> Markdown version of [/jobs/ext/2256769-palo-alto-network-engineer](https://www.wearedevelopers.com/jobs/ext/2256769-palo-alto-network-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Palo Alto Network Engineer - **Company:** System One - **Location:** Springfield, VA, United States - **Experience:** Expert - **Salary:** $166,400.0 - **Contract:** Temporary to permanent - **Skills:** Active Directory, Amazon Web Services, ARM Architecture, Microsoft Azure, Border Gateway Protocol, Configuration Management, Cyber Security, System Configuration, Network Address Translation, Hypertext Transfer Protocols (HTTP), Internet Protocol Security (IP SEC), Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Kerberos (Protocol), Network Security, Lightweight Directory Access Protocols (LDAP), Network Architecture, Network Planning and Design, Open Shortest Path First (OSPF), OAuth, Public Key Infrastructure, Ansible, Zero Trust Network Access, Security Assertion Markup Language (SAML), Wide Area Networks, Extensible Markup Language (XML), Transport Layer Security, Google Cloud, Cloud Platform System, Firewalls (Computer Science), Juniper, Information Technology, Palo Alto Networks, Cortex XSOAR Platform, BIG-IP Advanced Firewall Manager (AFM), BIG-IP Access Policy Manager (APM), Restful APIs, Cts+, Terraform, Cisco - **Published:** August 26, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9116922/palo-alto-network-engineer ## About the Role * Security Clearance: Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph. * A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments. * Active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. * DoD 8140.01 and DoD 8570.01-M IAT Level II compliance (for example, Security+ CE). * Ability to obtain and maintain a CSSP Infrastructure Support certification within 120 days of the start date. * Deep practical knowledge of legacy Gen 2/Gen 3 Palo Alto hardware, including PA-3000 and PA-5000 series platforms, legacy CLI, hardware troubleshooting, and line-card replacements. * Experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and VM-Series virtual firewalls in cloud environments such as AWS, Azure, GCP, or private-cloud. * Proven expertise with Panorama for centralized policy management, template/device-group inheritance, and configuration deployment across a hybrid firewall fleet. * Advanced understanding of BGP, OSPF, IPSec VPNs, NAT, TLS/SSL, mutual TLS (mTLS), HTTP, SAML, OAuth, OCSP revocation, DoD PKI, Kerberos, LDAP, and Active Directory. * Experience with F5 technologies, including APM, AFM, and SSL Orchestrator (SSLO), and troubleshooting TLS/SSL handshake/connection issues. * Strong network design, engineering, implementation, and troubleshooting skills, including ROM equipment lists and cost estimates. * Knowledge of DISA and Intelligence Community security standards and requirements. * Excellent interpersonal skills and technical judgment with the ability to work independently and support weekend/evening work if needed. * Bachelor's degree in IT, Cybersecurity, Computer Science, or a related field, with additional relevant experience considered in lieu of a degree. Desired Qualifications * Active Palo Alto Networks Certified Network Security Consultant (PCNSC) or Prisma Certified SASE Professional (PCSAE). * F5 Networks Certified Technology Specialist (CTS). * Cisco CCNP, CCVP, CCNA, CCDP, or equivalent. * ITIL v3 Foundations and/or ISC2 CISSP Certification. * Proficiency in Python and automation tools such as Ansible, Terraform, or Palo Alto XML/REST APIs. * Hands-on experience with Cortex XDR or Cortex XSOAR. * Experience with Palo Alto Networks Expedition for migration and rule consolidation. * Knowledge of Zero Trust Network Access (ZTNA) architectures and additional security platforms (e.g., Juniper SRX, Cisco FTD/ASA). * Master's degree in related fields is a plus. ## Description * Lead the design, requirements analysis, testing, integration, and implementation of secure network architectures centered on the Palo Alto Networks ecosystem. * Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment. * Engineer and implement solutions for customer Change Requests (CRQs); assess impacts on enterprise transport and security activities and provide technically sound recommendations. * Serve as the technical representative for assigned projects and coordinate issues with the appropriate owners, organizations, contract leadership, and customer leadership. * Manage the full lifecycle of Palo Alto hardware and software, including complex hardware refreshes, PAN-OS upgrades, legacy-platform sustainment, physical troubleshooting, and line-card replacements. * Develop, oversee, and maintain configuration-management processes, network architecture diagrams, technical documentation, integration and test plans, and Standard Operating Procedures (SOPs) for Palo Alto security platforms. * Use Panorama for centralized policy management, including templates, device groups, inheritance, and consistent configuration across a diverse fleet of physical and virtual firewalls. * Configure and maintain advanced security capabilities and profiles, including App-ID, User-ID, Content-ID, SSL Decryption, WildFire, NAT, IPSec VPNs, and threat prevention. * Oversee security-incident reporting, documentation, investigation, and corrective-action development. * Act as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network-security status, policies, procedures, and risks. * Evaluate and report on new and emerging network-security and communications technologies to improve network capacity, performance, reliability, standardization, and security. * Provide mentorship and technical oversight to junior engineers and serve as an escalation point for complex troubleshooting. * Follow all customer network-security processes and procedures, maintain compliance with Government and QA standards, and ensure service-performance indicators are met or exceeded. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)