Haystack
← Back to Jobs
Technology
AS

Cloud Security Engineer - (Palo Alto CNAPP)

Amtex Systems Inc.Bellevue, WA🇺🇸United StatesPosted 14 Sept 2026

Why This Role Stands Out

This role offers a fantastic opportunity to advance your career in cloud security, leveraging your expertise in Palo Alto CNAPP to protect critical infrastructure at a reputable company. You'll thrive here if you're a driven, mid-senior level engineer eager to contribute to impactful security initiatives. Apply now to join a dynamic team and shape the future of cybersecurity!

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Bellevue, WA, United States
Posted
Yesterday
AWSMFAAnsibleAzurePenetration TestingPrismaRESTTerraformZero Trust

Job Description

Amtex Systems Inc is an information technology and talent solutions company offering talent and BI consulting to the companies in US for over 25 years.

Our solutions are designed to fill resource gaps, by providing the right candidates who deliver value to the organization. Our propensity to nurture and build strong relationships with our clients helps us better understand their business demands and gives us the ability to provide services that are on time and rise above the rest.


Job Title: Cloud Security Engineer – Palo Alto CNAPP

Job Location: Bellevue, Washington

Work Model: Onsite

Project Duration: 6 months +

Mode of Interview: Video / In Person

Role Summary:

Seeking a Cloud Security Engineer to join an Advanced Fusion Center (AFC) Subject Matter Expert (SME) team supporting the ongoing, day-to-day operation and monitoring of a client's cloud security stack. This is a steady-state operations and monitoring role operating within client-owned infrastructure under client direction, rather than a net-new build or architecture role.

Must Have Skills:

  • AWS-primary cloud security experience, including hands-on operational security and compliance in production AWS environments.
  • Hands-on experience with Prisma Cloud and/or Cortex Cloud (Palo Alto CNAPP) for CSPM/CWPP posture management.
  • CI/CD security expertise with Terraform, including authoring and maintaining IaC in automated pipelines.
  • Deep proficiency in cloud-native network controls such as AWS Security Groups, Azure NSGs, routing, private endpoints, and ingress/egress design.
  • Experience with Infrastructure as Code (Ansible) and IT orchestration platforms.
  • Practical design and operational experience with Zero Trust and network segmentation.
  • Strong capabilities in security posture assessment and remediation.
  • Baseline SME competencies: proactive and reactive troubleshooting, containerization, modern problem-solving/scripting/automation, critical thinking beyond standard runbooks, and strong written/verbal communication skills.

Key Responsibilities:

  • Design and implement hybrid enterprise network architectures featuring segmentation, zero trust principles, and layered defenses.
  • Maintain operational cloud security and compliance continuity across hybrid cloud systems, with a primary focus on AWS.
  • Support Prisma Cloud, Cortex Cloud, and CI/CD pipelines utilizing Terraform.
  • Apply comprehensive knowledge of cloud-native controls including Azure NSGs, AWS SGs, routing, private endpoints, and ingress/egress controls.
  • Perform scripting, Infrastructure as Code management via Ansible, and IT orchestration across managed platforms.
  • Implement future-proof configurations designed for long-term maintainability and risk reduction
  • Collaborate with business stakeholders to design secure implementation patterns and orchestration strategies.
  • Assess the security posture of current network assets and execute necessary remediation.

Scope Boundaries & Logistics:

  • Exclusions: Architecture design and implementation of net-new platforms, project-based deliverables/outcomes, security monitoring outside of platform health monitoring, penetration testing, application security, and adversary emulation.
  • Schedule: Business hours (Monday through Friday, 8:00 A.M. to 5:00 P.M.), not to exceed 40 hours per week.
  • Access & Screening: Client-provided VDI with MFA and site-to-site VPN; comprehensive background checks required.

 

 

Similar jobs