> Markdown version of [/jobs/ext/3009905-data-security-analyst](https://www.wearedevelopers.com/jobs/ext/3009905-data-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Data Security Analyst - **Company:** GovCIO - **Location:** Austin, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $150,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Application Programming Interfaces (APIs), Amazon Web Services, Data Analysis, Spyware, Application Firewall, Application Lifecycle Management, ARM Architecture, Microsoft Azure, Border Gateway Protocol, Biometrics, Catalyst (Software), Cisco PIX, Cloud Computing, Cloud Engineering, Complex Networks, Cyber Security, Data Centers, Data Security, Data Systems, Dynamic Host Configuration Protocol, Network Address Translation, Domain Name System Security Extensions, Domain Name System (DNS), Data Flow Control, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Routing, Network Segmentation, Cisco Nexus Switches, Open Shortest Path First (OSPF), PCI Data Security Standards, Windows PowerShell, Role-Based Access Control, Ansible, Zero Trust Network Access, Security Information and Event Management, Software Engineering, TCP/IP, Virtual Local Area Networks, Software Vulnerability Management, Wireless Networks, Data Logging, Scripting, Computer Networking Systems, Identity Services Engine, Google Cloud, Computer Network Technologies, Firewalls (Computer Science), Information Technology, Cybercrime, Palo Alto Networks, CIS Benchmarks, Firepower, Restful APIs, Terraform, Cisco - **Published:** September 20, 2026 - **Apply:** https://dejobs.org/x/x/92F44945BD31474E8B36A8298EBC3724/job/ ## About the Role Bachelor's with 12+ years (or commensurate experience) * 10+ years of progressive experience in cybersecurity, network security, security engineering, or security operations, including substantial hands-on firewall administration and incident-response experience. * Deep expertise administering Palo Alto Networks next-generation firewalls in complex enterprise environments. * Advanced experience with Panorama , including centralized policy administration, device-group design, templates, HA workflows, logging, upgrades, troubleshooting, and configuration governance. * Strong practical knowledge of Palo Alto Strata security capabilities, including NGFW architecture, App-ID, User-ID, Content-ID, security profiles, decryption, segmentation, and policy optimization. * Strong experience using Palo Alto Cortex products or related XDR/EDR/SOAR/SIEM technologies for detection, investigation, incident response, threat hunting, and automation. * Demonstrated ability to investigate and resolve complex network-security issues using packet captures, firewall traffic logs, threat logs, system logs, routing information, and endpoint telemetry. * Strong Cisco networking background, including TCP/IP, DNS, DHCP, NAT, routing, switching, VLANs, VRFs, BGP/OSPF fundamentals, VPNs, network segmentation, and high-availability concepts. * Experience supporting Cisco security and network technologies, such as Cisco Secure Firewall/Firepower, ASA, ISE, Secure Network Analytics, Catalyst switching, Nexus switching, enterprise routing, and wireless platforms. * Thorough understanding of security principles including zero trust, least privilege, defense in depth, identity-aware access, network segmentation, threat prevention, encryption, logging, and vulnerability management. * Experience with security frameworks and control expectations such as NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 27001, PCI DSS, HIPAA, SOX, or similar requirements, as applicable. * Strong written and verbal communication skills, with the ability to explain complex technical risks and solutions to both technical and nontechnical stakeholders. Clearance Required: Must be able to attain and maintain an AOUSC Public Trust Preferred Skills and Experience * Master's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field * Palo Alto Networks certifications such as PCNSA, PCNSE,, or equivalent advanced Palo Alto Networks credentials. * Cisco certifications such as CCNA, CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, CCIE Security, or equivalent experience. * Experience with cloud networking and security in AWS, Microsoft Azure, and/or Google Cloud Platform, including cloud firewalls, transit architectures, virtual firewalls, security groups, and centralized logging. * Experience with infrastructure-as-code, automation, or scripting using Python, PowerShell, Ansible, Terraform, REST APIs, or Panorama APIs. * Experience with SIEM platforms, log pipelines, threat intelligence, vulnerability-management tools, and network detection and response capabilities. * Experience leading security projects, technical workstreams, audit remediation, control modernization, or enterprise-wide firewall migrations. #Dice #CHNO, * A valid photo ID must be presented during each interview * During the Hiring Process * Enhanced Biometrics ID verification screening * Background check, to include: * Criminal history (past 7 years) * Verification of your highest level of education * Verification of your employment history (past 7 years), based on information provided in your application ## Description * Architect, deploy, administer, and optimize Palo Alto Networks next-generation firewalls across data center, campus, branch, cloud, and remote-access environments. * Lead centralized firewall management using Palo Alto Panorama , including device groups, templates, template stacks, shared policy, role-based administration, configuration standards, software lifecycle management, and high-availability operations. * Design and maintain security policies using least privilege, application-aware controls, user identity, URL filtering, DNS security, TLS decryption where approved, threat prevention, WildFire analysis, anti-spyware, vulnerability protection, and file-blocking capabilities. * Lead the operational use of the Palo Alto Networks Strata portfolio to improve network security posture, policy consistency, visibility, segmentation, and operational resilience. * Deploy and operationalize Cortex capabilities for security analytics, endpoint detection and response, extended detection and response, incident investigation, automation, orchestration, and response improvement, as applicable to the enterprise environment. * Investigate security alerts, anomalous traffic, malware activity, policy violations, data-exfiltration indicators, and firewall-related incidents; coordinate containment, eradication, recovery, and post-incident review activities. * Develop and tune detections, correlation logic, dashboards, investigations, and response playbooks using Cortex tooling and integrated security platforms. * Build and maintain secure network segmentation strategies, including zone-based architecture, east-west traffic controls, microsegmentation principles, and protections for high-value data systems. * Partner with Cisco network engineering teams to integrate secure routing, switching, VPN, wireless, identity, and network-access controls. Troubleshoot issues across Cisco and Palo Alto environments without weakening security controls. * Support and strengthen Cisco security technologies and enterprise network services, which may include Cisco ASA/Firepower, Cisco Secure Firewall Management Center, Cisco ISE, Cisco Secure Network Analytics, VPN, routing, switching, and wireless infrastructure. * Review, approve, implement, and document firewall and network-security change requests according to established change-management, risk-review, and emergency-change processes. * Perform regular firewall rulebase reviews, access recertifications, risk assessments, policy cleanup, unused-rule retirement, object normalization, and security-control validation. * Maintain accurate network security diagrams, data-flow documentation, firewall standards, operational runbooks, architecture decisions, and escalation procedures. * Conduct vulnerability and configuration assessments; validate remediation of high-risk findings affecting firewall, network, endpoint, and data-security controls. * Collaborate with Security Operations Center, Incident Response, Cloud Engineering, Infrastructure, Application Development, Governance/Risk/Compliance, and Audit teams on security requirements and remediation plans. * Provide technical mentorship to analysts and engineers; establish engineering standards and lead complex troubleshooting and root-cause analysis. * Evaluate emerging technologies, platform features, and threat trends; recommend pragmatic improvements to the enterprise security roadmap. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)