Engineer II – Network & Cloud Security
Description
Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries.
Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!
This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5 day in office schedule over time.
About the role:
As an Engineer II – Network & Cloud Security, you will be part of a cutting-edge cybersecurity team responsible for securing Enphase's global network, cloud infrastructure, applications, and APIs. You will work across a broad range of security technologies, including Palo Alto firewalls, Cequence API Security, Zscaler, Web Application Firewalls (WAF), and AWS cloud security services.
You will play a key role in maintaining and improving the security posture of enterprise infrastructure, implementing security controls, troubleshooting complex security and networking issues, and driving automation through scripting and Infrastructure as Code (IaC).
What you will be doing:
- Manage, configure, monitor, and troubleshoot Palo Alto Networks firewalls, including security policies, NAT, routing, VPN, GlobalProtect, threat prevention, and high-availability configurations.
- Administer and support Palo Alto Panorama for centralized firewall management, configuration, policy deployment, and monitoring.
- Manage and maintain Cequence API Security solutions, including API discovery, protection policies, threat detection, and investigation of API security events.
- Manage and support Zscaler security services, including Zscaler Internet Access (ZIA) and related security policies and integrations.
- Manage and maintain Web Application Firewall (WAF) solutions and security policies protecting internet-facing applications.
- Implement and maintain AWS cloud security controls, including security groups, network architecture, IAM, VPCs, Transit Gateway, load balancers, and other cloud-native security services.
- Design and implement secure network architectures across cloud and enterprise environments.
- Monitor security events, investigate incidents, perform troubleshooting, and provide timely remediation of security and network issues.
- Collaborate with infrastructure, cloud, application, DevOps, and IT teams to implement security requirements and resolve complex technical issues.
- Develop automation using Python, PowerShell, Bash, or similar scripting languages to improve operational efficiency and reduce manual activities.
- Develop and maintain Terraform / Infrastructure as Code configurations for security and networking infrastructure.
- Participate in vulnerability remediation, security hardening, patching, and continuous improvement of security controls.
- Maintain technical documentation, operational procedures, network diagrams, and security standards.
- Participate in security projects, technology evaluations, migrations, and enterprise-wide security initiatives.
- Provide operational support and participate in an on-call or incident response rotation when required.
What you bring:
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, Engineering, or equivalent work experience is preferred.
- A minimum of 3–5 years of experience in network security, cloud security, cybersecurity, or a related infrastructure security role.
- Hands-on experience with Palo Alto Networks firewalls and Panorama.
- Experience with network security technologies, including firewalls, VPNs, routing, NAT, DNS, load balancers, and network segmentation.
- Experience with AWS networking and security services, including VPC, Transit Gateway, IAM, security groups, ALB/NLB, and related services.
- Experience with API security, preferably Cequence or a similar API security platform.
- Experience with Zscaler or other Secure Access Service Edge (SASE) / cloud security platforms.
- Experience with WAF technologies and protection of internet-facing applications.
- Working knowledge of Terraform and Infrastructure as Code practices.
- Scripting experience using Python, Bash, PowerShell, or similar languages.
- Understanding of common security concepts, vulnerabilities, attack techniques, and security best practices.
- Strong troubleshooting and analytical skills with the ability to diagnose complex network and security issues.
- Excellent oral, written, and interpersonal communication skills.
- Ability to work effectively with globally distributed teams and cross-functional stakeholders.
- Relevant certifications such as PCNSE, AWS Security, Zscaler, Terraform, or other cybersecurity/network certifications are a plus.
What we offer:
- Competitive compensation and comprehensive employee benefits.
- Opportunity to work with cutting-edge cloud, network, and cybersecurity technologies.
- A collaborative and innovative global work environment.
- Opportunities for professional growth, learning, and technical certifications.
- Opportunity to contribute to Enphase's mission of building a sustainable and clean energy future.
- A culture that encourages innovation, ownership, collaboration, and continuous learning.