About the Opportunity
The Network Security Engineer role requires extensive Palo Alto Panorama, Firewalls, and Global Protect experience, along with extensive networking experience. Palo Alto Prisma Access and Zero Trust Network Access knowledge and experience are highly desired. A Network Security Engineer is responsible for providing architectural, technical, and problem resolution support for a Federal Agency network and security infrastructure that promotes a secure and scalable environment that aligns with the security requirements of our customer.
A Network Security Engineer also focuses on both the short-term and the long-term strategy, recommends technology solutions and improvements to the network and security-related environments and is also responsible for delivering clear, concise, timely communications that promote confidence in our team’s ability to deliver operational excellence. They also perform Tier III “Build and Run” activities across multiple network and security environments, and review and recommend configuration changes, as needed.
The day-to-day responsibilities include the design, implementation, operations, troubleshooting, and resolution activities across multiple domains. They may be required to participate in system upgrades, deployments, and enhancements while focusing on delivery objectives, critical issues, and policy adherence. All Network Security Team members periodically work after hours to support system outages and critical infrastructure upgrades. This position may also require an on-site presence one or more days per week.
Qualifications
LI-JL1
Education :
- BS Degree in Computer Science or Engineering, or equivalent work experience (required)
Experience :
10+ years of relevant technical Network / Security Engineering experience (required)Certifications : Desire three or more of the following : CCNP, CCDP, CCSP, CISSP, OSCP, PCNSE, PCNSA, ITILRequired Skills :
Extensive experience with Palo Alto Firewalls (ex : 3200 and 5200 / 5400 / 5600 series)Extensive experience with Palo Alto Panorama and aboveExtensive experience with Palo Alto Global ProtectExtensive experience with Palo Alto Firewall Threat Protection, URL filtering, and other similar security featuresExtensive experience with decryption / TLS / Security Profiles / PKI and deep understanding of PCAPSExtensive experience with application-based traffic and designing solutions for Firewalling (Internal / Perimeter / External)Experience with Palo Alto Prisma Access-based Infrastructure, supporting multiple Data Centers and numerous officesDesired Skills and Abilities :
Vendor hardware and software support, such as Cisco, Juniper, Palo Alto, and othersData Center, WAN, LAN, WLAN, Firewall, and Load Balancer systems and supportAnalysis and forensic tools, along with effective troubleshooting of ingress / egress and zoned trafficAzure Infrastructure and understanding Azure VNETs, Routing, and FirewallingMicrosoft Entra ID and SAML authenticationLaptop setup and configurationsImplementing ZTNA with an understanding of all integration points of the ZT pillars, such as endpoint, identity, and workloadsDeveloping ZT security policies that incorporate telemetry from identity systems, endpoints, and external management systemsWhitelisting IP space for various project teams to access external vendors and to ensure safe and secure connectivityCreating Zones and Policies for various network segments and troubleshooting connectivity across Security ZonesWork with internal applications teams, design, and implement an appropriate ZTNA program with PA Prisma AccessDevelop documents that describe design, security controls, and operational manualsDevelop and participate in internal and external testing of applicable applications to ensure that sufficient security is in place Effective time management and organizational skills, and ability to translate technical issues for business usersWork independently as well as in a team environment with effective interpersonal communication skillsAnalytical, communication, and problem-solving skillsSupport InfoSec Standards and Best PracticesThrives in a fast-paced environment and looks for ways to do things more effectively (Current Mode / Future Mode)Location : Arlington, VA / Dallas, TX