Cybersecurity Engineer

Kimley-Horn

Phoenix (AZ)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Exceptional Retirement Plan
Comprehensive Health Coverage
Flexible scheduling
Tuition reimbursement

Job summary

Kimley-Horn is looking for a Cybersecurity Engineer in Phoenix, Arizona to lead their network security function, focusing on enterprise firewall architecture and operations. In this foundational role, you'll take ownership of their firewall environment and help define the future of network security across their organization.

The ideal candidate will have a strong networking background and hands-on firewall experience, especially in Palo Alto environments. Benefits include exceptional retirement plans and comprehensive health coverage.

Qualifications

  • 4+ years of experience in network security engineering or related roles.
  • Strong hands-on experience with firewall design, implementation, and management.
  • Excellent problem-solving skills under pressure.

Responsibilities

  • Serve as the primary owner of the enterprise firewall environment.
  • Create, review, and maintain firewall policies and rules.
  • Troubleshoot complex networking and security issues.

Skills

Firewall design
Network security engineering
Hands-on experience with Palo Alto
Problem-solving
Excellent communication skills

Education

Bachelor’s degree in Information Security or related field

Tools

Palo Alto firewalls
Web Application Firewalls (WAFs)
Cisco ISE

Job description

Overview

Kimley-Horn is seeking a Cybersecurity Engineer to help lead and mature our network security function, with a primary focus on enterprise firewall architecture and operations.

This is a foundational role within our Information Security team, where you’ll take ownership of a growing firewall environment, influence security strategy, and help define the future of network security across a rapidly expanding, multi-site organization.

If you have a strong networking background and deep hands‑on firewall experience—especially in Palo Alto environments—this is an opportunity to truly own and evolve a critical security domain.

This is not a remote position. Applicants must be legally authorized to work for Kimley-Horn in the U.S. without employer sponsorship. We do not typically sponsor H1-B or other work visa petitions.

Responsibilities
  • Serve as the primary owner of Kimley-Horn’s enterprise firewall environment, including design, implementation, and ongoing optimization.
  • Create, review, and maintain firewall policies and rules across on‑prem and cloud environments.
  • Lead firewall strategy decisions, including policy standardization, segmentation, and performance tuning.
  • Administer and optimize Palo Alto firewalls and Panorama.
  • Manage and enhance GlobalProtect policies and secure remote access configurations.
  • Analyze and implement ACLs, rule bases, and logical security controls across a multi‑vendor environment.
  • Drive continuous improvement in firewall posture, balancing security and user experience.
  • Support and manage Next‑Gen Firewalls in Azure environments.
  • Administer and optimize Web Application Firewalls (WAFs).
  • Participate in SASE and cloud security architecture discussions and reviews.
  • Implement and maintain network security controls, including firewalls, VPNs, IDS/IPS, and access controls.
  • Troubleshoot complex networking and security issues across cloud and hybrid environments.
  • Monitor and resolve network performance issues (latency, throughput, utilization, system slowness).
  • Partner with Network Operations and Cloud teams to review designs and provide a security‑first perspective.
  • Assist in evaluating and implementing Network Detection & Response (NDR) solutions.
  • Support the transition and ongoing ownership of Cisco ISE capabilities.
  • Contribute to security tooling decisions, standards, and long‑term strategy.
  • Coordinate and guide work across matrixed IT partners.
  • Provide technical guidance, training, and mentorship on network security best practices.
  • Participate in incident response, change management, and after‑hours maintenance for critical events.
Qualifications
  • Bachelor’s degree in Information Security, Cybersecurity, or a related field.
  • 4+ years of experience in network security engineering or related roles within enterprise environments.
  • Strong hands‑on experience with firewall design, implementation, and management (required).
  • Direct experience with Palo Alto firewalls and Panorama.
  • Experience with firewall architectures across internal, perimeter, and cloud environments.
  • Experience administering Web Application Firewalls (WAFs).
  • Experience with Cisco ISE or similar identity‑based network access platforms.
  • Solid understanding of networking fundamentals (routing, switching, TCP/IP, DNS, DHCP).
  • Experience with change management practices and operational processes.
  • Strong problem‑solving skills and ability to perform under pressure.
  • Excellent communication skills with the ability to explain technical concepts to non‑technical stakeholders.
Preferred Certifications
  • Security+
  • Network+
  • CCNP Security
  • AZ-700/AZ-500
  • CISSP
  • or similar
Benefits
  • Exceptional Retirement Plan: 2-to-1 company match on up to 4% of eligible compensation (salary + bonus) and additional profit‑sharing contribution.
  • Comprehensive Health Coverage: Low‑cost medical, dental, and vision insurance options.
  • Time Off: Personal leave, flexible scheduling, floating holidays, and half‑day Fridays.
  • Financial Wellness: Student loan matching in our 401(k), and performance‑based bonuses.
  • Professional Development: Tuition reimbursement and extensive internal training programs.
  • Family‑Friendly Benefits: New Parent Leave, family building benefits, and childcare resources.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

Kimley-Horn • Dallas (TX)

On-site
USD 110,000 - 160,000
Retirement match: 2-to-1 company match
Health coverage: medical/dental/vision
Flexible time off & holidays
+1
Network Security Engineer
Network Security Engineer

Kimley-Horn • Austin (TX)

On-site
USD 120,000 - 160,000
Retirement plan match
Health coverage
Flexible time off
+3
Network Security Engineer
Network Security Engineer

Kimley-Horn • Dallas (TX)

On-site
USD 100,000 - 130,000
Exceptional Retirement Plan
Comprehensive Health Coverage
Time Off including half-day Fridays
+2
Senior Network Security Engineer
Senior Network Security Engineer

Cedar Cares, Inc • Overland Park (KS)

On-site
USD 119,000 - 169,400
Generous paid time off
Health, dental and vision benefits
2:1 401(k) match
+1
Firewall Architect & Network Security Engineer (Palo Alto)
Firewall Architect & Network Security Engineer (Palo Alto)

Kimley-Horn • Phoenix (AZ)

On-site
USD 90,000 - 120,000
Exceptional Retirement Plan
Comprehensive Health Coverage
Flexible scheduling
+1
Senior Technical Consultant - Network Security
Senior Technical Consultant - Network Security

Thinkahead • United States

Hybrid
USD 120,000 - 150,000
Medical, Dental, and Vision Insurance
401(k) plan
Paid time off
+2
Sr Network Security Engineer
Sr Network Security Engineer

Worldpac • Flower Mound (TX)

On-site
USD 76,000 - 101,000
Firewall Architect & Network Security Engineer (Palo Alto)
Firewall Architect & Network Security Engineer (Palo Alto)

Kimley-Horn • Dallas (TX)

On-site
USD 100,000 - 130,000
Exceptional Retirement Plan
Comprehensive Health Coverage
Time Off including half-day Fridays
+2
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Socket.dev • California (MO)

On-site
USD 154,000 - 250,000
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Palo Alto Networks • Santa Clara (CA)

On-site
USD 154,000 - 250,000