Firewall Architect
Role details
Job location
Tech stack
Job description
We are seeking a highly experienced Firewall Architect / Lead Analyst to design, implement, and maintain enterprise?grade network security infrastructure within a large, complex healthcare environment. This role serves as a technical leader, escalation point, and key contributor to our ongoing Zscaler Zero Trust transformation.
You will work hands?on in a Palo Alto-heavy environment, with Zscaler (ZIA/ZTB) as a major strategic focus over the next 12 months. This position partners closely with Security Architecture and leads critical enterprise initiatives, including segmentation, new site builds, and Zscaler migration efforts., Architecture & Design
- Design and maintain enterprise network security architecture, including firewalls, routing/switching, and security technologies.
- Lead segmentation strategies to reduce threat exposure and minimize blast radius.
Firewall Management
- Own firewall policy, rule creation, and lifecycle management across on?prem and cloud environments.
- Analyze traffic flows and troubleshoot inconsistencies.
Project Leadership
- Lead enterprise network initiatives such as:
- Zscaler migration projects (including Ambulatory environments)
- New site builds
- Integrations of acquired sites
Escalation & Support
- Serve as the senior escalation point for complex firewall and network security issues.
- Collaborate closely with Security Architecture on new deployments and enterprise security strategy.
Zscaler?Focused Responsibilities
- Ensure Zscaler architecture is scalable, stable, and aligned with enterprise standards.
- Optimize and clean up existing Zscaler configurations.
- Support the enterprise?wide transition to Zscaler over the next 12 months.
- No major redesigns expected unless clear value is identified.
Automation & Engineering
- Hands?on automation not required, but experience with Ansible or Python is a plus.
- Environment is not yet fully ready for firewall?as?code workflows.
- Team is actively improving Palo Alto Panorama to support future automation.
Technology Environment
Firewalls:
- Palo Alto NGFW (10.1.2, upgrading)
- Cisco ASA / Firepower
Zscaler:
- ZIA (integration completed)
- ZTB (POC completed; moving into rollout)
- ZPA exposure is a plus
Priority:
- Zscaler and Palo Alto are equal priority
- Cisco is a supporting skillset ("Cisco flavor")
Role Scope & Leadership
- Lead major network security initiatives, not just execute tasks.
- Act as the go?to technical resource for Zero Trust and Zscaler transformation.
- Work within a large, complex, Palo Alto-heavy enterprise environment.
Requirements
- Bachelor's degree
- 8+ years experience in large enterprise network/security architecture
- Strong expertise with Palo Alto and Cisco firewalls
- Strong experience with Zscaler, including:
- Zscaler ZTB hardware and setup
- Understanding of ZTB architecture and bridge connector functionality
- Understanding of ZIA and its integration with Zero Trust
Preferred Qualifications
- Healthcare industry experience
- Certifications: CCNP, CISSP, Palo Alto
- Hyperscale experience
- Exposure to Ansible and Python
- Experience with Azure