Data Security Analyst

Cisco Systems, Inc.
United States
2 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$150,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Application Programming Interfaces (APIs) Amazon Web Services Data Analysis Spyware Application Firewall Application Lifecycle Management ARM Architecture Microsoft Azure Border Gateway Protocol Catalyst (Software) Cisco PIX
+46 more
Cloud Computing Cloud Engineering Complex Networks Cyber Security Data Centers Data Security Data Systems Dynamic Host Configuration Protocol Network Address Translation Domain Name System Security Extensions Domain Name System (DNS) Data Flow Control Intrusion Detection and Prevention Virtual Private Networks (VPN) Python (Programming Language) Network Security Routing Network Segmentation Cisco Nexus Switches Open Shortest Path First (OSPF) PCI Data Security Standards Windows PowerShell Role-Based Access Control Ansible Zero Trust Network Access Security Information and Event Management Software Engineering TCP/IP Virtual Local Area Networks Software Vulnerability Management Wireless Networks Data Logging Scripting Computer Networking Systems Identity Services Engine Google Cloud Computer Network Technologies Firewalls (Computer Science) Information Technology Cybercrime Palo Alto Networks CIS Benchmarks Firepower Restful APIs Terraform Cisco

Job description

GovCIO is seeking a highly experienced Data Security Analyst - Master to lead the design, implementation, operation, and continuous improvement of enterprise security controls that protect data, networks, applications, and cloud-connected environments. This senior individual-contributor role requires deep hands-on expertise with the Palo Alto Networks security portfolio-particularly next-generation firewalls, Panorama, Cortex, and Strata-as well as strong Cisco networking and security capabilities., * Architect, deploy, administer, and optimize Palo Alto Networks next-generation firewalls across data center, campus, branch, cloud, and remote-access environments.

  • Lead centralized firewall management using Palo Alto Panorama, including device groups, templates, template stacks, shared policy, role-based administration, configuration standards, software lifecycle management, and high-availability operations.
  • Design and maintain security policies using least privilege, application-aware controls, user identity, URL filtering, DNS security, TLS decryption where approved, threat prevention, WildFire analysis, anti-spyware, vulnerability protection, and file-blocking capabilities.
  • Lead the operational use of the Palo Alto Networks Strata portfolio to improve network security posture, policy consistency, visibility, segmentation, and operational resilience.
  • Deploy and operationalize Cortex capabilities for security analytics, endpoint detection and response, extended detection and response, incident investigation, automation, orchestration, and response improvement, as applicable to the enterprise environment.
  • Investigate security alerts, anomalous traffic, malware activity, policy violations, data-exfiltration indicators, and firewall-related incidents; coordinate containment, eradication, recovery, and post-incident review activities.
  • Develop and tune detections, correlation logic, dashboards, investigations, and response playbooks using Cortex tooling and integrated security platforms.
  • Build and maintain secure network segmentation strategies, including zone-based architecture, east-west traffic controls, microsegmentation principles, and protections for high-value data systems.
  • Partner with Cisco network engineering teams to integrate secure routing, switching, VPN, wireless, identity, and network-access controls. Troubleshoot issues across Cisco and Palo Alto environments without weakening security controls.
  • Support and strengthen Cisco security technologies and enterprise network services, which may include Cisco ASA/Firepower, Cisco Secure Firewall Management Center, Cisco ISE, Cisco Secure Network Analytics, VPN, routing, switching, and wireless infrastructure.
  • Review, approve, implement, and document firewall and network-security change requests according to established change-management, risk-review, and emergency-change processes.
  • Perform regular firewall rulebase reviews, access recertifications, risk assessments, policy cleanup, unused-rule retirement, object normalization, and security-control validation.
  • Maintain accurate network security diagrams, data-flow documentation, firewall standards, operational runbooks, architecture decisions, and escalation procedures.
  • Conduct vulnerability and configuration assessments; validate remediation of high-risk findings affecting firewall, network, endpoint, and data-security controls.
  • Collaborate with Security Operations Center, Incident Response, Cloud Engineering, Infrastructure, Application Development, Governance/Risk/Compliance, and Audit teams on security requirements and remediation plans.
  • Provide technical mentorship to analysts and engineers; establish engineering standards and lead complex troubleshooting and root-cause analysis.
  • Evaluate emerging technologies, platform features, and threat trends; recommend pragmatic improvements to the enterprise security roadmap. *

Requirements

Bachelor’s with 12+ years (or commensurate experience)

  • 10+ years of progressive experience i n cybersecurity, network security, security engineering, or security operations, including substantial hands-on firewall administration and incident-response experience.
  • Deep expertise administering Palo Alto Networks next-generation firewalls in complex enterprise environments.
  • Advanced experience with Panorama, including centralized policy administration, device-group design, templates, HA workflows, logging, upgrades, troubleshooting, and configuration governance.
  • Strong practical knowledge of Palo Alto Strata security capabilities, including NGFW architecture, App-ID, User-ID, Content-ID, security profiles, decryption, segmentation, and policy optimization.
  • Strong experience using Palo Alto Cortex products or related XDR/EDR/SOAR/SIEM technologies for detection, investigation, incident response, threat hunting, and automation.
  • Demonstrated ability to investigate and resolve complex network-security issues using packet captures, firewall traffic logs, threat logs, system logs, routing information, and endpoint telemetry.
  • Strong Cisco networking background, including TCP/IP, DNS, DHCP, NAT, routing, switching, VLANs, VRFs, BGP/OSPF fundamentals, VPNs, network segmentation, and high-availability concepts.
  • Experience supporting Cisco security and network technologies, such as Cisco Secure Firewall/Firepower, ASA, ISE, Secure Network Analytics, Catalyst switching, Nexus switching, enterprise routing, and wireless platforms.
  • Thorough understanding of security principles including zero trust, least privilege, defense in depth, identity-aware access, network segmentation, threat prevention, encryption, logging, and vulnerability management.
  • Experience with security frameworks and control expectations such as NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 27001, PCI DSS, HIPAA, SOX, or similar requirements, as applicable.
  • Strong written and verbal communication skills, with the ability to explain complex technical risks and solutions to both technical and nontechnical stakeholders. *

Clearance Required: Must be able to attain and maintain an AOPublic Trust

Preferred Skills and Experience

  • Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field
  • Palo Alto Networks certifications such as PCNSA, PCNSE,, or equivalent advanced Palo Alto Networks credentials.
  • Cisco certifications such as CCNA, CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, CCIE Security, or equivalent experience.
  • Experience with cloud networking and security in AWS, Microsoft Azure, and/or Google Cloud Platform, including cloud firewalls, transit architectures, virtual firewalls, security groups, and centralized logging.
  • Experience with infrastructure-as-code, automation, or scripting using Python, PowerShell, Ansible, Terraform, REST APIs, or Panorama APIs.
  • Experience with SIEM platforms, log pipelines, threat intelligence, vulnerability-management tools, and network detection and response capabilities.
  • Experience leading security projects, technical workstreams, audit remediation, control modernization, or enterprise-wide firewall migrations.

Dice

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all