Firewall Engineer

CRI Advantage, Inc.
Idaho Falls, ID, United States
2 months ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$124,800.0 - $145,600.0
Working hours
Regular working hours

Tech stack

Application Firewall IPv4 IPv6 Network Security Firewalls (Computer Science) Palo Alto Networks Firewall Services Module

Job description

The Firewall Engineer is responsible for implementing and supporting IPv4/IPv6 dual-stack networking across an enterprise Palo Alto Networks firewall environment. Working primarily in Palo Alto Panorama, you will design, build, deploy, validate, and troubleshoot firewall policies - developing IPv6 rulesets based on the organization’s existing IPv4 policy and deploying them to firewalls throughout the environment. This role keeps a mission-critical production network secure and available while modernizing it to support IPv6., The approximate time allocations below reflect the primary focus of the role and may vary with project needs.

  • Build, deploy, and maintain firewall rules and policies across the enterprise Palo Alto Networks environment (approx. 70% of time).

  • Develop IPv6 rulesets in Palo Alto Panorama, mirroring current IPv4 policy, and deploy them to firewalls enterprise-wide.

  • Build and configure IPv6 interfaces on firewall devices to support dual-stack operation (approx. 10% of time).

  • Validate and troubleshoot firewall traffic to confirm rulesets function as intended and to resolve policy or connectivity issues (approx. 20% of time).

  • Participate in change planning, implementation, and validation activities to minimize operational risk during firewall deployments.

  • Document configurations, changes, and troubleshooting steps to support ongoing operations and knowledge transfer.

  • Comply with all environmental, safety, health, security, and quality requirements, and apply Integrated Safety Management System principles when performing job duties.

  • Perform other related duties as assigned in support of the network security team.

Requirements

  • Bachelor’s degree plus 2 years of relevant experience, or an equivalent combination of education and experience.

  • Hands-on experience administering Palo Alto Networks firewalls and Panorama centralized management.

  • Demonstrated experience implementing and supporting IPv4/IPv6 dual-stack networking within an enterprise environment.

  • Demonstrated experience designing, deploying, validating, and troubleshooting enterprise firewall policies.

  • U.S. citizenship; ability to complete standard site onboarding and background screening prior to starting.

Preferred Qualifications

  • Palo Alto Networks Certified Network Security Engineer (PCNSE) or comparable certification.

  • Experience administering Palo Alto Panorama Device Groups and Templates.

  • Experience planning or executing enterprise firewall migrations.

  • Experience supporting large, highly available production environments.

  • Experience with enterprise IPv6 migrations or large dual-stack rollouts.

  • Prior experience in a government, national laboratory, or other regulated IT environment.

Knowledge, Skills & Abilities

  • In-depth knowledge of Palo Alto Networks firewall administration and Panorama policy management.

  • Strong understanding of IPv4 and IPv6 addressing, dual-stack networking, and firewall policy design.

  • Strong analytical, problem-solving, and troubleshooting skills with close attention to detail.

  • Ability to work independently, manage competing priorities, and follow change-control processes in a production environment.

  • Effective written and verbal communication and clear technical documentation.

Work Environment & Physical Requirements

  • Work is performed 100% onsite at a secure facility in Idaho Falls, Idaho; remote or hybrid work is not available for this position.

  • Prolonged periods working at a computer and performing repetitive keyboard/mouse tasks.

  • Occasional standing, bending, or lifting of equipment (typically up to 25 pounds) may be required.

  • Must adhere to all site safety, security, and emergency-action procedures.

Benefits & conditions

$60.00 - $70.00 / hr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · World Congress 2025

2:22 min

Introducing Skupper for application connectivity

Alex Soto Alex Soto · World Congress 2024

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all