Cloud Network Security Engineer; Terraform
Listed on 2026-06-02
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security
Job Description
We are seeking a highly skilled Cloud Network Security Engineer to design, deploy, and operate Palo Alto Networks Next‑Generation Firewalls (NGFWs) across Microsoft Azure and Google Cloud Platform (GCP) environments.
This role will be hands‑on and delivery‑focused, supporting:
- Palo Alto firewall deployments using Terraform
- Migration of existing GCP mesh network topology to a hub‑and‑spoke architecture
- Standardization of cloud perimeter, egress, and inter‑VPC/VNet security controls
The engineer will work closely with Security Architecture, Cloud Platform, and Network Engineering teams to implement secure, scalable, and repeatable cloud network security patterns.
Key Responsibilities Palo Alto Firewall Deployment & Operations- Design and deploy Palo Alto NGFWs (VM-Series) in Azure and GCP (perimeter, shared services, and hub networks)
- Implement and manage firewall policies using App-, Threat Prevention, URL Filtering, and logging
- Support north‑south and east‑west traffic inspection use cases
- Integrate firewall logging with centralized SIEM platforms (e.g., Splunk)
- Develop and maintain Terraform modules for:
- Palo Alto firewall deployments
- Hub‑and‑spoke networking (VPCs/VNets, routing, NAT, load balancers)
- Security policy and rule standardization
- Follow Git‑based workflows (PRs, code reviews, versioning)
- Ensure repeatability, consistency, and automated deployments across environments
- Assist in migrating from GCP mesh VPC topology to a hub‑and‑spoke model
- Design and implement:
- Centralized ingress and egress VPCs
- Shared firewall hubs
- VPC peering / cloud routing strategies
- Minimize application downtime and reduce blast radius during migration
- Collaborate with architecture teams to implement approved cloud security patterns
- Support routing, NAT, load balancing, and high‑availability designs
- Implement secure connectivity between:
- Cloud‑to‑cloud (Azure and GCP)
- Cloud‑to‑on‑prem environments
- Participate in troubleshooting complex network and firewall issues
- Produce clear technical documentation:
- Terraform modules
- Firewall design diagrams
- Deployment and rollback procedures
- Support operational handoff to NOC/SOC teams
- Participate in change management and CAB processes
Pay Rate: $6-$10 an hour depending on skills and experience
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances.
If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy:
Required Qualifications Core Technical Skills
- 5+ years of experience in network security or cloud networking
- Hands‑on experience deploying Palo Alto Networks firewalls (VM-Series)
- Strong experience with Terraform in production environments
- Solid knowledge of GCP networking:
- VPCs, subnets, routing, firewall rules, NAT, load balancers
- Working experience with Azure networking:
- VNets, UDRs, Azure Load Balancer, Azure Firewall or NVA patterns
- Understanding of hub‑and‑spoke cloud architectures
- Strong TCP/IP, routing, and firewall fundamentals
- Experience with:
- North‑south and east‑west traffic control
- Centralized egress and ingress models
- Familiarity with logging, monitoring, and SIEM integrations
- Experience working with US‑based teams in a global/offshore model
- Ability to follow architecture standards and security patterns
- Strong documentation and verbal communication skills
- Palo Alto certifications (PCNSA, PCNSE)
- Experience with:
- GCP Shared VPCs
- Azure Landing Zones
- Exposure to Zero Trust or segmentation concepts
- Experience supporting large‑scale cloud migrations
- Familiarity with CI/CD pipelines for Terraform
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).