Haystack
← Back to Jobs
Technology

Senior Lead Network Security Engineer (Palo Alto)

ComTec Information SystemsHouston, TX🇺🇸United StatesPosted 10 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Job Title: Senior Lead Network Security Engineer (Palo Alto)

Responsibilities:

  • Design and implement Palo Alto firewall policies, NAT rules, VPN configurations, and security zones.
  • Deploy, configure, and manage Palo Alto firewalls including policies, NAT, VPN, IPS, and threat prevention features.
  • Demonstrate expertise in deploying, configuring, and managing Palo Alto firewall and VPN solutions across on-premises, cloud, and remote access environments, ensuring seamless integration and security.
  • Define, configure, and optimize firewall policies and rules.
  • Perform troubleshooting and root cause analysis for network security incidents and firewall-related issues.
  • Manage security zones, access control policies, and URL filtering.
  • Manage and support enterprise certificate lifecycle processes, including certificate issuance, renewal, revocation, and compliance monitoring, preferably using Venafi.
  • Plan and execute firewall upgrades, patches, and migrations with minimal downtime.
  • Monitor and respond to security events and incidents related to firewalls and network devices.
  • Perform regular firewall rule reviews to optimize security and ensure compliance with security best practices while ensuring business continuity.
  • Ensure security of routing protocols (BGP, OSPF), VLANs, and load balancing across the network.
  • Involve in security audits, vulnerability assessments, and incident response to ensure network security compliance.
  • Monitor network performance and proactively address bottlenecks, latency issues, and security breaches.
  • Maintain detailed documentation for firewall configurations, security policies, network diagrams, and certificate management processes.
  • Oncall rotation one week, every 5 weeks. Oncall schedule: Monday 7AM to Monday 7AM.
  • Weekend support as needed for weekend deployments.


Required Skills:

  • 10+ years of experience in Network Security Engineering.
  • 7+ years of strong experience in Palo Alto Firewall administration.
  • Hands-on experience with certificate management is required; experience with Venafi is preferred.
  • Experience managing digital certificates, PKI infrastructure, certificate lifecycle management, and certificate-related security controls.
  • Experience in log analysis, incident response, and security monitoring.
  • Hands-on with VPNs (SSL/IPSec), NAT, IDS/IPS, Threat Prevention, and URL Filtering.
  • In-depth knowledge of TCP/IP, routing, VLANs, NAT, VPN, IPS, IDS, and general network architecture.
  • Understanding of network protocols (TCP/IP, BGP, OSPF, VLANs, DHCP, DNS, NAT, SNMP, IPsec, GRE, VXLAN).
  • Must have excellent understanding of security architecture and integration.
  • Strong proficiency in scripting (Python, Bash) and automation (Ansible)
  • Experience with change management and ITIL-based processes.
  • Strong troubleshooting and analytical skills.
  • Any experience with AI will be a huge plus.
  • Excellent communication and documentation skills.
  • Able to participate in oncall rotation schedule. One week for every 5 weeks. Monday 7AM to Monday 7AM.
  • Nice to have: Certifications such as PCNSE, PCNSA, CISSP, or CCNP.

Skills

Load Balancing
TCP/IP
Ansible
Bash
DNS
PKI
Python

Similar jobs