Palo Alto Security Engineer

Zappsec Inc.

India

On-site

INR 4,000,000 - 6,500,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Zappsec Technologies Inc. is seeking a Palo Alto Security Engineer specializing in NGFW and SASE to design, deploy, and operate Palo Alto networks for major enterprise clients. You will configure Panorama, migrate rules to PAN-OS in cloud, and build SASE services with Prisma Access and GlobalProtect.

Daily hands-on work includes CLI usage, policy design, and validation of migrations with customer engineers. Strong expertise in PAN-OS, Expedition, and security policy is essential.

Qualifications

  • Five+ years configuring and operating Palo Alto NGFW in production.
  • Direct experience administering Panorama including templates, template stacks, device groups.
  • Proven record of firewall rule migration to PAN-OS from other vendors.
  • Knowledge of App-ID, User-ID, Content-ID, and security profile design.
  • Experience deploying VM-Series or Cloud NGFW in at least one public cloud.

Responsibilities

  • Configure Panorama templates, template stacks, and device groups for client estates.
  • Write, tune, and document security, NAT, and decryption policies; convert legacy rules to App-ID.
  • Migrate rule bases to PAN-OS in cloud (AWS/Azure) using Expedition or similar tools.
  • Configure GlobalProtect and Prisma Access for SASE deployments; manage VPN and remote access.
  • Produce design documents, runbooks, and as-built records; conduct knowledge transfer.

Skills

Palo Alto NGFW
Panorama admin
App-ID/User-ID
Cloud NGFW
Firewall policy
Migration tooling
Networking fundamentals

Tools

Expedition
Policy Optimizer
PAN-OS
Terraform
Ansible

Job description

Palo Alto Security Engineer, NGFW and SASE

Zappsec Technologies Inc.

About the role

Zappsec designs and operates network security platforms enterprise clients. This role owns the Palo Alto Networks side of that work.

You will configure Panorama, write and tune firewall policy, and migrate existing rule bases onto Palo Alto platforms in AWS and Azure. You will also build and support SASE services through Prisma Access and GlobalProtect.

This is a hands-on engineering role. You will be in the consoles and the CLI daily. You will not manage vendors or coordinate other people's work.

What you will do
Panorama configuration and platform management
  • Build and maintain Panorama templates, template stacks, and device groups across client estates.
  • Structure pre-rules and post-rules so inheritance behaves predictably as device groups grow.
  • Run commit and push workflows, including partial commits and config audits before change windows.
  • Manage log collectors, log forwarding profiles, and retention design.
  • Schedule and validate dynamic content updates for applications, threats, and WildFire.
  • Plan and execute PAN-OS upgrades across HA pairs, with tested rollback for every step.
  • Onboard new firewalls into Panorama and bring them under central policy control.
Firewall policy engineering
  • Write, tune, and document security policy, NAT policy, and decryption policy.
  • Convert legacy port-based rules to App-ID rules using Policy Optimizer.
  • Identify and remove shadowed, redundant, expired, and unused rules.
  • Apply security profile groups covering antivirus, anti-spyware, vulnerability protection, URL filtering, WildFire, file blocking, and DNS Security.
  • Maintain address objects, service objects, tags, dynamic address groups, and external dynamic lists against a naming standard.
  • Configure User-ID and bind policy to identity groups rather than IP ranges.
  • Configure SSL forward proxy and inbound inspection, including certificate handling and decryption exclusions.
Migration of rules to Palo Alto in cloud
  • Migrate rule bases from Cisco ASA, Check Point, Fortinet, and Juniper SRX to PAN-OS.
  • Use Expedition or equivalent tooling for conversion, object cleanup, and App-ID adoption.
  • Rehost policy onto VM-Series and Cloud NGFW in AWS and Azure.
  • Design the enforcement topology with the client architect, covering Gateway Load Balancer, transit VPC, and Azure Virtual WAN hub patterns.
  • Map on-premises zones, objects, and groups to cloud constructs, resource tags, and dynamic address groups.
  • Validate each migration wave against traffic logs before and after cutover.
  • Write the cutover plan, the rollback plan, and the post-migration validation steps for every window.
SASE and Prisma Access
  • Configure Prisma Access mobile users, remote networks, and service connections.
  • Build and support GlobalProtect portals, gateways, HIP checks, and split tunnel design.
  • Write ZTNA access policy and explicit proxy configuration.
  • Configure CASB and DLP controls where the engagement includes them.
  • Use Autonomous DEM to diagnose user experience problems across the service path.
  • Operate deployments under Strata Cloud Manager or Panorama managed Prisma Access.
Client advisory and delivery
  • Run platform health checks and best practice reviews, then deliver written remediation guidance.
  • Take escalations on complex issues using packet captures, session analysis, and global counters.
  • Open and drive Palo Alto TAC cases to resolution.
  • Produce high level and low level design documents, runbooks, and as-built records.
  • Run knowledge transfer sessions so client teams can operate what you build.
Requirements
  • Five or more years configuring and operating Palo Alto NGFW in production environments.
  • Direct experience administering Panorama, including templates, template stacks, and device groups.
  • Proven record of firewall rule migration from another vendor platform to PAN-OS.
  • Working knowledge of App-ID, User-ID, Content-ID, and security profile design.
  • Experience deploying VM-Series or Cloud NGFW in at least one public cloud.
  • Strong routing and switching fundamentals, including BGP, OSPF, NAT, and IPSec.
  • Experience with GlobalProtect or Prisma Access in a production deployment.
  • Ability to write client-facing documentation without an editor rewriting it.
  • Comfort working directly with client engineers and architects during change windows.
Preferred
  • PCNSE certification. PCNSA or PCSFE also considered.
  • Experience with Expedition for large rule base conversions.
  • Consulting or managed services background across multiple client environments.
  • Terraform or Ansible experience for firewall and policy automation.
  • Exposure to Cortex XDR, Cortex Data Lake, or Prisma Cloud.
  • Experience in regulated environments such as financial services, healthcare, or energy.
Tools you will use
  • Management: Panorama, Strata Cloud Manager
  • Platform: PAN-OS, PA-Series, VM-Series, CN-Series, Cloud NGFW
  • SASE: Prisma Access, GlobalProtect, Explicit Proxy, Autonomous DEM
  • Migration: Expedition, Policy Optimizer, Best Practice Assessment
  • Cloud: AWS, Azure
  • Automation: Terraform, Ansible, Git, PAN-OS XML API
  • Analysis: Wireshark, packet captures, traffic and threat log analysis
  • Delivery: [Confirm ticketing and documentation stack]
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer (Palo Alto Network)
Senior Security Engineer (Palo Alto Network)

Careernet • Hyderabad

Hybrid
INR 2,800,000 - 4,200,000
Senior Network Security Engineer / Security Architect
Senior Network Security Engineer / Security Architect

Sb Hr Consultancy Kolkata • Dadri, Greater Noida

On-site
INR 900,000 - 1,300,000
Network Engineer
Network Engineer

SourcingXPress • Hyderabad

On-site
INR 1,200,000 - 3,000,000
Palo Alto Networks-Consultant-Freelancing
Palo Alto Networks-Consultant-Freelancing

InOpTra Digital • Bengaluru

Hybrid
INR 1,800,000 - 2,400,000
Sr. Engineer - Security Engineering
Sr. Engineer - Security Engineering

CBTS • Chennai

On-site
INR 1,000,000 - 1,500,000
Fortinet SASE and SD-WAN Engineer
Fortinet SASE and SD-WAN Engineer

Zappsec • India

On-site
INR 1,800,000 - 2,500,000
Specialist - Presales (Palo Alto)
Specialist - Presales (Palo Alto)

Ingram Micro, Inc. • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Fortinet SASE and SD-WAN Engineer
Fortinet SASE and SD-WAN Engineer

Zappsec Inc. • India

On-site
INR 1,200,000 - 1,800,000
Professional Services Consultant-Prisma Access
Professional Services Consultant-Prisma Access

Infinity Labs • Dadri

On-site
INR 1,200,000 - 2,100,000
Network Security Automation
Network Security Automation

LTM • Bengaluru

On-site
INR 1,200,000 - 1,800,000