Palo Alto Integration Engineer, MID

Digital Global Connectors
McLean, VA, United States
20 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$110,000.0 - $140,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Application Programming Interfaces (APIs) Amazon Web Services Spyware Application Firewall ARM Architecture Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Configuration Management CompTIA Network+
+34 more
CompTIA Security+ Cyber Security Computer Networks Data Centers Domain Name System Security Extensions Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Virtual Private Networks (VPN) Information Systems Security Architecture Professional Python (Programming Language) Network Security Network Troubleshooting Log Analysis Routing Network Segmentation Windows PowerShell Zero Trust Network Access Runbook Security Information and Event Management Systems Integration TCP/IP Virtual Local Area Networks Data Logging Scripting Transport Layer Security Mitre Att&ck Firewalls (Computer Science) Infrastructure Automation Frameworks Information Technology Palo Alto Networks CIS Benchmarks Firewall Services Module Prisma Cloud Platform Cisco

Job description

Digital Global Connectors (DGC) is seeking a Palo Alto Integration Engineer, MID to support the engineering, implementation, administration, and continuous improvement of enterprise Palo Alto Networks security infrastructure in a federal government environment.

This is a local, on-site position requiring a daily commute to the customer site in the Washington, DC area. Only candidates who currently reside within a reasonable daily commuting distance of the worksite will be considered. This position is not remote, and candidates seeking to relocate to the area at a later date will not be considered for this opening.

The Palo Alto Integration Engineer will work as part of a network and cybersecurity engineering team supporting Palo Alto Networks Next-Generation Firewalls (NGFW), Panorama, Prisma Access, GlobalProtect, Prisma Cloud, and Cortex XDR capabilities. The engineer will work closely with senior security engineers, network engineers, cloud operations personnel, and Government stakeholders to maintain secure, reliable, and compliant network security services.

The ideal candidate has hands-on Palo Alto Networks experience, strong enterprise networking fundamentals, and experience supporting cybersecurity operations in environments governed by Federal security and compliance requirements.

Key Responsibilities

Palo Alto NGFW Engineering & Administration

  • Engineer, implement, configure, administer, and troubleshoot Palo Alto Networks Next-Generation Firewall infrastructure across perimeter, internal segmentation, data center, and cloud-connected environments.
  • Develop and maintain firewall security policies using Palo Alto Networks App-ID, User-ID, and Content-ID capabilities.
  • Configure and maintain threat prevention capabilities, including antivirus, anti-spyware, vulnerability protection, URL filtering, file blocking, WildFire, and DNS Security.
  • Assist with the implementation and maintenance of SSL/TLS decryption policies.
  • Perform firewall rule reviews, rule-base optimization, shadow-rule identification, and security policy lifecycle management.
  • Troubleshoot firewall connectivity, performance, routing, and security policy issues and perform root-cause analysis.
  • Analyze NGFW traffic, threat, and security logs to support troubleshooting, security monitoring, and incident investigations.

Panorama & Centralized Management

  • Administer and maintain Palo Alto Networks Panorama centralized management capabilities.
  • Configure and maintain Panorama device groups, templates, shared policies, pre-rules, and post-rules.
  • Support onboarding and configuration management of Palo Alto Networks firewalls through Panorama.
  • Monitor Panorama platform health, device connectivity, synchronization, and policy deployment.
  • Support Panorama upgrades, patches, configuration changes, and operational maintenance.
  • Generate operational, security, and compliance reports through Panorama.

Prisma Access & GlobalProtect

  • Support the administration and maintenance of Palo Alto Networks Prisma Access capabilities.
  • Configure and troubleshoot GlobalProtect remote-access services, gateways, agents, and authentication integrations.
  • Monitor Prisma Access availability, connectivity, performance, and security effectiveness.
  • Maintain and optimize cloud-delivered security policies, URL filtering, and threat prevention configurations.

Security Operations & Threat Prevention

  • Monitor and analyze Palo Alto Networks threat prevention logs, WildFire results, and security events.
  • Assist with tuning threat prevention profiles and firewall policies to improve security effectiveness and reduce false positives.
  • Support cybersecurity incident response activities through firewall log analysis, traffic investigation, policy analysis, and containment support.
  • Assist with Cortex XDR monitoring, alert triage, prevention policy administration, and detection-content tuning.
  • Support the use of MITRE ATT&CK concepts in security monitoring and detection activities.

Cloud Security

  • Assist with the administration and monitoring of Palo Alto Networks Prisma Cloud capabilities.
  • Monitor and triage cloud security posture and compliance findings.
  • Support Prisma Cloud policy configuration, alerting, reporting, and remediation tracking.
  • Assist with integration of Prisma Cloud findings into SIEM and vulnerability-management processes.
  • Support cloud security operations within AWS and/or Microsoft Azure environments.

Change Management & Documentation

  • Prepare firewall and security-platform changes for Change Advisory Board (CAB) review.
  • Develop implementation plans, technical impact assessments, testing procedures, and rollback plans.
  • Execute approved configuration changes in accordance with established change-management procedures.
  • Develop and maintain technical documentation, including SOPs, runbooks, troubleshooting guides, configuration records, and operational procedures.
  • Maintain accurate configuration, change, and operational records.

Federal Cybersecurity Compliance

  • Support configuration and operation of Palo Alto Networks technologies in accordance with applicable Federal cybersecurity requirements and security baselines.
  • Support NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, OMB Zero Trust requirements, and applicable DISA STIG requirements.
  • Assist with Authorization to Operate (ATO) activities, including security-control implementation documentation, SSP contributions, continuous-monitoring evidence, and audit artifacts.
  • Support configuration-compliance assessments and remediation of security baseline or STIG deviations.
  • Monitor applicable Palo Alto Networks vulnerabilities and vendor advisories and support vulnerability-remediation activities.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related field. An equivalent combination of education and directly relevant professional experience may be considered.
  • 3-5 years of hands-on experience in network security engineering, firewall administration, or a closely related discipline.
  • At least 2-3 years of hands-on experience with Palo Alto Networks NGFW platforms in an enterprise environment.
  • Demonstrated experience developing and administering Palo Alto Networks firewall security policies and threat prevention profiles.
  • Hands-on experience with Palo Alto Networks Panorama.
  • Strong knowledge of enterprise networking concepts, including:
  • Routing and switching
  • VLANs
  • Network segmentation
  • Firewall zones
  • IPsec and SSL VPNs
  • TCP/IP and network troubleshooting
  • Experience troubleshooting firewall connectivity, performance, and security-policy issues.
  • Experience analyzing firewall, traffic, and threat-prevention logs.
  • Familiarity with Federal cybersecurity requirements, including NIST SP 800-53, FISMA, and applicable DISA STIGs.
  • Experience working within formal change-management processes.
  • Strong written and verbal communication skills.
  • Ability to develop clear technical documentation and communicate effectively with technical and non-technical stakeholders.
  • Active security clearance or ability to obtain and maintain the Government background investigation, clearance, and IT access required for the position., * Previous experience supporting Palo Alto Networks technologies on a Federal Government contract or Federal IT program.
  • Experience administering Palo Alto Networks Prisma Access and GlobalProtect.
  • Experience with Prisma Cloud.
  • Experience with Cortex XDR.
  • Experience with Palo Alto Networks WildFire.
  • Experience supporting AWS and/or Microsoft Azure Government environments.
  • Experience integrating Palo Alto Networks logging with enterprise SIEM platforms.
  • Experience supporting ATO and continuous-monitoring activities.
  • Knowledge of Zero Trust Architecture and NIST SP 800-207.
  • Familiarity with MITRE ATT&CK.
  • Experience using the PAN-OS CLI for troubleshooting and configuration verification.
  • Basic scripting experience using Python, PowerShell, or Bash.
  • Experience with Palo Alto Networks APIs and security-platform automation.

Preferred Certifications

One or more of the following certifications is preferred:

  • Palo Alto Networks Certified Network Security Administrator (PCNSA)
  • Palo Alto Networks Certified Network Security Engineer (PCNSE)
  • CompTIA Security+
  • CompTIA Network+
  • Cisco Certified Network Associate (CCNA)
  • Cisco Certified Network Professional (CCNP)
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Certified Enterprise Defender (GCED)
  • Other relevant networking, Palo Alto Networks, or cybersecurity certifications

Core Competencies

Successful candidates will demonstrate:

  • Strong Palo Alto Networks technical proficiency
  • Enterprise network-security engineering knowledge
  • Analytical and troubleshooting ability
  • Security-first decision making
  • Attention to configuration and documentation accuracy
  • Ability to operate within structured Federal change-management and compliance environments
  • Strong collaboration with engineering, cybersecurity, cloud, and Government teams
  • Ability to work independently while appropriately escalating complex technical issues

Benefits & conditions

DGC anticipates a base salary range of $110,000-$140,000 annually for this position. Actual compensation will be determined based on factors including relevant experience, Palo Alto Networks expertise, certifications, Federal contracting experience, clearance status, education, and other job-related qualifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:59 min

Designing HTTP and HTML for familiar document sharing

Tim Berners-Lee · World Congress 2023

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

Videos

See all

Related articles

See all