Quick Overview
Job Description
We are seeking an experienced Network Security Engineer to manage, maintain, and enhance our perimeter and internal security infrastructure. In this role, you will serve as the primary subject matter expert for our Palo Alto Networks firewall environment, ensuring high availability, robust protection against cyber threats, and seamless enterprise connectivity. This position includes participation in an on-call rotation to support critical incident response and maintenance outside standard business hours.
Key Responsibilities
Architecture & Deployment: Plan, configure, deploy, and maintain Palo Alto Next-Generation Firewalls (NGFW) across physical, virtual, and cloud environments.
Management & Monitoring: Utilize Palo Alto Panorama for centralized management, policy creation, software updates, and configuration backups across all security appliances.
Policy & Threat Management: Design, review, and optimize Security, NAT, Threat Prevention, URL Filtering, WildFire, and App-ID policies.
VPN & Access Control: Implement and support IPsec VPNs, GlobalProtect Remote Access, and site-to-site connectivity.
Troubleshooting: Perform deep-packet analysis and log review to isolate complex network, firewall, and routing issues (OSPF, BGP, static routing).
On-Call & Incident Support: Participate in an engineering team on-call rotation (e.g., 1 week every 4–6 weeks) to troubleshoot urgent outage reports, mitigate active security incidents, and conduct off-hours scheduled changes.
Compliance & Auditing: Perform regular security audits, rulebase cleanup, and vulnerability remediation to maintain compliance standards.
Qualifications & Requirements
Experience: 3–5+ years of hands-on experience dedicated to Palo Alto Networks firewall administration in enterprise environments.
Certifications: PCNSA, PCNSE, or equivalent demonstrable network security expertise required.
Core Technical Skills:
Advanced knowledge of PAN-OS, Panorama, GlobalProtect, and Palo Alto security subscriptions.
Strong foundation in TCP/IP, routing protocols (BGP, OSPF), VLANs, and network segmentation.
Experience with network packet analyzers (Wireshark, PAN-OS packet capture).
On-Call Availability: Willingness and capability to respond to critical P1/P2 incidents promptly while on call, and to execute planned maintenance during off-peak maintenance windows.
Soft Skills: Strong analytical problem-solving abilities, documentation habits, and clear communication under high-pressure security events.
Preferred Qualifications
Bachelor’s degree in Computer Science, Information Technology, or a related field (or equivalent work experience).
Experience integrating Palo Alto firewalls with cloud platforms (AWS, Azure, or Google Cloud Platform).
Familiarity with automation tools (Python, Ansible, Terraform) or Palo Alto APIs for network automation.
Similar jobs
- ID
Penetration Tester
NewIdexcel Inc.
United States🇺🇸Hybrid17 hours agoOWASPPenetration TestingPowerShell+1Technology - AD
Security Architect (W2)
NewAdientOne LLC
United States🇺🇸Remote17 hours agoDockerBashConfluence+5Technology - ID
InfoSec Engineer
NewIdexcel Inc.
Reston, VA🇺🇸Hybrid17 hours agoEngineering - DS
Network Data Security Engineer / Specialist
NewDecision Six Inc.
Vancouver, WA🇺🇸HybridYesterdayEncryptionPCI DSSAzure+5Technology - IT
Cybersecurity Engineer
isolve technology inc
Richmond, VA🇺🇸Hybrid3 days agoAWSSOC 2Splunk+3Technology - IG
Security Control Assessor with Security Clearance
NewInsight Global, Inc.
Denver, CO🇺🇸On-site17 hours agoAdministrative