> Markdown version of [/jobs/ext/3096750-sr-firewall-engineer-checkpoint-palo-alto-focus-progression](https://www.wearedevelopers.com/jobs/ext/3096750-sr-firewall-engineer-checkpoint-palo-alto-focus-progression). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Firewall Engineer, Checkpoint & Palo Alto Focus, Progression - **Company:** Tampa Electric Company - **Location:** Lutz, FL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Firewall, Microsoft Azure, Border Gateway Protocol, VoIP, Cyber Security, Dynamic Host Configuration Protocol, DDoS Mitigation, Domain Name System (DNS), Supervisory Control and Data Acquisition (SCADA), Internet Protocol Security (IP SEC), Intrusion Detection Systems, Storage Area Network (SAN), Virtual Private Networks (VPN), Multi-protocol Systems, Information Systems Security Architecture Professional, Session Initiation Protocols, Network Security, Network Architecture, Network Forensics, Routing, Network Segmentation, Packet Analyzer, Open Shortest Path First (OSPF), Wide Area Networks, Wireless Access Point, Wi-Fi Technology, Network Routers, Computer Networking Systems, Load Balancing, Computer Network Technologies, System Availability, Hyperconverged Infrastructure, Firewalls (Computer Science), Information Technology, Routing & Switching, Communication Devices, Smartgrid, Cisco, SSL VPN, Citrix Netscaler, Vmware - **Published:** September 26, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/86607553/1 ## About the Role * Strong hands on Palo Alto experience in production * Previous Checkpoint experience a plus * Proven experience designing and supporting VPN solutions * Experience in high availability or large scale enterprise environments Note that this position can be hired at any level within the job family of progression based on Education and years of experience but is ideally targeting to hire at the Lead level (3rd level in the JD)., Required: High School Diploma or GED Preferred: Bachelor's degree in Computer Science, Engineering, Math, or equivalent IT discipline (MIS). LICENSES/CERTIFICATIONS Required: Has obtained at least three or two, with the condition to obtain a third certification within one year of hire for this position, related network, system, operating system, or information security professional certifications: (e.g., Microsoft Certified Solutions Associate (MCSA), Microsoft Certified Solutions Expert (MCSE), VMware Certified Professional (VCP), Cisco Certified Network Associate (CCNA), Cisco Certified Network Professional (CCNP), Certified Ethical Hacker (CEH), GIAC Network Forensic Analyst (GNFA) or other GIAC Certifications, Certified Information Systems Security Professional (CISSP), Certified SCADA Security Architect (CSSA). Preferred: ITIL v3, CCNP, MCSE, VCP, GNFA, CISSP, Required: Minimum eight (8) years of related hands-on experience implementing and maintaining Windows, VMware, firewall support, DDoS protection, proxies, WAFs, NetScaler load balancers, Storage Area Networks, or Cisco Networking. In lieu of some experience listed above, may consider six (6) years of related experience with an Associate's Degree or four (4) years of related experience with a Bachelor's Degree in Computer Science, Engineering, Math, or equivalent IT discipline (e.g., MIS)., * Expert knowledge of network, server, and security controls infrastructure regardless of the complexity * Thorough working knowledge for most of the following technologies and operational functions: switching, routing, DNS/DHCP, Windows Active Directory, VMware, Voice over IP, Storage Area Networking, firewall support, DDoS protection, proxy, WAF, NetScaler load balancing, network segmentation, NAC, IDS/IPS, antivirus support, cyber security best practices, and networking/hardware installation and maintenance * Thorough working knowledge with packet analysis and denial of service protection * Strong critical thinking, analytical, problem solving, and risk assessment skills as well as strong listening and communication skills (oral and written) * Ability to present issues and topics of a complex technical nature to non-technical audiences * Excellent interpersonal, mentoring, and organizational skills * Good working knowledge of the processes that ensure compliance with regulatory or industry requirements such as NERC CIP, SOX, and PCI ## Description The Network & Systems Security Analyst (Firewall Engineer), is responsible for planning/designing, implementing, and supporting new and existing network, server, storage infrastructure. This role is also responsible for ensuring all network security controls (i.e., firewalls, web application firewalls [WAF], proxies, network segmentation, NAC, ACLs, etc.) are implemented and managed per corporate information security standards. Additionally, responsibilities include assessing enterprise assets and critical assets for secure configurations and maintaining and enforcing regulations and standards such as NERC Critical Infrastructure Protection (CIP), Sarbanes-Oxley (SOX), and Payment Card Industry (PCI). Responsible for the design, planning, operation, maintenance, and support of the TECO and NMGC network infrastructure. This includes primary accountability for network technologies such as route/switch, on-premise LAN/WAN, IPAM, Wi-Fi, ISP management, site-to-site VPNs, proxies (forward and reverse), perimeter firewall management, DNS, Azure cloud environments, automation, NAC/user access, hyperconverged infrastructure, and overall network security. Partners with the Telecommunication teams on establishing/upgrading existing circuits/communication links. Responsible for the NERC Cyber Infrastructure Protection and disaster recovery plans. Responsible for VoIP, SIP, DHCP, DNS, TCP/IP routing and routing protocols such as OSPF and BGP, binary mathematics, NAT, PAT, IPsec and SSL VPN technologies, GRE tunneling, route redistribution, traffic shaping, port-level filtering, SD-WAN, MPLS and other communications related technologies. Responsible for the installation, configuration, and maintenance of all WAN and LAN connectivity which includes core and campus switches, routers, firewalls, wireless access points, WAN scalers and load balancer technologies. Responsible for the design, installation, configuration, and maintenance of DNP over IP and serial SCADA communications between the primary and backup control centers, power plants, solar sites, and substations. Responsible for the configuration and maintenance of Smart GRID communication hardware switches and routers between the primary and backup control centers. NETWORK & SYSTEMS SECURITY ANALYST LEAD In addition to the duties & responsibilities of the Analyst Sr, has increased responsibilities in consulting on small project design and plans. May serve as a project lead, cross-train peers, and mentor Analysts. Works under general direction. ADDITIONAL DUTIES AND RESPONSIBILITIES 1. Monitors, troubleshoots, diagnoses, and remedies server, network, DDoS protection, NetScaler load balancers, and security controls related problems and failures. 2. Installs and configures server and network related hardware/software which meet the company's security standards. 3. Design and planning required for small projects. 4. Project leadership, consulting, or cross-train peers. RELATIONSHIPS Key Internal: Consults with all IT departments as needed. This role requires the ability to provide technical direction to members of project teams. Key External: Consults with vendor technical specialists and account managers for the various technologies deployed. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Generating code with Angular schematics](https://www.wearedevelopers.com/videos/129-generating-code-with-angular-schematics) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) ## Related Articles - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)