Senior Palo Alto Network Security Engineer

MarineTraffic
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$26,000.0
Working hours
Regular working hours

Tech stack

Active Directory Active Directory Federation Services User Authentication Disaster Recovery Failover Intrusion Detection and Prevention Intrusion Detection Systems Virtual Private Networks (VPN) Network Security Lightweight Directory Access Protocols (LDAP) Routing Ping (Networking Utility)
+12 more
Public Key Infrastructure Remote Access Technology Azure Active Directory Runbook Security Assertion Markup Language (SAML) Single Sign-On Dynamic Routing Okta Document Metadata System Availability Firewalls (Computer Science) Palo Alto Networks

Job description

The selected engineer will perform a controlled, zero-downtime upgrade of a High Availability Palo Alto firewall environment while diagnosing and resolving existing SAML/Single Sign-On authentication issues impacting administrative access and GlobalProtect users.

This engagement requires extensive experience performing production firewall upgrades in highly available environments where service interruption is unacceptable.

The project will be executed by a single senior engineer responsible for all planning, execution, validation, documentation, and project closeout., The selected engineer will perform all technical activities required to complete the engagement, including, * Assess the current Palo Alto firewall environment and overall health.

  • Validate High Availability (HA) configuration, synchronization, and failover readiness.
  • Inventory PAN-OS versions, Dynamic Updates, GlobalProtect, plugins, and content releases.
  • Export and secure running configurations, device state files, and technical support files.
  • Evaluate Panorama dependencies and upgrade sequencing.
  • Establish baseline performance metrics including:
  • CPU utilization
  • Session counts
  • Throughput
  • VPN utilization
  • Packet buffers
  • Review licensing and support entitlement status.
  • Document upgrade readiness and identify technical risks., * Troubleshoot and resolve SAML/Single Sign-On authentication issues.
  • Validate synchronization between firewalls and Identity Providers (IdPs).
  • Review and update:
  • IdP metadata
  • Signing certificates
  • Certificate chains
  • Entity IDs
  • Assertion Consumer Service (Client) URLs
  • Group mappings
  • Authentication profiles
  • Analyze authentication and system logs to isolate root causes.
  • Validate GlobalProtect authentication workflows.
  • Configure and verify local break-glass administrative access., * Develop a production-ready upgrade strategy.
  • Determine the appropriate PAN-OS target release.
  • Validate software compatibility with:
  • Panorama
  • GlobalProtect
  • User-ID
  • Dynamic Updates
  • Plugins
  • Routing services
  • Stage software images.
  • Develop rollback procedures and recovery plans.
  • Produce detailed maintenance window documentation.
  • Define Go/No-Go decision points., * Validate HA health.
  • Upgrade passive firewall.
  • Verify synchronization and health.
  • Execute controlled failover.
  • Monitor:
  • Routing
  • VPN connectivity
  • NAT
  • Production traffic
  • Session stability
  • Upgrade remaining firewall.
  • Restore preferred HA state.
  • Validate overall operational health., * Validate GlobalProtect authentication.
  • Test role mappings and group-based access.
  • Verify HA failover behavior following upgrade.
  • Compare post-upgrade performance against baseline metrics.
  • Document metadata renewal procedures.
  • Produce final operational acceptance documentation., The engineer will be responsible for producing the following project artifacts:
  • Production Firewall Assessment Report
  • SSO Root Cause Analysis / Restoration Report
  • Approved Upgrade & Rollback Plan
  • Production Change Execution Documentation
  • Post-Upgrade Validation Report
  • Operational Acceptance Documentation
  • Final Project Closeout Report

Requirements

  • Minimum 8 years of enterprise network security engineering experience.
  • Minimum 5 years administering Palo Alto Networks next-generation firewalls.
  • Demonstrated experience performing production PAN-OS upgrades in High Availability environments.
  • Strong understanding of:
  • Active/Passive HA
  • Active/Active HA
  • Session synchronization
  • Failover operations
  • Extensive experience with:
  • GlobalProtect
  • User-ID
  • Dynamic Updates
  • Panorama
  • Experience troubleshooting enterprise SAML authentication.
  • Strong knowledge of:
  • SAML 2.0
  • Identity Providers (Microsoft Entra ID/Azure AD, Okta, Ping, ADFS, etc.)
  • Certificates
  • PKI
  • NTP
  • Experience developing rollback strategies and production maintenance runbooks.
  • Strong documentation and technical writing skills.
  • Experience working within formal change management processes., * Palo Alto Networks Certified Network Security Engineer (PCNSE)
  • Palo Alto Certified Network Security Administrator (PCNSA)
  • Experience supporting enterprise environments with 24x7 operational requirements.
  • Experience with enterprise VPN environments.
  • Experience supporting Federal Government or highly regulated environments.
  • ITIL Foundation certification.
  • Security+ CE (preferred)., * Palo Alto Networks Firewalls
  • PAN-OS 10.x
  • Panorama
  • GlobalProtect
  • High Availability (HA)
  • SAML 2.0
  • Single Sign-On (SSO)
  • Microsoft Entra ID / Azure AD
  • Okta
  • Active Directory
  • LDAP
  • RADIUS
  • PKI
  • TLS Certificates
  • NTP
  • Dynamic Routing
  • NAT
  • VPN Technologies
  • User-ID
  • WildFire
  • Threat Prevention
  • Logging & Monitoring
  • Change Management
  • Disaster Recovery
  • Rollback Planning, * Excellent troubleshooting and analytical abilities.
  • Ability to independently lead complex infrastructure projects.
  • Strong verbal and written communication skills.
  • Ability to perform structured root cause analysis.
  • Experience supporting mission-critical production environments.
  • Ability to work during scheduled after-hours maintenance windows.
  • Strong organizational and documentation skills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www2.jobdiva.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · WWC Europe 2026

Videos

See all

Related articles

See all