Cloud Network Security Engineer (Terraform)

Insight Global

Atlanta (GA)

On-site

USD 8,265 - 13,776

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Insight Global is seeking a skilled Cloud Network Security Engineer to design, deploy, and manage Palo Alto Networks firewalls across Microsoft Azure and GCP environments. You will support various network security projects including the migration of GCP mesh topology and work closely with architecture and engineering teams to implement secure cloud networking solutions.

The ideal candidate has extensive experience with network security, Terraform, and cloud architectures. This role offers an opportunity to shape and enhance cloud security practices.

Qualifications

  • 5+ years of experience in network security or cloud networking.
  • Hands-on experience deploying Palo Alto Networks firewalls (VM-Series).
  • Strong experience with Terraform in production environments.
  • Solid knowledge of GCP networking: VPCs, subnets, routing, firewall rules.
  • Working experience with Azure networking: VNets, Azure Load Balancer.

Responsibilities

  • Design and deploy Palo Alto NGFWs in Azure and GCP.
  • Implement and manage firewall policies using App-ID and Threat Prevention.
  • Develop and maintain Terraform modules for firewall deployments.
  • Assist in migrating from GCP mesh VPC topology to a hub-and-spoke model.
  • Produce clear technical documentation for Terraform modules and firewall design.

Skills

Network security experience
Palo Alto Networks firewalls deployment
Terraform expertise
GCP networking knowledge
Azure networking experience
TCP/IP and routing fundamentals
Collaboration and communication skills

Tools

Palo Alto Networks
Terraform
Google Cloud Platform (GCP)
Microsoft Azure

Job description

Job Description

We are seeking a highly skilled Cloud Network Security Engineer to design, deploy, and operate Palo Alto Networks Next‑Generation Firewalls (NGFWs) across Microsoft Azure and Google Cloud Platform (GCP) environments.

This role will be hands‑on and delivery‑focused, supporting:

  • Palo Alto firewall deployments using Terraform
  • Migration of existing GCP mesh network topology to a hub‑and‑spoke architecture
  • Standardization of cloud perimeter, egress, and inter‑VPC/VNet security controls

The engineer will work closely with Security Architecture, Cloud Platform, and Network Engineering teams to implement secure, scalable, and repeatable cloud network security patterns.

Key Responsibilities
Palo Alto Firewall Deployment & Operations
  • Design and deploy Palo Alto NGFWs (VM-Series) in Azure and GCP (perimeter, shared services, and hub networks)
  • Implement and manage firewall policies using App-ID, Threat Prevention, URL Filtering, and logging
  • Support north‑south and east‑west traffic inspection use cases
  • Integrate firewall logging with centralized SIEM platforms (e.g., Splunk)
Terraform & Infrastructure as Code
  • Develop and maintain Terraform modules for:
    • Palo Alto firewall deployments
    • Hub‑and‑spoke networking (VPCs/VNets, routing, NAT, load balancers)
    • Security policy and rule standardization
  • Follow Git‑based workflows (PRs, code reviews, versioning)
  • Ensure repeatability, consistency, and automated deployments across environments
GCP Network Topology Migration
  • Assist in migrating from GCP mesh VPC topology to a hub‑and‑spoke model
  • Design and implement:
    • Centralized ingress and egress VPCs
    • Shared firewall hubs
    • VPC peering / cloud routing strategies
  • Minimize application downtime and reduce blast radius during migration
Cloud Networking & Security Integration
  • Collaborate with architecture teams to implement approved cloud security patterns
  • Support routing, NAT, load balancing, and high‑availability designs
  • Implement secure connectivity between:
    • Cloud‑to‑cloud (Azure and GCP)
    • Cloud‑to‑on‑prem environments
  • Participate in troubleshooting complex network and firewall issues
Documentation & Operational Readiness
  • Produce clear technical documentation:
    • Terraform modules
    • Firewall design diagrams
    • Deployment and rollback procedures
  • Support operational handoff to NOC/SOC teams
  • Participate in change management and CAB processes

Pay Rate: $6-$10 an hour depending on skills and experience

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com. To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Skills and Requirements
Required Qualifications
Core Technical Skills
  • 5+ years of experience in network security or cloud networking
  • Hands‑on experience deploying Palo Alto Networks firewalls (VM-Series)
  • Strong experience with Terraform in production environments
  • Solid knowledge of GCP networking:
    • VPCs, subnets, routing, firewall rules, NAT, load balancers
  • Working experience with Azure networking:
    • VNets, UDRs, Azure Load Balancer, Azure Firewall or NVA patterns
  • Understanding of hub‑and‑spoke cloud architectures
Security & Networking Fundamentals
  • Strong TCP/IP, routing, and firewall fundamentals
  • Experience with:
    • North‑south and east‑west traffic control
    • Centralized egress and ingress models
  • Familiarity with logging, monitoring, and SIEM integrations
Collaboration & Communication
  • Experience working with US‑based teams in a global/offshore model
  • Ability to follow architecture standards and security patterns
  • Strong documentation and verbal communication skills
Comfortable working in Agile or sprint‑based delivery model
  • Palo Alto certifications (PCNSA, PCNSE)
  • Experience with:
    • GCP Shared VPCs
    • Azure Landing Zones
    • Exposure to Zero Trust or segmentation concepts
    • Experience supporting large‑scale cloud migrations
    • Familiarity with CI/CD pipelines for Terraform
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Terraform Cloud Network Security Engineer - Azure & GCP
Terraform Cloud Network Security Engineer - Azure & GCP

Insight Global • Atlanta (GA)

On-site
USD 8,265 - 13,776
Network Security Engineer, Tech Lead
Network Security Engineer, Tech Lead

Jobtailor • Town of Texas (WI)

On-site
USD 120,000 - 160,000
SOSC-Network Engineer - Consultant - Palo Alto Cloud Engineer - 12762
SOSC-Network Engineer - Consultant - Palo Alto Cloud Engineer - 12762

RICEFW Technologies Inc • Columbia (SC)

Hybrid
USD 120,000 - 180,000
Cloud Engineer – Contract
Cloud Engineer – Contract

Jobtailor • Columbia (SC)

On-site
USD 140,000 - 190,000
Network Security Cloud Engineer
Network Security Cloud Engineer

Fixity Technologies • Phoenix (AZ)

On-site
USD 130,000 - 190,000
Staff Network Engineer
Staff Network Engineer

GEICO • Seattle (WA)

Hybrid
USD 100,000 - 130,000
Network Security Engineer II
Network Security Engineer II

Jobtailor • San Antonio (TX)

On-site
USD 85,000 - 125,000
Sr Network Security Engineer
Sr Network Security Engineer

Worldpac • Flower Mound (TX)

On-site
USD 76,000 - 101,000
Senior Security Engineer
Senior Security Engineer

MDS is now part of Secur-Serv • Dallas (TX)

On-site
USD 120,000 - 140,000
Sr. Firewall/Network Security Administrator
Sr. Firewall/Network Security Administrator

Calance • Tallapoosa (GA)

Hybrid
USD 90,000 - 130,000
EPO/PPO Medical Plans
401K Retirement vesting program
Flex Spending Plan
+1