Job Closed
This listing is no longer active.
TOMORROW HIRE is revolutionizing the staffing industry by integrating advanced AI technology with deep human expertise.
Cloud Network Security Architect
Location
District Of Columbia + 1 moreAll locations: District Of Columbia | Washington
Posted
72 days ago
Salary
$160K - $190K / year
Seniority
Entry Level
Job Description
Cloud Network Security Architect
TOMORROW HIRE
• Architect and manage complex AWS network environments to meet TIC 3.0 and federal security standards. • Deploy and manage Palo Alto VM-Series firewalls in AWS, including configuration of GlobalProtect, Panorama, and security policy orchestration. • Use Terraform or CloudFormation to deploy major networking components via Infrastructure as Code (IaC), ensuring repeatable, documented, and auditable environments. • Configure, troubleshoot, and maintain hybrid connectivity solutions, including AWS Direct Connect, Site-to-Site VPNs, and SD-WAN integrations. • Design and implement Transit Gateway architecture and VPC Peering in multi-account AWS environments. • Apply Zero Trust principles and TIC 3.0 requirements within AWS and Palo Alto ecosystems to enhance application and network security. • Serve as the primary (or sole) Network Architect/Engineer responsible for discovery, documentation, design, and execution of network security solutions with minimal supervision. • Collaborate with stakeholders to ensure secure, compliant network designs that support mission-critical federal applications.
Job Requirements
- 5+ years of experience architecting and managing complex AWS network environments
- 3+ years of experience deploying and managing Palo Alto VM-Series firewalls within a public cloud environment (AWS), including with Global Protect, Panorama, and security policy orchestration
- 2+ years of experience with Terraform or CloudFormation, including using IaC to deploy major networking components to ensure repeatable, documented environments
- Experience with Hybrid Connectivity and WAN, including configuring and troubleshooting AWS Direct Connect, Site-to-Site VPNs, and SD-WAN integrations to maintain hybrid-cloud connectivity
- Knowledge of Transit Gateway architecture and VPC Peering in multi-account environments
- Knowledge of implementing Zero Trust AND TIC 3 principles within an AWS or Palo Alto ecosystem
- Ability to function as the sole Network Architect or Engineer to be responsible for discovery, documentation, and execution with minimal supervision
- Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
- HS diploma or GED
- Preferred Qualifications**
- AWS Certified Advanced Networking – Specialty Certification
- Palo Alto Networks Certified Network Security Engineer (PCNSE) Certification
- Bachelors degree
- Active Secret clearance
Benefits
- Health, Vision, and Dental Insurance
- PTO
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Sales Specialist – Data & AI Security
Veeam SoftwareYour Single Backup and Data Management Platform for Cloud, Virtual and Physical
• Develop and execute a territory plan to drive repeatable revenue within assigned accounts. • Collaborate with account executives to identify and maximize cross-sell opportunities for Securiti AI solutions. • Lead the entire sales process, serving as a trusted advisor, and presenting compelling business cases to customers. • Manage a pipeline of high-value opportunities, ensuring accurate forecasting and CRM discipline. • Expand relationships with key channel partners and resellers to accelerate deal flow and market reach.
IT Security Engineer
Defense UnicornsWe help mission-focused heroes solve the world’s biggest software challenges.
• Serve as the primary point of contact for Tier 1 and Tier 2 user technical support requests, triaging issues and resolving or escalating as appropriate • Provision user laptops and administer a company-wide Mobile Device Management (MDM) solution • Manage inventory of physical and digital IT assets • Onboard and offboard users by managing access through Google Admin Console and related tools • Collaborate with third-party vendors and internal stakeholders to support rollout, troubleshooting, and updates of SaaS tools • Assist with Third Party Risk Management (TPRM) reviews, including security research and audit report reviews • Support technical implementation of security controls aligned with NIST SP 800-171, such as logging, SIEM, incident response, and configuration management • Assist with triage of security events, log audits, and incident response processes
• Baseline our control library mapped to SOC 2, PCI DSS, and key fintech obligations. • Implement lightweight evidence collection pipelines for top controls such as access reviews, backup tests, vulnerability management, and CI/CD change management. • Complete a security risk register refresh with likelihood and impact ratings, and publish a quarterly risk report. • Lead our next SOC 2 Type II audit cycle end‑to‑end, including auditor coordination, population requests, and walkthroughs. • Roll out a vendor risk management workflow integrated with procurement and Legal, including tiering, due diligence, and continuous monitoring. • Partner with Engineering to define secure SDLC checkpoints and automate evidence from GitHub, CI, and cloud. • Develop an AI/ML risk assessment framework covering model governance, training data privacy, and shadow AI usage across the organization. • Drive PCI DSS certification readiness, including SoA ownership, internal audits, and management review inputs. • Establish KPI/KRIs and dashboards for control effectiveness and risk trends consumed by execs and customers. • Mature incident response playbooks and conduct at least one cross‑functional tabletop with measurable improvements. • Establish AI governance policies and integrate AI risk into the existing risk register, vendor assessments, and compliance monitoring.
AI Security Engineer, IAM
Metsi TechnologiesGlobal Systems Integrator | Digital Maturity | Data Center Automation | Hybrid Multicloud | Anything-as-a-Service
• Manage processes and technologies to implement identity lifecycle operations for AI agents and service principals • Administer RBAC and ABAC policies • Manage credentials used by AI agents • Collaborate with product teams to capture use cases • Assist in investigations and incident response involving autonomous AI agents




