Palo Alto Network Engineer
System One
Springfield, VA, United States
2 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$166,400.0
Working hours
Shift work
Job source
Tech stack
Active Directory
Amazon Web Services
ARM Architecture
Microsoft Azure
Border Gateway Protocol
Configuration Management
Cyber Security
System Configuration
Network Address Translation
Hypertext Transfer Protocols (HTTP)
Internet Protocol Security (IP SEC)
Intrusion Detection and Prevention
+29 more
Virtual Private Networks (VPN)
Python (Programming Language)
Kerberos (Protocol)
Network Security
Lightweight Directory Access Protocols (LDAP)
Network Architecture
Network Planning and Design
Open Shortest Path First (OSPF)
OAuth
Public Key Infrastructure
Ansible
Zero Trust Network Access
Security Assertion Markup Language (SAML)
Wide Area Networks
Extensible Markup Language (XML)
Transport Layer Security
Google Cloud
Cloud Platform System
Firewalls (Computer Science)
Juniper
Information Technology
Palo Alto Networks
Cortex XSOAR Platform
BIG-IP Advanced Firewall Manager (AFM)
BIG-IP Access Policy Manager (APM)
Restful APIs
Cts+
Terraform
Cisco
Job description
- Lead the design, requirements analysis, testing, integration, and implementation of secure network architectures centered on the Palo Alto Networks ecosystem.
- Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment.
- Engineer and implement solutions for customer Change Requests (CRQs); assess impacts on enterprise transport and security activities and provide technically sound recommendations.
- Serve as the technical representative for assigned projects and coordinate issues with the appropriate owners, organizations, contract leadership, and customer leadership.
- Manage the full lifecycle of Palo Alto hardware and software, including complex hardware refreshes, PAN-OS upgrades, legacy-platform sustainment, physical troubleshooting, and line-card replacements.
- Develop, oversee, and maintain configuration-management processes, network architecture diagrams, technical documentation, integration and test plans, and Standard Operating Procedures (SOPs) for Palo Alto security platforms.
- Use Panorama for centralized policy management, including templates, device groups, inheritance, and consistent configuration across a diverse fleet of physical and virtual firewalls.
- Configure and maintain advanced security capabilities and profiles, including App-ID, User-ID, Content-ID, SSL Decryption, WildFire, NAT, IPSec VPNs, and threat prevention.
- Oversee security-incident reporting, documentation, investigation, and corrective-action development.
- Act as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network-security status, policies, procedures, and risks.
- Evaluate and report on new and emerging network-security and communications technologies to improve network capacity, performance, reliability, standardization, and security.
- Provide mentorship and technical oversight to junior engineers and serve as an escalation point for complex troubleshooting.
- Follow all customer network-security processes and procedures, maintain compliance with Government and QA standards, and ensure service-performance indicators are met or exceeded.
Requirements
- Security Clearance: Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph.
- A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments.
- Active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification.
- DoD 8140.01 and DoD 8570.01-M IAT Level II compliance (for example, Security+ CE).
- Ability to obtain and maintain a CSSP Infrastructure Support certification within 120 days of the start date.
- Deep practical knowledge of legacy Gen 2/Gen 3 Palo Alto hardware, including PA-3000 and PA-5000 series platforms, legacy CLI, hardware troubleshooting, and line-card replacements.
- Experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and VM-Series virtual firewalls in cloud environments such as AWS, Azure, GCP, or private-cloud.
- Proven expertise with Panorama for centralized policy management, template/device-group inheritance, and configuration deployment across a hybrid firewall fleet.
- Advanced understanding of BGP, OSPF, IPSec VPNs, NAT, TLS/SSL, mutual TLS (mTLS), HTTP, SAML, OAuth, OCSP revocation, DoD PKI, Kerberos, LDAP, and Active Directory.
- Experience with F5 technologies, including APM, AFM, and SSL Orchestrator (SSLO), and troubleshooting TLS/SSL handshake/connection issues.
- Strong network design, engineering, implementation, and troubleshooting skills, including ROM equipment lists and cost estimates.
- Knowledge of DISA and Intelligence Community security standards and requirements.
- Excellent interpersonal skills and technical judgment with the ability to work independently and support weekend/evening work if needed.
- Bachelor’s degree in IT, Cybersecurity, Computer Science, or a related field, with additional relevant experience considered in lieu of a degree.
Desired Qualifications
- Active Palo Alto Networks Certified Network Security Consultant (PCNSC) or Prisma Certified SASE Professional (PCSAE).
- F5 Networks Certified Technology Specialist (CTS).
- Cisco CCNP, CCVP, CCNA, CCDP, or equivalent.
- ITIL v3 Foundations and/or ISC2 CISSP Certification.
- Proficiency in Python and automation tools such as Ansible, Terraform, or Palo Alto XML/REST APIs.
- Hands-on experience with Cortex XDR or Cortex XSOAR.
- Experience with Palo Alto Networks Expedition for migration and rule consolidation.
- Knowledge of Zero Trust Network Access (ZTNA) architectures and additional security platforms (e.g., Juniper SRX, Cisco FTD/ASA).
- Master’s degree in related fields is a plus.
About the company
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
EM
Eli McGarvie
over 3 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
15 days ago
MH
Michael Hunger
Everything a Developer Needs to Know About MCP with Neo4j
about 1 year ago
CS
Christina Schaireiter
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
3 months ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago