Sr. AWS Cloud Architect

ExpediteInfoTech, Inc
  • Rockville, MD
  • Remote
  • Quick Apply
1 day ago

Job Description

Location: Remote with occasional travel to the client site in DC.

Status: This position requires a U.S. Citizen. The selected candidate will go through a Public Trust Clearance process.

Responsibilities:

Cloud Architecture and Solutions Engineering

Design and govern AWS infrastructure supporting the application portfolio, including:

  • VPC design, subnet segmentation, routing, NAT gateways, and security groups
  • IAM policy design aligned to least-privilege principles
  • Solutions architecture for new applications, including deployment strategy, service selection, and integration patterns
  • Infrastructure-as-code development and maintenance (CloudFormation, Terraform, AWS CDK)
  • Environment management (development, staging, production)
  • Integration with enterprise security controls (e.g., Palo Alto firewalls)
  • Architectural documentation to support Authority to Operate (ATO) requirements
  • Cloud cost governance and optimization

AWS Networking & Load Balancing

  • Deep expertise in AWS Gateway Load Balancer (GWLB) architecture, deployment, and configuration
  • Proficient in designing and managing Gateway Load Balancer Endpoints (GWLBe) for traffic inspection
  • Strong understanding of GWLB GENEVE protocol tunneling and packet encapsulation/decapsulation
  • Experience integrating GWLB with third-party virtual appliances for inline traffic inspection
  • Ability to design bump-in-the-wire traffic inspection architectures using GWLB
  • Proficient in GWLB target groups, health checks, and flow stickiness configurations
  • Experience with VPC endpoint services and consumer/provider models
  • Understanding of east-west and north-south traffic inspection patterns using GWLB

AWS Cloud Infrastructure

  • Strong knowledge of AWS Landing Zone Accelerator (LZA) deployment and customization
  • Experience managing AWS Control Tower and multi-account AWS Organizations structures
  • Proficient in AWS CDK (Cloud Development Kit) using Python, TypeScript, or Java
  • Skilled in writing and maintaining AWS CloudFormation templates (YAML/JSON)
  • Experience with CDK Constructs, Stacks, and App lifecycle management
  • Ability to convert CloudFormation templates to CDK and vice versa
  • Proficient in CloudFormation StackSets for multi-account/multi-region deployments
  • Familiarity with AWS Transit Gateway, VPC peering, and hybrid connectivity
  • Knowledge of AWS Route 53, VPC DNS resolution, and private hosted zones
  • Experience with AWS IAM, SCPs, and least-privilege security models

Linux (Red Hat Enterprise Linux - RHEL)

  • Expert-level proficiency in Red Hat Enterprise Linux (RHEL) administration
  • Strong skills in systemd, service management, and process monitoring
  • Proficient in networking configuration using nmcli, ip commands, and network scripts
  • Experience with SELinux policy management and troubleshooting
  • Skilled in firewalld/iptables rule management for host-based security
  • Proficient in shell scripting (Bash) for automation and operational tasks
  • Experience with RHEL subscription management, yum/dnf package management
  • Knowledge of kernel tuning and performance optimization for network-heavy workloads
  • Familiarity with Red Hat Satellite or Ansible for configuration management
  • Experience with tcpdump, Wireshark, netstat, ss for network troubleshooting on Linux

Palo Alto Networks (Firewall & Security)

  • Expert knowledge of Palo Alto NGFW (Next-Generation Firewall) configuration and management
  • Deep understanding of Security Policies, NAT Policies, and PBF (Policy-Based Forwarding)
  • Proficient in App-ID, User-ID, and Content-ID technologies
  • Experience deploying Palo Alto VM-Series firewalls in AWS environments
  • Strong skills in Threat Prevention, Anti-Virus, Anti-Spyware, and Vulnerability Protection profiles
  • Proficient in URL Filtering, DNS Security, and WildFire sandbox integration
  • Experience with High Availability (HA) configurations (Active/Passive and Active/Active)
  • Knowledge of Palo Alto bootstrapping in cloud environments (S3 bootstrap)
  • Skilled in log forwarding, monitoring, and integration with SIEM platforms
  • Familiarity with Decryption Policies (SSL/TLS inspection)

Panorama (Centralized Management)

  • Expert proficiency in Panorama centralized firewall management and administration
  • Experience managing Device Groups, Templates, and Template Stacks in Panorama
  • Skilled in policy hierarchy management (Pre-rules, Post-rules, and Default rules)
  • Proficient in Panorama log collection and log forwarding configurations
  • Experience with Panorama High Availability setup and failover
  • Ability to onboard and manage large-scale Palo Alto firewall deployments via Panorama
  • Knowledge of Panorama Plugins (e.g., AWS, Azure cloud plugins)
  • Proficient in Software/Content updates and version management through Panorama
  • Experience with role-based administration and admin account management in Panorama

Global Protect VPN

  • Expert knowledge of GlobalProtect VPN architecture (Gateways, Portals, and Agents)
  • Experience designing and deploying large-scale GlobalProtect remote access solutions
  • Proficient in pre-logon, user-logon, and on-demand connect methods
  • Strong understanding of HIP (Host Information Profile) checks and endpoint compliance enforcement
  • Experience integrating GlobalProtect with SAML, LDAP, RADIUS, and MFA authentication
  • Knowledge of split tunneling and traffic steering configurations
  • Skilled in GlobalProtect Clientless VPN for web-based remote access
  • Experience troubleshooting GlobalProtect agent connectivity and gateway selection issues
  • Familiarity with GlobalProtect Cloud Service (GPCS) and Prisma Access integration

Infrastructure as Code (IaC) & Automation

  • Strong proficiency in AWS CDK for defining cloud infrastructure programmatically
  • Expert in AWS CloudFormation template development, nested stacks, and custom resources
  • Experience with LZA (Landing Zone Accelerator) configuration files and customization pipeline
  • Skilled in CI/CD pipeline integration (AWS CodePipeline, CodeBuild, GitHub Actions) for IaC deployments
  • Proficient in Python and/or TypeScript for CDK and automation scripting
  • Experience with AWS Systems Manager (SSM) Parameter Store and Secrets Manager integration
  • Knowledge of infrastructure drift detection and remediation strategies
  • Familiarity with Terraform as an additional IaC tool (complementary skill)

Network Security Architecture

  • Ability to design Zero Trust network architectures in AWS multi-account environments
  • Experience with centralized egress/ingress inspection architectures using GWLB and Palo Alto
  • Strong understanding of network segmentation, micro-segmentation, and security zones
  • Knowledge of AWS Security Hub, GuardDuty, and CloudTrail for security monitoring
  • Experience with distributed vs. centralized firewall deployment models
  • Understanding of compliance frameworks (NIST, FedRAMP, HIPAA, PCI-DSS) as applied to cloud networking

Monitoring & Troubleshooting

  • Proficient in AWS VPC Flow Logs analysis for network traffic visibility
  • Experience with AWS CloudWatch metrics, alarms, and dashboards for network monitoring
  • Skilled in using Palo Alto Traffic Logs, Threat Logs, and System Logs for incident analysis
  • Ability to troubleshoot GWLB traffic flow issues including GENEVE encapsulation problems
  • Experience with packet capture tools both in AWS (Traffic Mirroring) and on Linux hosts
  • Familiarity with network performance benchmarking and latency analysis tools

Soft Skills & Collaboration

  • Ability to document complex network architectures using tools like Visio, Lucidchart, or Draw.io
  • Experience working in Agile/Scrum environments with infrastructure teams
  • Strong written and verbal communication skills for cross-functional collaboration
  • Ability to conduct architecture reviews and provide technical guidance to junior staff
  • Experience with ticketing systems (ServiceNow, Jira) for change management and incident tracking

Certifications Recommended:

  • AWS Certified Advanced Networking – Specialty
  • AWS Certified Solutions Architect – Professional
  • Palo Alto Networks Certified Network Security Engineer (PCNSE)
  • Red Hat Certified Engineer (RHCE)
  • AWS Certified Security – Specialty


About:ExpediteInfoTech, Inc. (EIT) is a SBA certified small business. Headquartered in Rockville, MD since 2012, EIT has provided specialized technical, cybersecurity, IT, and financial advisory solutions to the Federal, State and County governments. Our clients include the US Department of Education, US Department of Transportation, US Department of Justice, US Department of Health & Human Services, Montgomery County government, Prince George's County Government, the governments of the State of Maryland and the District of Columbia. EIT is appraised at level 3 for CMMI Services & CMMI Development, as well as ISO 9001:2015, ISO 20000-1:2018 and ISO 27001:2013.

EIT offers a competitive benefits package including medical, dental, vision and prescription drug coverage, paid time off, federal holidays, matching 401K plan, and tuition/professional development reimbursement benefits.

EIT is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by applicable law.

Numbers & Facts

LocationRockville, MD (
Remote
)

More jobs like this

See more jobs

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.