Cybersecurity Firewall Analyst II

Optomi

Charlotte (NC)

On-site

USD 95,000 - 135,000

Full time

38 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Optomi in Charlotte, NC is seeking a Security Engineer to support and evolve the organization's SASE environment (Palo Alto Prisma Access, GlobalProtect, Strata Cloud Manager) while maintaining legacy Inspection Zone technologies such as F5 BIG-IP and proxy solutions.

You will drive threat prevention, policy management, cloud security controls, and security monitoring across enterprise environments, partnering with Security Operations, Network Engineering, and Incident Response teams.

Qualifications

  • 3+ years of Cybersecurity experience (or 4+ years equivalent without degree).
  • Experience with Palo Alto Networks SASE/Prisma Access.
  • Strong understanding of Security Service Edge (SWG, CASB, ZTNA).
  • Networking expertise including BGP, IPSec, NAT, routing, and VPN technologies.
  • Experience with GlobalProtect.
  • Cloud-delivered security architecture and policy management.
  • Experience supporting enterprise security platforms in large environments.
  • Bachelor's Degree or equivalent experience in Cybersecurity/CS/MIS.
  • Ability to support and optimize cybersecurity infrastructure in a 24x7 operations environment.
  • Must be eligible to convert to a full-time employee.

Responsibilities

  • Participate in the implementation, support, and lifecycle management of Palo Alto SASE solutions within a large enterprise, while maintaining integration with legacy Inspection Zone technologies.
  • Design, deploy, and optimize cloud-delivered security controls including SWG, CASB, ZTNA, and threat prevention.
  • Provide advanced engineering support for SASE and Inspection Zone platforms, partnering with Security Operations, Network Engineering, and Incident Response teams.
  • Drive security monitoring, telemetry integration, and policy enforcement across SASE and on-prem environments for visibility and threat detection.
  • Perform system hardening, high availability design, and resilience engineering for SASE and Inspection Zone environments.
  • Maintain understanding of global threat landscape and apply Palo Alto threat intelligence to reduce risk.
  • Drive continuous improvement of detection and response using SASE telemetry for incident analysis and threat hunting.
  • Develop and report on operational and security metrics to inform leadership decisions.
  • Collaborate with cross-functional teams to align SASE strategy with enterprise security architecture and modernization efforts.

Skills

Cybersecurity
SASE/Prisma Access
SWG
CASB
ZTNA
Networking
GlobalProtect
Cloud security
24x7 ops

Education

Bachelor's degree in a related field

Tools

Palo Alto Prisma Access
GlobalProtect
Strata Cloud Manager
F5 BIG-IP

Job description

This role will help support and evolve the organization's Secure Access Service Edge (SASE) environment, including Palo Alto Prisma Access, GlobalProtect, and Strata Cloud Manager, while maintaining legacy Inspection Zone technologies such as F5 BIG-IP and proxy solutions. The analyst will help drive threat prevention, policy management, cloud security controls, security monitoring, and modernization efforts across the enterprise.

Key Responsibilities:
  • Participate in the implementation, support, and lifecycle management of Palo Alto Networks Secure Access Service Edge (SASE) solutions (Prisma Access, Global Protect, Strata Cloud Manager) within a large-scale enterprise environment, while maintaining integration with Inspection Zone technologies (F5 BIG-IP, SWG/Proxy, etc.)
  • Design, deploy, and continuously optimize cloud-delivered security controls including secure web gateway (SWG), CASB, ZTNA, and threat prevention capabilities aligned to Palo Alto SASE architecture
  • Provide advanced engineering support for SASE and Inspection Zone security platforms, partnering closely with Security Operations, Network Engineering, and Incident Response teams
  • Drive security monitoring, telemetry integration, and policy enforcement across SASE and on-prem inspection environments to ensure consistent visibility and threat detection
  • Perform system hardening, high availability design, and resilience engineering for SASE and Inspection Zone environments, including failover strategy and service continuity planning
  • Maintain a strong understanding of the global threat landscape and apply Palo Alto threat intelligence and best practices to proactively reduce enterprise risk exposure
  • Drive continuous improvement of detection and response capabilities, leveraging SASE telemetry to enhance incident analysis, threat hunting, and mitigation effectiveness
  • Develop and report on operational and security metrics (e.g., policy effectiveness, threat prevention performance, user activity visibility) to inform leadership decision-making and improve operational maturity
  • Collaborate with cross-functional teams and leadership to align SASE strategy with enterprise security architecture, modernization initiatives (e.g., legacy proxy replacement), and business objectives
Required Qualifications:
  • 3+ years of Cybersecurity experience (or 4+ years equivalent experience without degree)
  • Experience with Palo Alto Networks SASE/Prisma Access
  • Strong understanding of Security Service Edge (SWG, CASB, ZTNA)
  • Networking expertise including BGP, IPSec, NAT, routing, and VPN technologies
  • Experience with GlobalProtect
  • Cloud-delivered security architecture and policy management
  • Experience supporting enterprise security platforms in large environments
  • Bachelor's Degree (Cybersecurity, Information Security, Computer Science, MIS, or related field) or equivalent experience
  • Ability to support and optimize cybersecurity infrastructure in a 24x7 operations environment
  • Must be eligible to convert to a full-time employee

*Must be currently located in Charlotte, NC*

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Firewall Analyst II (Prisma-SASE-Palo)
Cybersecurity Firewall Analyst II (Prisma-SASE-Palo)

Gravity IT Resources • Charlotte (NC)

Hybrid
USD 110,000 - 140,000
Senior Network & Security Engineer – SD-WAN / SASE (Palo Alto)
Senior Network & Security Engineer – SD-WAN / SASE (Palo Alto)

TECEZE • New York (NY)

On-site
USD 120,000 - 150,000
Prisma Access / SASE Engineer (Palo Alto Network Security) | Vertex Elite Solutions | Plano, Texas, USA
Prisma Access / SASE Engineer (Palo Alto Network Security) | Vertex Elite Solutions | Plano, Texas, USA

Vertex Elite Solutions • Plano (TX)

On-site
USD 110,000 - 165,000
SASE Security Engineer (Palo Alto) | CSOC Specialist
SASE Security Engineer (Palo Alto) | CSOC Specialist

Gravity IT Resources • Charlotte (NC)

Hybrid
USD 110,000 - 140,000
Senior Technical Support Engineer ( SASE | Prisma SD-WAN | CNGFW/VM )
Senior Technical Support Engineer ( SASE | Prisma SD-WAN | CNGFW/VM )

Palo Alto Networks • Town of Texas (WI)

On-site
USD 103,000 - 167,000
Senior Technical Support Engineer ( SASE | Prisma SD-WAN | CNGFW/VM )
Senior Technical Support Engineer ( SASE | Prisma SD-WAN | CNGFW/VM )

Palo Alto Networks • Plano (TX)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

MDS is now part of Secur-Serv • Dallas (TX)

On-site
USD 120,000 - 140,000
Principal Software Automation/Test Engineer (Prisma Access)
Principal Software Automation/Test Engineer (Prisma Access)

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 147,000 - 238,000
Principal Software Automation/Test Engineer (Prisma Access)
Principal Software Automation/Test Engineer (Prisma Access)

Palo Alto Networks • Santa Clara (CA)

On-site
USD 147,000 - 238,000
SOSC-Network Engineer - Consultant - Palo Alto Cloud Engineer - 12762
SOSC-Network Engineer - Consultant - Palo Alto Cloud Engineer - 12762

RICEFW Technologies Inc • Columbia (SC)

Hybrid
USD 120,000 - 180,000