Haystack
← Back to Jobs
Technology
CI

Principal Network Security Architect Palo Alto

ComTec Information SystemsUnited States🇺🇸United StatesPosted 2 Sept 2026

Why This Role Stands Out

As a Principal Network Security Architect, you will architect and implement cutting-edge Palo Alto Networks security solutions, driving significant impact in a hybrid environment. This leadership role is perfect for a seasoned professional eager to leverage their deep expertise in network security design and troubleshooting, offering a fantastic opportunity for career growth and technical leadership. Apply now to join a reputable company and shape the future of their network security.

Quick Overview

Seniority
Leader
Work mode
Hybrid
Location
United States
Posted
1 week ago
PrismaZero TrustTCP/IPDNS

Job Description

Title: Principal Network Security Architect Palo Alto

Duration: Full Time

We are seeking a Principal Network Security Architect/Engineer with deep hands-on expertise in Palo Alto Networks security technologies and enterprise networking. The ideal candidate will be responsible for designing, architecting, implementing, troubleshooting, and optimizing complex network security environments. This role requires strong expertise in Palo Alto firewalls, Panorama, Prisma/GlobalProtect, security policy design, and general networking, along with the ability to provide technical leadership on complex security initiatives.

Key Responsibilities

  • Lead the architecture, design, implementation, and optimization of Palo Alto Networks firewalls across enterprise, data center, and hybrid cloud environments.
  • Design, implement, and troubleshoot Palo Alto security policies using User-ID, App-ID, Content-ID, Security Profiles, URL Filtering, Threat Prevention, WildFire, and DNS Security.
  • Perform firewall rulebase analysis, including policy review, rule optimization, shadowed/duplicate rules, overly permissive policies, unused rules, and security best-practice compliance.
  • Manage and architect Panorama for centralized firewall management, policy administration, configuration, logging, and operational standards.
  • Design, implement, and support GlobalProtect remote-access and VPN solutions.
  • Provide expertise with Prisma Access/Prisma solutions and integration with enterprise network security architectures.
  • Design secure network architectures incorporating network segmentation, Zero Trust, DMZs, high availability, defense-in-depth, and secure connectivity.
  • Troubleshoot complex routing, switching, NAT, VPN, DNS, VLAN, and firewall connectivity issues.
  • Provide Level 3 technical escalation for complex network and security incidents.
  • Lead firewall migrations, upgrades, policy cleanup, platform refreshes, and security transformation projects.
  • Analyze firewall traffic, threat, URL, WildFire, and system logs to identify security threats and connectivity issues.
  • Develop security architecture standards, configuration baselines, network diagrams, SOPs, and implementation documentation.
  • Collaborate with network, cloud, infrastructure, application, and cybersecurity teams to design and implement secure solutions.
  • Mentor network security engineers and provide technical leadership for complex projects.

Required Skills

  • 10+ years of experience in network security engineering and architecture.
  • Extensive hands-on experience with Palo Alto Networks NGFW and Panorama.
  • Strong expertise in User-ID, App-ID, Content-ID, WildFire, Security Profiles, URL Filtering, and Threat Prevention.
  • Strong experience performing Palo Alto firewall rulebase analysis and optimization.
  • Hands-on experience with GlobalProtect and Prisma Access/Prisma.
  • Strong understanding of general networking, including TCP/IP, routing, switching, VLANs, subnetting, DNS, DHCP, NAT, BGP, OSPF, and network segmentation.
  • Strong experience with IPSec VPN, SSL VPN, site-to-site VPN, and remote-access solutions.
  • Experience designing and supporting high-availability Palo Alto firewall deployments.
  • Strong troubleshooting skills using firewall logs, packet captures, session information, and network monitoring tools.
  • Experience with enterprise and data center network security architecture.
  • Strong understanding of Zero Trust, defense-in-depth, and secure network architecture principles.
  • Ability to lead complex technical initiatives and provide L3/L4-level troubleshooting and engineering support.
  • Excellent communication, documentation, analytical, and problem-solving skills.

Similar jobs