AWS Cloud Firewall SME

Ampcus Inc.McLean, VA
Onsite

About The Position

Ampcus Inc. is seeking a highly motivated AWS Cloud Firewall Subject Matter Expert (SME) focused on the architecture, implementation, and central management of network security across cloud environments. This role is crucial for designing and maintaining secure network topologies and managing firewall policies in AWS.

Requirements

  • Deep expertise in AWS Network Firewall, Firewall Manager, WAF, Security Groups, NACLs, and AWS Shield.
  • Advanced knowledge of VPCs, Transit Gateway, Route 53 Resolver DNS Firewall, and PrivateLink.
  • Experience with enterprise firewall platforms like Palo Alto Networks, Cisco ASA/Firepower, or Fortinet within AWS.
  • Proficiency in Terraform, CloudFormation, and scripting (Python, Bash, or PowerShell).
  • Skilled in using AWS CloudWatch, CloudTrail, and Security Hub for centralized security monitoring.

Nice To Haves

  • Typically, 5 years in network engineering or cloud security, with at least 3 years specifically in cloud network architecture.
  • AWS Certified Security – Specialty.
  • AWS Certified Advanced Networking – Specialty.
  • Vendor-specific certs like PCNSE (Palo Alto).
  • Bachelor’s degree in computer science, Information Technology, or a related field.

Responsibilities

  • Design and implement secure AWS network topologies, including VPC design, routing, and hybrid connectivity (VPN, Direct Connect).
  • Act as the primary expert for AWS Firewall Manager to centrally configure and manage rules for AWS WAF, AWS Network Firewall, Shield Advanced, and Security Groups across multiple accounts.
  • Maintain and optimize rules for AWS Network Firewall and third-party firewalls (e.g., Palo Alto, Fortinet) to control ingress/egress traffic.
  • Develop and manage Infrastructure as Code (IaC) templates using Terraform or CloudFormation to automate firewall deployments and security governance policies.
  • Enforce network security standards and compliance frameworks (e.g., NIST, CIS, PCI-DSS) by conducting periodic firewall rule audits and access reviews.
  • Act as an SME during network-related security incidents, supporting SOC teams with packet analysis, firewall log investigation, and immediate containment actions.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service