Cloud Firewall Architect

  • Location: Downey, California
  • Type: Contract
  • Job #106486

Cloud Firewall Architect (Hybrid – Downey, CA)

Epitec is seeking an experienced Cloud Firewall Architect to support a large-scale enterprise network security environment. This is an excellent opportunity for a highly skilled cloud and network security professional with deep expertise in Palo Alto Networks technologies, cloud security architectures, and enterprise firewall strategy.
This role requires a candidate who can quickly contribute with minimal acclimation while designing, implementing, and optimizing secure cloud connectivity and firewall solutions across complex hybrid environments.

Location

  • Hybrid
  • Downey, CA (9150 E. Imperial Hwy., Downey, CA 90242)

Employment Details

  • Contract Assignment
  • Target Start Date: October 19, 2026
  • Target End Date: October 18, 2027
  • Schedule: Full-Time, 40 hours per week
  • Travel Required: No

Key Responsibilities

  • Architect and implement cloud firewall and network security solutions across multi-cloud environments.
  • Design and optimize Palo Alto Networks security platforms, including physical appliances, VM-Series firewalls, Panorama, Device Groups, Templates, Template Stacks, and Strata Cloud Manager (SCM).
  • Develop and maintain firewall security policies, access controls, network segmentation strategies, and security best practices.
  • Lead enterprise firewall modernization and migration initiatives from legacy security platforms.
  • Design cloud traffic inspection architectures utilizing AWS Gateway Load Balancer (GWLB), AWS Transit Gateway (TGW), security VPCs, Azure hub-and-spoke environments, NVAs, and User-Defined Routing (UDR).
  • Support hybrid connectivity solutions using dynamic routing protocols including BGP and private cloud interconnect technologies.
  • Collaborate with infrastructure, cloud, and security teams to ensure highly available, scalable, and compliant network security architectures.
  • Implement automation and Infrastructure as Code (IaC) practices to improve operational efficiency and consistency.

Required Qualifications

Certifications

  • Palo Alto Networks Certified Network Security Engineer (PCNSE) certification is required.

Technical Expertise

  • Advanced knowledge of Palo Alto Networks security platforms.
  • Advanced knowledge of Next-Generation Firewall (NGFW) technologies and security concepts.
  • Advanced knowledge of enterprise firewall technologies and migration methodologies.
  • Advanced knowledge of cloud network security architectures across:
    • Amazon Web Services (AWS)
    • Microsoft Azure
    • Google Cloud Platform (GCP)
    • Oracle Cloud Infrastructure (OCI)
  • Advanced understanding of firewall policy management, access controls, rule optimization, and network segmentation.
  • Strong knowledge of routing, switching, network services, and security technologies.
  • Strong knowledge of network security monitoring and threat analysis.
  • Strong understanding of high-availability and fault-tolerant security architectures.
  • Experience with security content management, firewall software administration, and private network interconnects.
  • Knowledge of security automation and Infrastructure as Code (IaC) methodologies.

Experience

  • 5+ years of experience with Palo Alto Networks firewalls, VM-Series, Panorama, Device Groups, Templates, Template Stacks, and Strata Cloud Manager (or comparable platforms).
  • 5+ years of experience with NGFW technologies including:
    • IPS
    • App-ID
    • User-ID
    • URL Filtering
    • Content Filtering
    • SSL/TLS Inspection
  • 3+ years of cloud network security experience across AWS, Azure, GCP, and OCI.
  • 5+ years designing and supporting cloud traffic inspection architectures utilizing GWLB, TGW, security VPCs, Azure hub-and-spoke designs, NVAs, and UDR.
  • 4+ years deploying and operating cloud-based firewalls, virtual appliances, and native cloud security controls.
  • 5+ years implementing hybrid connectivity solutions using BGP, AWS Transit Gateway, Azure ExpressRoute, or equivalent technologies.

#INDPRO
#LI-NS2

Scroll to Top