Cloud Engineer Network
Shelton, CT - USA
Job Summary
Cloud Engineer Network
Franchise World Headquarters LLC
Why Join Subway
At Subway we are not standing still. We are building.
This is a business focused on what matters most: growing franchisee profitability strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.
You will not just do the work. You will shape it.
We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.
If you bring energy accountability and a bias for action you will fit right in.
We take the work seriously but we also know the best results come from teams that support each other celebrate wins and show up ready to build something better every day.
This is your chance to be part of whats next.
Position Overview
We are seeking a Cloud Engineer Network to design implement and support enterprise network and cloud connectivity infrastructure across on-premises multi-cloud and hybrid environments. This role is critical as Subway transitions network operations from managed services to an in-house engineering team requiring deep hands-on expertise across next-generation firewalls SD-WAN cloud networking architectures and infrastructure automation. This is a key build-out hire that directly enables a stronger more responsive in-house network engineering capability.
Responsibilities
Design deploy and maintain enterprise network security infrastructure using Palo Alto Networks (PAN-OS Panorama); administer and troubleshoot GlobalProtect VPN including portal/gateway configuration authentication flows certificates HIP checks and user access issues.
Manage and optimize Silver Peak (Aruba EdgeConnect) SD-WAN infrastructure across distributed sites including overlay design path conditioning and QoS; design configure and support enterprise routing switching wireless and campus/data center network infrastructure using Juniper including Juniper Mist Wireless management RF optimization and AIOps-assisted diagnostics.
Architect and support cloud networking across Azure (VNets VNet Peering Azure Firewall ExpressRoute VPN Gateways) and AWS (Transit Gateway VPC design Direct Connect VPN connections); design and manage ACLs and security group policies across cloud and on-premises environments to enforce least-privilege network access.
Build and maintain Terraform modules for network provisioning driving Infrastructure-as-Code adoption across the network estate and reducing manual configuration drift; implement and manage microsegmentation strategies to enforce zero-trust principles and reduce lateral movement risk.
Evaluate and integrate AI-driven tools for network monitoring anomaly detection and operational efficiency; support identity and authentication integrations including SAML RADIUS MFA certificate-based authentication and identity-aware access policies for VPN wireless and network access control use cases.
Execute formal change management practices for firewall SD-WAN VPN wireless and LAN/WAN changes including risk assessment implementation planning validation rollback planning and post-change documentation; serve as an escalation point for complex network incidents performing root-cause analysis and driving remediation.
Monitor platform health and performance using observability platforms; analyze firewall traffic review VPN usage validate SD-WAN path health and troubleshoot wireless performance proactively.
Partner with Cloud Engineering Cyber Security and Infrastructure Architecture teams on network segmentation secure connectivity and disaster recovery design; develop and maintain network documentation topology diagrams and standard operating procedures; participate in on-call rotation for critical network incidents.
Qualifications
710 years of enterprise network engineering experience.
Hands-on expertise administering Palo Alto Networks firewalls (PAN-OS Panorama) and supporting enterprise GlobalProtect VPN environments including user troubleshooting authentication certificates and security policy enforcement.
Production experience with Silver Peak / Aruba EdgeConnect SD-WAN.
Hands-on expertise with enterprise routing and switching using Juniper (Junos) and/or Cisco (IOS IOS-XE NX-OS); experience operating Juniper Mist Wireless environments including WLAN configuration RF/client troubleshooting and AIOps-assisted diagnostics.
Strong working knowledge of Azure networking (VNets Gateways ExpressRoute NSGs) and AWS networking (Transit Gateway VPCs VPNs Direct Connect).
Demonstrated hands-on experience building and maintaining Terraform modules for network infrastructure including state management module design and CI/CD-integrated provisioning.
Working knowledge of AI-driven network tools (AIOps anomaly detection automated remediation) and interest in applying AI to network operations.
Experience with SAML RADIUS MFA certificate-based authentication and identity-aware access policies.
Strong understanding of BGP OSPF IPsec VPN NAT QoS VLANs STP route redistribution failover and traffic engineering.
Experience troubleshooting complex multi-site network and connectivity issues.
Preferred Qualifications
Microsegmentation experience with platforms such as Guardicore/Akamai Guardicore Illumio or similar.
Relevant certifications: PCNSE/PCCET JNCIS-ENT/JNCIP-ENT Juniper Mist AI CCNP Enterprise Aruba EdgeConnect/Silver Peak AWS Advanced Networking Specialty Azure Network Engineer Associate or HashiCorp Terraform Associate.
Experience with additional automation tooling such as Ansible or Python scripting.
Familiarity with SASE and zero-trust network architectures.
Prior experience transitioning managed or outsourced network functions to an in-house engineering team.
What do we offer
Insurance Plans (Medical Life)
Pension/401K/RSP (country specific)
Competitive Bonus
Mobility Allowance
Tuition Reimbursement
Company Holidays
Volunteering time
And More..
Required Experience:
IC