AWS Cloud Firewall SME
Job in
McLean, Fairfax County, Virginia, USA
Listed on 2026-01-12
Listing for:
Ampcus Incorporated
Full Time
position Listed on 2026-01-12
Job specializations:
-
IT/Tech
Cybersecurity, Network Security, Systems Engineer, Cloud Computing
Job Description & How to Apply Below
Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.
Job Title: AWS Cloud Firewall SME.
Location: McLean, VA.
Job Description:
- Need an AWS Cloud Firewall Subject Matter Expert (SME) focused on the architecture, implementation, and central management of network security across cloud environments.
- Security Architecture & Design:
Design and implement secure AWS network topologies, including VPC design, routing, and hybrid connectivity (VPN, Direct Connect). - Centralized Firewall Management:
Act as the primary expert for AWS Firewall Manager to centrally configure and manage rules for AWS WAF, AWS Network Firewall, Shield Advanced, and Security Groups across multiple accounts. - Policy Implementation:
Maintain and optimize rules for AWS Network Firewall and third-party firewalls (e.g., Palo Alto, Fortinet) to control ingress/egress traffic. - Automation (Dev Sec Ops ):
Develop and manage Infrastructure as Code (IaC) templates using Terraform or Cloud Formation to automate firewall deployments and security governance policies. - Compliance & Auditing:
Enforce network security standards and compliance frameworks (e.g., NIST, CIS, PCI-DSS) by conducting periodic firewall rule audits and access reviews. - Incident Support:
Act as an SME during network-related security incidents, supporting SOC teams with packet analysis, firewall log investigation, and immediate containment actions.
- AWS Security Services:
Deep expertise in AWS Network Firewall, Firewall Manager, WAF, Security Groups, NACLs, and AWS Shield. - Cloud Networking:
Advanced knowledge of VPCs, Transit Gateway, Route 53 Resolver DNS Firewall, and Private Link. - Third-Party Expertise:
Experience with enterprise firewall platforms like Palo Alto Networks, Cisco ASA/Firepower, or Fortinet within AWS. - Automation Tools:
Proficiency in Terraform, Cloud Formation, and scripting (Python, Bash, or Power Shell). - Monitoring & Logging:
Skilled in using AWS Cloud Watch, Cloud Trail, and Security Hub for centralized security monitoring.
- Experience:
Typically, 5 years in network engineering or cloud security, with at least 3 years specifically in cloud network architecture.
- AWS Certified Security – Specialty.
- AWS Certified Advanced Networking – Specialty.
- Vendor-specific certs like PCNSE (Palo Alto).
- Bachelor’s degree in computer science, Information Technology, or a related field.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×