (AIOps, anomaly detection, automated remediation) and interest in applying AI to network operations.
  • Experience with SAML, RADIUS, MFA, certificate-based authentication, and identity-aware access policies.
  • Strong understanding of BGP, OSPF, IPsec VPN, NAT, QoS, VLANs, STP, route redistribution, failover, and traffic engineering.
  • Experience troubleshooting complex, multi-site network and connectivity issues.
Preferred Qualifications
  • Microsegmentation experience with platforms such as Guardicore/Akamai Guardicore, Illumio, or similar.
  • Relevant certifications: PCNSE/PCCET, JNCIS-ENT/JNCIP-ENT, Juniper Mist AI, CCNP Enterprise, Aruba EdgeConnect/Silver Peak, AWS Advanced Networking Specialty, Azure Network Engineer Associate, or HashiCorp Terraform Associate.
  • Experience with additional automation tooling such as Ansible or Python scripting.
  • Familiarity with SASE and zero-trust network architectures.
  • Prior experience transitioning managed or outsourced network functions to an in-house engineering team.
What do we offer?
  • Insurance Plans (Medical, Life)
  • Pension/401K/RSP (country specific)
  • Competitive Bonus
  • Mobility Allowance
  • Tuition Reimbursement
  • Company Holidays
  • Volunteering time
  • And More…
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Engineer - Network
Cloud Engineer - Network

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 120,000 - 180,000
Insurance Plans
Pension/401K/RSP
Competitive Bonus
+4
Cloud Engineer - Network
Cloud Engineer - Network

Pho Prime, LLC • Shelton (CT)

On-site
USD 110,000 - 165,000
Mobility Allowance
Cloud Engineer - Network (AWS & Azure)
Cloud Engineer - Network (AWS & Azure)

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 138,000 - 173,000
Insurance Plans (Medical, Life)
Pension/401K/RSP (country specific)
Competitive Bonus
+4
Director, Network
Director, Network

Franchise World Headquarters, LLC • Shelton (CT)

On-site
USD 130,000 - 180,000
Insurance Plans (Medical, Life)
Pension/401K/RSP (country specific)
Competitive Bonus
+4
Senior Network Engineer
Senior Network Engineer

Domino's • Ann Arbor (MI)

Hybrid
USD 120,000 - 160,000
Medical, Dental & Vision benefits
401k matching
Paid holidays and vacation
+3
Staff Network Engineer
Staff Network Engineer

GEICO • Seattle (WA)

Hybrid
USD 100,000 - 130,000
Director of Network
Director of Network

Subway • Shelton (CT)

On-site
USD 184,000 - 231,000
Pension/401K/RSP
Competitive Bonus
Tuition Reimbursement
+2
Network Engineer 2
Network Engineer 2

Condé Nast • New York (NY)

Hybrid
USD 120,000 - 180,000
Hybrid work schedule
Senior Cloud Network Engineer (SD-WAN & Security)
Senior Cloud Network Engineer (SD-WAN & Security)

Subway • Shelton (CT)

On-site
USD 140,000 - 190,000
Insurance Plans (Medical, Life)
Pension/401K/RSP
Competitive Bonus
+4
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 154,000 - 250,000