> Markdown version of [/jobs/ext/1140914-sme-azure-cloud-security-palo-alto-firewall](https://www.wearedevelopers.com/jobs/ext/1140914-sme-azure-cloud-security-palo-alto-firewall). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SME - Azure & Cloud Security, Palo Alto Firewall - **Company:** HCL America Inc. - **Location:** Frisco, TX, United States - **Experience:** Expert - **Salary:** $123,000.0 - **Contract:** Permanent contract - **Skills:** Access Network, Amazon Web Services, Microsoft Azure, Border Gateway Protocol, Cisco PIX, Cloud Computing Security, CompTIA Security+, Cyber Security, Data Centers, Network Address Translation, Data-Flow Analysis, Internet Protocol Security (IP SEC), Virtual Private Networks (VPN), Python (Programming Language), Network Security, Routing, Network Segmentation, Open Shortest Path First (OSPF), PCI Data Security Standards, Remote Access Technology, Ansible, Zero Trust Network Access, Security Information and Event Management, Simple Network Management Protocols, Syslog, TCP/IP, Virtual Local Area Networks, Scripting, Transport Layer Security, QRadar, Firewalls (Computer Science), Information Technology, Palo Alto Networks, Check Point Firewalls, Fortinet, CIS Benchmarks, Splunk, Algosec Firewall - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=363ce329537400d2 ## About the Role * Minimum 8 years of hands-on experience with Palo Alto Networks firewalls (NGFW, Panorama). * Deep expertise in security policy management, zone-based architectures, and advanced traffic inspection techniques. * Proficiency with AlgoSec Firewall Analyzer and FireFlow for policy automation and compliance. * Strong understanding of TCP/IP, routing protocols (BGP, OSPF), VLANs, and network segmentation principles. * Demonstrated experience with VPN technologies (IPSec, SSL/TLS, GlobalProtect). * Familiarity with Syslog, SNMP, and SIEM platforms (e.g., Splunk, QRadar). * Practical knowledge of ITIL-based change management processes. EDUCATION * Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent professional experience. REQUIRED CERTIFICATIONS * Palo Alto Networks Certified Network Security Engineer (PCNSE) - Mandatory Other Requirements * Experience with Cisco ASA/FTD, Fortinet, or Check Point firewalls. * Knowledge of cloud security controls, such as AWS Security Groups, Azure Firewall, or equivalent. * Familiarity with scripting or automation (Python, Ansible) for firewall policy management. * Experience with Tufin or FireMon as alternatives/complements to AlgoSec. * Understanding of Zero Trust Architecture principles. * Additional certifications such as PCNSA, CCNP Security/CCIE Security, AlgoSec Certified Engineer, CompTIA Security+, CEH, or ITIL Foundation (v3/v4). ## Description We are looking for an experienced Network Security Engineer with strong hands-on expertise in Palo Alto Networks firewalls to support enterprise firewall operations in a complex managed services environment. The role will be primarily responsible for advanced troubleshooting, firewall policy administration, rule lifecycle management, change execution, incident resolution, compliance support, and operational optimization. Hands-on experience with AlgoSec for policy analysis, risk assessment, and compliance validation is essential/preferred depending on the exact role scope. This role also requires strong knowledge of Panorama, VPN technologies, TCP/IP, routing, NAT, and broader network security operations., FIREWALL OPERATIONS and MANAGEMENT * Own and manage the enterprise-grade Palo Alto Networks firewall infrastructure, including PA-Series, VM-Series, and CN-Series devices. * Configure, implement, and maintain robust security policies, NAT rules, zones, and routing via Panorama and device-level interfaces. * Lead advanced troubleshooting for firewall-related incidents, utilizing packet captures, flow analysis, and comprehensive log reviews. * Administer GlobalProtect VPN, SSL decryption, URL filtering, App-ID, and User-ID policies to safeguard network access and integrity. * Manage L3 escalations from L1/L2 teams, driving issues to timely resolution in alignment with SLAs. SECURITY POLICY and COMPLIANCE * Conduct regular firewall rule reviews, cleanup, and optimization to minimize the organization's attack surface. * Leverage AlgoSec tools (Firewall Analyzer, FireFlow) for automated policy analysis, risk assessment, and streamlined change management. * Ensure configurations adhere to CIS benchmarks, internal security standards, and compliance frameworks such as PCI-DSS, ISO 27001, and NIST. * Actively participate in internal and external security audits to maintain compliance and reduce risk. CHANGE MANAGEMENT and PROJECTS * Evaluate, implement, and test firewall rule change requests end-to-end, ensuring seamless integration and minimal disruption. * Lead firewall migration and upgrade initiatives, including OS upgrades, hardware refreshes, and data center migrations. * Collaborate with network, cloud, and security architecture teams on new deployments and security enhancements. * Develop and maintain comprehensive runbooks, SOPs, and technical documentation for operational consistency. MONITORING and INCIDENT RESPONSE * Monitor firewall health, performance, and security events through SIEM integration and Panorama dashboards. * Participate in an on-call rotation, responding efficiently to P1/P2 security incidents and driving rapid remediation. * Conduct thorough root cause analysis (RCA) and post-incident reviews to prevent recurrence and strengthen defenses. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)