Data Security Analyst

GovCIO
Austin, TX, United States
1 day ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$150,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Application Programming Interfaces (APIs) Amazon Web Services Data Analysis Spyware Application Firewall Application Lifecycle Management ARM Architecture Microsoft Azure Border Gateway Protocol Biometrics Catalyst (Software)
+47 more
Cisco PIX Cloud Computing Cloud Engineering Complex Networks Cyber Security Data Centers Data Security Data Systems Dynamic Host Configuration Protocol Network Address Translation Domain Name System Security Extensions Domain Name System (DNS) Data Flow Control Intrusion Detection and Prevention Virtual Private Networks (VPN) Python (Programming Language) Network Security Routing Network Segmentation Cisco Nexus Switches Open Shortest Path First (OSPF) PCI Data Security Standards Windows PowerShell Role-Based Access Control Ansible Zero Trust Network Access Security Information and Event Management Software Engineering TCP/IP Virtual Local Area Networks Software Vulnerability Management Wireless Networks Data Logging Scripting Computer Networking Systems Identity Services Engine Google Cloud Computer Network Technologies Firewalls (Computer Science) Information Technology Cybercrime Palo Alto Networks CIS Benchmarks Firepower Restful APIs Terraform Cisco

Job description

  • Architect, deploy, administer, and optimize Palo Alto Networks next-generation firewalls across data center, campus, branch, cloud, and remote-access environments.
  • Lead centralized firewall management using Palo Alto Panorama , including device groups, templates, template stacks, shared policy, role-based administration, configuration standards, software lifecycle management, and high-availability operations.
  • Design and maintain security policies using least privilege, application-aware controls, user identity, URL filtering, DNS security, TLS decryption where approved, threat prevention, WildFire analysis, anti-spyware, vulnerability protection, and file-blocking capabilities.
  • Lead the operational use of the Palo Alto Networks Strata portfolio to improve network security posture, policy consistency, visibility, segmentation, and operational resilience.
  • Deploy and operationalize Cortex capabilities for security analytics, endpoint detection and response, extended detection and response, incident investigation, automation, orchestration, and response improvement, as applicable to the enterprise environment.
  • Investigate security alerts, anomalous traffic, malware activity, policy violations, data-exfiltration indicators, and firewall-related incidents; coordinate containment, eradication, recovery, and post-incident review activities.
  • Develop and tune detections, correlation logic, dashboards, investigations, and response playbooks using Cortex tooling and integrated security platforms.
  • Build and maintain secure network segmentation strategies, including zone-based architecture, east-west traffic controls, microsegmentation principles, and protections for high-value data systems.
  • Partner with Cisco network engineering teams to integrate secure routing, switching, VPN, wireless, identity, and network-access controls. Troubleshoot issues across Cisco and Palo Alto environments without weakening security controls.
  • Support and strengthen Cisco security technologies and enterprise network services, which may include Cisco ASA/Firepower, Cisco Secure Firewall Management Center, Cisco ISE, Cisco Secure Network Analytics, VPN, routing, switching, and wireless infrastructure.
  • Review, approve, implement, and document firewall and network-security change requests according to established change-management, risk-review, and emergency-change processes.
  • Perform regular firewall rulebase reviews, access recertifications, risk assessments, policy cleanup, unused-rule retirement, object normalization, and security-control validation.
  • Maintain accurate network security diagrams, data-flow documentation, firewall standards, operational runbooks, architecture decisions, and escalation procedures.
  • Conduct vulnerability and configuration assessments; validate remediation of high-risk findings affecting firewall, network, endpoint, and data-security controls.
  • Collaborate with Security Operations Center, Incident Response, Cloud Engineering, Infrastructure, Application Development, Governance/Risk/Compliance, and Audit teams on security requirements and remediation plans.
  • Provide technical mentorship to analysts and engineers; establish engineering standards and lead complex troubleshooting and root-cause analysis.
  • Evaluate emerging technologies, platform features, and threat trends; recommend pragmatic improvements to the enterprise security roadmap.

Requirements

Bachelor’s with 12+ years (or commensurate experience)

  • 10+ years of progressive experience in cybersecurity, network security, security engineering, or security operations, including substantial hands-on firewall administration and incident-response experience.
  • Deep expertise administering Palo Alto Networks next-generation firewalls in complex enterprise environments.
  • Advanced experience with Panorama , including centralized policy administration, device-group design, templates, HA workflows, logging, upgrades, troubleshooting, and configuration governance.
  • Strong practical knowledge of Palo Alto Strata security capabilities, including NGFW architecture, App-ID, User-ID, Content-ID, security profiles, decryption, segmentation, and policy optimization.
  • Strong experience using Palo Alto Cortex products or related XDR/EDR/SOAR/SIEM technologies for detection, investigation, incident response, threat hunting, and automation.
  • Demonstrated ability to investigate and resolve complex network-security issues using packet captures, firewall traffic logs, threat logs, system logs, routing information, and endpoint telemetry.
  • Strong Cisco networking background, including TCP/IP, DNS, DHCP, NAT, routing, switching, VLANs, VRFs, BGP/OSPF fundamentals, VPNs, network segmentation, and high-availability concepts.
  • Experience supporting Cisco security and network technologies, such as Cisco Secure Firewall/Firepower, ASA, ISE, Secure Network Analytics, Catalyst switching, Nexus switching, enterprise routing, and wireless platforms.
  • Thorough understanding of security principles including zero trust, least privilege, defense in depth, identity-aware access, network segmentation, threat prevention, encryption, logging, and vulnerability management.
  • Experience with security frameworks and control expectations such as NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 27001, PCI DSS, HIPAA, SOX, or similar requirements, as applicable.
  • Strong written and verbal communication skills, with the ability to explain complex technical risks and solutions to both technical and nontechnical stakeholders.

Clearance Required: Must be able to attain and maintain an AOUSC Public Trust

Preferred Skills and Experience

  • Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field
  • Palo Alto Networks certifications such as PCNSA, PCNSE,, or equivalent advanced Palo Alto Networks credentials.
  • Cisco certifications such as CCNA, CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, CCIE Security, or equivalent experience.
  • Experience with cloud networking and security in AWS, Microsoft Azure, and/or Google Cloud Platform, including cloud firewalls, transit architectures, virtual firewalls, security groups, and centralized logging.
  • Experience with infrastructure-as-code, automation, or scripting using Python, PowerShell, Ansible, Terraform, REST APIs, or Panorama APIs.
  • Experience with SIEM platforms, log pipelines, threat intelligence, vulnerability-management tools, and network detection and response capabilities.
  • Experience leading security projects, technical workstreams, audit remediation, control modernization, or enterprise-wide firewall migrations.

Dice

CHNO, * A valid photo ID must be presented during each interview

  • During the Hiring Process
  • Enhanced Biometrics ID verification screening
  • Background check, to include:
  • Criminal history (past 7 years)
  • Verification of your highest level of education
  • Verification of your employment history (past 7 years), based on information provided in your application

Benefits & conditions

At GovCIO, we consistently hear that meaningful work and a collaborative team environment are two of the top reasons our employees enjoy working here. In addition, our employees have access to a range of perks and benefits to support their personal and professional well-being, beyond the standard company offered health benefits, including:

  • Employee Assistance Program (EAP)
  • Corporate Discounts
  • Learning & Development platform, to include certification preparation content
  • Training, Education and Certification Assistance*
  • Referral Bonus Program
  • Internal Mobility Program
  • Pet Insurance
  • Flexible Work Environment

*Available to full-time employees

Our employees’ unique talents and contributions are the driving force behind our success in supporting our customers, which ultimately fuels the success of our company. Join us and be a part of a culture that invests in its people and prioritizes continuous enhancement of the employee experience.

We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, disability, or status as a protected veteran. EOE, including disability/vets.

Posted Pay Range

The posted pay range, if referenced, reflects the range expected for this position at the commencement of employment, however, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, education, experience, and internal equity. The total compensation package for this position may also include other compensation elements, to be discussed during the hiring process. If hired, employee will be in an “at-will position” and the GovCIO reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, GovCIO or individual department/team performance, and market factors.

About the company

GovCIO is a team of transformers–people who are passionate about transforming government IT. Every day, we make a positive impact by delivering innovative IT services and solutions that improve how government agencies operate and serve our citizens.

But we can’t do it alone. We need great people to help us do great things - for our customers, our culture, and our ability to attract other great people. We are changing the face of government IT and building a workforce that fuels this mission. Are you ready to be a transformer?

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger · World Congress 2025

Videos

See all

Related articles

See all