Network Engineer IV

Palo Alto, Inc.
United States
21 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$115,000.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Border Gateway Protocol Cloud Computing Network Address Translation Internet Protocol Security (IP SEC) Virtual Private Networks (VPN) Python (Programming Language) Microsoft Visio Network Planning and Design Network Monitoring
+18 more
Routing Open Shortest Path First (OSPF) Ansible Zero Trust Network Access Security Assertion Markup Language (SAML) Wide Area Networks Network Routers Google Cloud System Availability Firewalls (Computer Science) Juniper Palo Alto Networks Performance Monitor Check Point Firewalls Wireless Technologies Fortinet Terraform Cisco

Job description

  • Serve as a Tier-3 escalation engineer for Prisma SASE.
  • Troubleshoot advanced issues across Prisma SD-WAN, Prisma Access, GlobalProtect, IPsec, and cloud-delivered firewalling.
  • Lead high-severity incidents, customer communication, and root cause analysis (RCA).
  • Support full lifecycle management: onboarding, changes, upgrades, migrations, and decommissioning.
  • Enforce routing, segmentation, security policies, high availability, and resiliency standards.
  • Support advanced routing (BGP required, OSPF) and hybrid/cloud connectivity across AWS, Azure, and GCP.
  • Implement and support ZTNA, SWG, FWaaS, and identity integrations (SAML, MFA).
  • Contribute to automation (APIs, Python, Ansible, Terraform preferred) and improve monitoring/telemetry.
  • Maintain SOPs, runbooks, and escalation guides; mentor Tier-1 and Tier-2 engineers.
  • Collaborate with cross-functional teams to evolve Prisma SASE managed services.

Requirements

  • 10+ years of hands-on network engineering experience in enterprise or managed services.
  • Hands-on expertise with Prisma SD-WAN and Prisma Access.
  • Experience with Palo Alto, Fortinet, or Check Point firewalls.
  • Proficiency with network monitoring/performance tools and Visio.
  • Strong experience with routers, switches, firewalls, and WAN infrastructure.
  • Deep understanding of cloud-delivered security, SD-WAN overlays/underlays, traffic steering, and segmentation.
  • Advanced routing skills: BGP (required) and OSPF.
  • Experience supporting hybrid/cloud networking across AWS, Azure, and GCP.
  • Strong knowledge of HA, QoS, NAT, VPN, and TCP/IP fundamentals.
  • Required Certifications:
  • Palo Alto Networks Certified SD-WAN Engineer
  • Palo Alto Networks Certified Security Service Edge Engineer
  • Education: Bachelor’s degree in a related field or equivalent experience.

Preferred:

  • Palo Alto PCCSE certification.
  • Cisco CCNP or CCIE.
  • Experience with multi-vendor SD-WAN/SASE (Fortinet, Cisco, VeloCloud, Juniper Mist/SSR).
  • Prior network design or presales engineering experience.
  • Familiarity with wireless technologies and security intelligence sources (CERT, BugTraq).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on crbworkforce.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · WWC 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger · WWC 2025

Videos

See all

Related articles

See all