PALO ALTO ENGINEER (NGFW)

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 51-200

Location

United States

Posted

4 days ago

Salary

Not specified

Seniority

Mid Level

Palo Alto NGFWFirewall ConfigurationSSL DecryptionWildfireSMTP Traffic InspectionThreat DetectionSIEM IntegrationNetwork SecurityUser ID LoggingChange Management

Job Description

SUMMARY:

We are seeking a highly specialized Palo Alto Next Generation Firewall (NGFW) Engineer with expertise in complex environments to join Zermount's team. The Palo Alto NGFW Engineer will play a pivotal role in designing, implementing, and maintaining network security infrastructure tailored for one of our Federal client's complex environments. The Palo Alto NGFW Engineer will configure, implement, administer, & maintain the suite of Palo Alto NGFWs to include SSL decryption & inspection of all inbound & outbound web traffic with inline service chain & traffic forwarding, review & make recommendations on all exceptions to Palo Alto rule configurations & implement as appropriate. Integrate Wildfire analysis into decrypted SMTP traffic flow, and enhance threat detection capabilities by configuring & tuning the NGFW against known & unknown threats. This role demands an exceptional understanding of advanced network security practices and hands-on proficiency in Palo Alto NGFW configurations within intricate settings.

DUTIES & RESPONSIBILITIES:

  • Architect, configure and oversee Palo Alto NGFWs, customizing security solutions for the unique requirements of the Federal client.
  • Configure, implement, administer, and maintain PA NGFW to include decryption and inspection of all inbound and outbound web traffic with inline service chain and traffic forwarding,
  • Craft, administer, and optimize intricate security policies, rules, and access controls specific to Palo Alto firewall settings, addressing the client's complex network architecture.
  • Review and make recommendations on all exceptions to Palo Alto NGFW rule configurations and implement them as appropriate.
  • Integrate Wildfire analysis into decrypted SMTP traffic flow.
  • Enhance threat detection capabilities by configuring and tuning the NGFW against known and unknown threats.
  • Expand PA coverage with full implementation for all client's environments. Ensure PA logging ties user-IDs to traffic, and logs are fed into the client's SIEM architecture as well as passive network inspection tools.
  • Conduct vigilant monitoring of network traffic and security alerts within the client's context, swiftly responding to and mitigating sophisticated security threats.
  • Collaborate closely with cross-functional teams, adapting network security strategies to suit client's multifaceted environment and unique challenges.
  • Provide expert technical support and rapid troubleshooting for Palo Alto NGFW-related issues tailored to client's specific setup.
  • Troubleshoot and resolve service requests and submit and implement change requests as required.

QUALIFICATIONS:

  • 5 years of hands-on experience in network security engineering with 3 years of Palo Alto experience.

EDUCATION:

  • A minimum of a bachelor's degree in computer science, Information Technology, or a related field.
    • Experience may be considered as a substitute for the degree requirement.

CERTIFICATIONS:

  • A minimum of one (1) Palo Alto Technical (Engineering or Administrator) Certification is required, such as PCNSA.

CLEARANCE:

  • Minimum Background Investigation (MBI).

LOCATION:

  • Remote (Initial onboarding in Arlington, VA)
  • Minimal travel may be required if requested by the agency.

HOURS:

  • 8:00 am ET - 4:30 am ET

  • Ability to pass a minimum background investigation.

Job Requirements

  • 5 years of hands-on experience in network security engineering with 3 years of Palo Alto experience.
  • A minimum of a bachelor's degree in computer science, Information Technology, or a related field. Experience may be considered as a substitute for the degree requirement.
  • A minimum of one (1) Palo Alto Technical (Engineering or Administrator) Certification is required, such as PCNSA.
  • Minimum Background Investigation (MBI).

Benefits

  • Remote (Initial onboarding in Arlington, VA).
  • Minimal travel may be required if requested by the agency.
  • Hours: 8:00 am ET - 4:30 am ET.
  • Ability to pass a minimum background investigation.

Related Categories

Related Job Pages

More Security Engineer Jobs

CrowdStrike logo

Information Systems Security Officer (Remote)

CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Security Engineer4 days ago
Full TimeRemoteTeam 5,001-10,000Since 2011H1B Sponsor

The ISSO will enhance security and compliance for federal cloud environments, manage ATO processes, conduct audits, and oversee incident responses.

Aws GovcloudCC++CI/CDEndpoint SecurityFedrampFismaJavaScriptNist Sp 800-53PythonRmfSIEM
United States
$125K - $180K / year
ELYON International logo

Cloud Security Threat Modeler – Service & API Patterns

ELYON International

Solutions for a Changing World. Certified NMSDC, WBENC, VOSB, MBE, WOSB

Security Engineer4 days ago
ContractRemoteTeam 201-500H1B No Sponsor

Cloud Security Threat Modeler standardizing security patterns for AWS, Azure, and GCP

AWSAzureCloudGoogle Cloud Platform
Washington
$55 - $60 / hour
Guidehouse logo

Senior Cybersecurity Lead

Guidehouse

Solving big problems, building trust in society, and empowering our clients to shape the future.

Security Engineer4 days ago
Full TimeRemoteTeam 10,001+Since 2018H1B Sponsor

This role involves designing, managing, and maintaining the security posture for a multi-system Identity and Credential Management solution while leading cross-functional teams to implement and test IT security controls. The lead will apply cybersecurity principles, develop RMF plans, and maintain implementation schedules across the program lifecycle.

United States
$130K - $216K / year
Mondelēz International logo

Senior Security Detection Engineer (F/M/X)

Mondelēz International

We’re a house of incredible brands providing people with the right snack, for the right moment, made the right way.

Security Engineer4 days ago
Full TimeRemoteTeam 10,001+Since 2012H1B No Sponsor

The engineer will design, build, and maintain detection content across enterprise environments, translating adversary behavior into high-fidelity detections. Key tasks include developing detection rules, tuning analytics, and improving coverage across endpoints, network, identity, cloud, and application platforms.

United States + 3 moreAll locations: United States, Greece, Poland, Spain