Lead Network Security Engineer

Palo Alto, Inc.
United States
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Application Firewall Bash Shell Border Gateway Protocol Cyber Security System Configuration Dynamic Host Configuration Protocol Network Address Translation Domain Name System (DNS) Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Intrusion Detection Systems
+24 more
Virtual Private Networks (VPN) Python (Programming Language) Network Security Log Analysis Network Architecture Network Diagrams Network Monitoring Routing Network Protocols Open Shortest Path First (OSPF) Public Key Infrastructure Remote Access Technology Ansible Security Information and Event Management Simple Network Management Protocols TCP/IP Virtual Local Area Networks SSL Certificate Management Scripting Transport Layer Security Load Balancing In-Plane Switching (IPS) Firewall Services Module Vulnerability Analysis

Job description

  • Design and implement Palo Alto firewall policies, NAT rules, VPN configurations, and security zones.
  • Deploy, configure, and manage Palo Alto firewalls including policies, NAT, VPN, IPS, and threat prevention features.
  • Demonstrate expertise in deploying, configuring, and managing Palo Alto firewall and VPN solutions across on-premises, cloud, and remote access environments, ensuring seamless integration and security.
  • Define, configure, and optimize firewall policies and rules.
  • Perform troubleshooting and root cause analysis for network security incidents and firewall-related issues.
  • Manage security zones, access control policies, and URL filtering.
  • Manage and support enterprise certificate lifecycle processes, including certificate issuance, renewal, revocation, and compliance monitoring, preferably using Venafi.
  • Plan and execute firewall upgrades, patches, and migrations with minimal downtime.
  • Monitor and respond to security events and incidents related to firewalls and network devices.
  • Perform regular firewall rule reviews to optimize security and ensure compliance with security best practices while ensuring business continuity.
  • Ensure security of routing protocols (BGP, OSPF), VLANs, and load balancing across the network.
  • Involve in security audits, vulnerability assessments, and incident response to ensure network security compliance.
  • Monitor network performance and proactively address bottlenecks, latency issues, and security breaches.
  • Maintain detailed documentation for firewall configurations, security policies, network diagrams, and certificate management processes.
  • Oncall rotation one week, every 5 weeks. Oncall schedule: Monday 7AM to Monday 7AM.
  • Weekend support as needed for weekend deployments.

Requirements

  • 10+ years of experience in Network Security Engineering.
  • 7+ years of strong experience in Palo Alto Firewall administration.
  • Hands-on experience with certificate management is required; experience with Venafi is preferred.
  • Experience managing digital certificates, PKI infrastructure, certificate lifecycle management, and certificate-related security controls.
  • Experience in log analysis, incident response, and security monitoring.
  • Hands-on with VPNs (SSL/IPSec), NAT, IDS/IPS, Threat Prevention, and URL Filtering.
  • In-depth knowledge of TCP/IP, routing, VLANs, NAT, VPN, IPS, IDS, and general network architecture.
  • Understanding of network protocols (TCP/IP, BGP, OSPF, VLANs, DHCP, DNS, NAT, SNMP, IPsec, GRE, VXLAN).
  • Must have excellent understanding of security architecture and integration.
  • Strong proficiency in scripting (Python, Bash) and automation (Ansible)
  • Experience with change management and ITIL-based processes.
  • Strong troubleshooting and analytical skills.
  • Any experience with AI will be a huge plus.
  • Excellent communication and documentation skills.
  • Able to participate in oncall rotation schedule. One week for every 5 weeks. Monday 7AM to Monday 7AM.
  • Nice to have: Certifications such as PCNSE, PCNSA, CISSP, or CCNP.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · WWC 2024

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

1:51 min

Overview of the three Google Maps routing applications

Germán Álvarez · LIVE

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger · WWC 2025

Videos

See all

Related articles

See all