Cloud Firewall Architect (Hybrid – Downey, CA)
Epitec is seeking an experienced Cloud Firewall Architect to support a large-scale enterprise network security environment. This is an excellent opportunity for a highly skilled cloud and network security professional with deep expertise in Palo Alto Networks technologies, cloud security architectures, and enterprise firewall strategy.
This role requires a candidate who can quickly contribute with minimal acclimation while designing, implementing, and optimizing secure cloud connectivity and firewall solutions across complex hybrid environments.
Location
- Hybrid
- Downey, CA (9150 E. Imperial Hwy., Downey, CA 90242)
Employment Details
- Contract Assignment
- Target Start Date: October 19, 2026
- Target End Date: October 18, 2027
- Schedule: Full-Time, 40 hours per week
- Travel Required: No
Key Responsibilities
- Architect and implement cloud firewall and network security solutions across multi-cloud environments.
- Design and optimize Palo Alto Networks security platforms, including physical appliances, VM-Series firewalls, Panorama, Device Groups, Templates, Template Stacks, and Strata Cloud Manager (SCM).
- Develop and maintain firewall security policies, access controls, network segmentation strategies, and security best practices.
- Lead enterprise firewall modernization and migration initiatives from legacy security platforms.
- Design cloud traffic inspection architectures utilizing AWS Gateway Load Balancer (GWLB), AWS Transit Gateway (TGW), security VPCs, Azure hub-and-spoke environments, NVAs, and User-Defined Routing (UDR).
- Support hybrid connectivity solutions using dynamic routing protocols including BGP and private cloud interconnect technologies.
- Collaborate with infrastructure, cloud, and security teams to ensure highly available, scalable, and compliant network security architectures.
- Implement automation and Infrastructure as Code (IaC) practices to improve operational efficiency and consistency.
Required Qualifications
Certifications
- Palo Alto Networks Certified Network Security Engineer (PCNSE) certification is required.
Technical Expertise
- Advanced knowledge of Palo Alto Networks security platforms.
- Advanced knowledge of Next-Generation Firewall (NGFW) technologies and security concepts.
- Advanced knowledge of enterprise firewall technologies and migration methodologies.
- Advanced knowledge of cloud network security architectures across:
- Amazon Web Services (AWS)
- Microsoft Azure
- Google Cloud Platform (GCP)
- Oracle Cloud Infrastructure (OCI)
- Advanced understanding of firewall policy management, access controls, rule optimization, and network segmentation.
- Strong knowledge of routing, switching, network services, and security technologies.
- Strong knowledge of network security monitoring and threat analysis.
- Strong understanding of high-availability and fault-tolerant security architectures.
- Experience with security content management, firewall software administration, and private network interconnects.
- Knowledge of security automation and Infrastructure as Code (IaC) methodologies.
Experience
- 5+ years of experience with Palo Alto Networks firewalls, VM-Series, Panorama, Device Groups, Templates, Template Stacks, and Strata Cloud Manager (or comparable platforms).
- 5+ years of experience with NGFW technologies including:
- IPS
- App-ID
- User-ID
- URL Filtering
- Content Filtering
- SSL/TLS Inspection
- 3+ years of cloud network security experience across AWS, Azure, GCP, and OCI.
- 5+ years designing and supporting cloud traffic inspection architectures utilizing GWLB, TGW, security VPCs, Azure hub-and-spoke designs, NVAs, and UDR.
- 4+ years deploying and operating cloud-based firewalls, virtual appliances, and native cloud security controls.
- 5+ years implementing hybrid connectivity solutions using BGP, AWS Transit Gateway, Azure ExpressRoute, or equivalent technologies.
#INDPRO
#LI-NS2
