Network -6

REALIGN LLC

Sunnyvale (CA)

On-site

USD 120,000 - 180,000

Full time

26 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

REALIGN LLC in Sunnyvale, CA is seeking an experienced Network Palo Alto Firewall Engineer to design, deploy, and support enterprise security infrastructure using Palo Alto Networks firewalls and PAN-OS. You will configure security policies, NAT, VPNs, and centralized management with Panorama, and collaborate with cross-functional teams to ensure Zero Trust security and reliable network operations.

Strong troubleshooting and logging skills are essential, with hands-on experience in

Qualifications

  • Extensive hands-on experience with Palo Alto firewalls and PAN-OS.
  • Experience with Panorama for centralized firewall management.
  • Strong knowledge of security policies, NAT, ACLs, zones, virtual routers, and interfaces.
  • Experience with App-ID, User-ID, Content-ID, URL Filtering, Threat Prevention, and WildFire.
  • Experience with IPSec VPN, GlobalProtect, and site-to-site VPNs.
  • Strong TCP/IP, DNS, DHCP, VLANs, subnetting, and network security knowledge.
  • Experience with BGP, OSPF, and static routing.
  • HA Active/Passive and Active/Active configurations.
  • Zero Trust principles awareness.

Responsibilities

  • Design, deploy, configure, and maintain Palo Alto firewall infrastructure.
  • Configure and manage firewall security policies, NAT, routing, zones, and interfaces.
  • Manage Palo Alto devices through Panorama and centralized configuration changes.
  • Configure and troubleshoot GlobalProtect, IPSec VPN, SSL decryption, and remote-access solutions.
  • Implement firewall policies based on applications, users, devices, and security requirements.
  • Monitor firewall health, traffic and security events.
  • Troubleshoot connectivity, application access, routing and policy issues.
  • Perform upgrades, patches, migrations, and configuration reviews.
  • Implement and maintain High Availability configurations.
  • Analyze traffic and security logs; perform packet-level troubleshooting when needed.
  • Collaborate with network, security, cloud, and infrastructure teams to resolve issues.
  • Develop and maintain network security documentation, diagrams, procedures.
  • Participate in security assessments, incident response, and infrastructure improvement.
  • Support enterprise network segmentation and Zero Trust initiatives.

Skills

Palo Alto firewalls
PAN-OS
Panorama
Security policies
NAT
ACLs
VLANs
OSPF
BGP
TLS inspection
IPSec VPN
GlobalProtect
Troubleshooting
Zero Trust

Tools

Panorama
Splunk
Python
Ansible
REST APIs
Terraform
AWS
Azure

Job description

Sunnyvale, California 94043 Posted September 14th, 2026

Job Title: Network - Palo Alto Firewall Engineer

Location: Sunnyvale, CA

Full Time

Job Description

We are looking for an experienced Network Palo Alto Firewall Engineer to design, implement, configure, and support enterprise network security infrastructure. The ideal candidate will have strong hands-on experience with Palo Alto Networks firewalls, PAN-OS, Panorama, network routing, VPN, security policies, and troubleshooting.

Palo Alto Networks NGFWs provide application-, user-, and content-based visibility and control through technologies such as App-ID, User-ID, and Content-ID.

Must-Have Technical Skills

  • Strong hands-on experience with Palo Alto Networks Next-Generation Firewalls
  • Expert knowledge of PAN-OS and Palo Alto firewall architecture
  • Experience with Panorama for centralized firewall management
  • Strong understanding of Security Policies, NAT, ACLs, Zones, Virtual Routers, and interfaces
  • Experience with App-ID, User-ID, Content-ID, URL Filtering, Threat Prevention, and WildFire
  • Hands-on experience with SSL Decryption / TLS inspection
  • Experience configuring and troubleshooting IPSec VPN, GlobalProtect, and site-to-site VPNs
  • Strong knowledge of TCP/IP, DNS, DHCP, VLANs, subnetting, and network security
  • Experience with routing protocols including BGP, OSPF, and static routing
  • Experience with HA Active/Passive and Active/Active configurations
  • Knowledge of QoS, GRE tunnels, NAT, and network segmentation
  • Strong troubleshooting skills using firewall logs, packet captures, and monitoring tools
  • Experience with firewall upgrades, migrations, configuration backups, and disaster recovery
  • Knowledge of enterprise network security and Zero Trust principles

Palo Alto's current PAN-OS networking capabilities include interfaces, zones, VLANs, virtual routers, IPSec/GRE tunnels, DHCP, DNS, QoS, and dynamic routing such as OSPF and BGP.

  • Design, deploy, configure, and maintain Palo Alto firewall infrastructure.
  • Configure and manage firewall security policies, NAT policies, routing, zones, and interfaces.
  • Manage Palo Alto firewalls through Panorama and perform centralized configuration changes.
  • Configure and troubleshoot GlobalProtect, IPSec VPN, SSL decryption, and remote-access solutions.
  • Implement firewall policies based on applications, users, devices, and security requirements.
  • Monitor firewall health, traffic patterns, security events, and performance.
  • Troubleshoot network connectivity, application access, routing, and firewall policy issues.
  • Perform firewall upgrades, patches, migrations, and configuration reviews.
  • Implement and maintain High Availability configurations.
  • Analyze traffic and security logs and perform packet-level troubleshooting when required.
  • Work with network, security, cloud, and infrastructure teams to resolve complex issues.
  • Develop and maintain network security documentation, diagrams, and operational procedures.
  • Participate in security assessments, incident response, and infrastructure improvement initiatives.
  • Support enterprise network segmentation and Zero Trust security initiatives.

Preferred Skills

  • Palo Alto Networks certifications such as PCNSA, PCNSE, or PCCET
  • Experience with Cisco, Juniper, or Arista networking
  • Knowledge of AWS/Azure cloud networking and cloud firewalls
  • Experience with Prisma Access / Prisma Cloud
  • Knowledge of automation using Python, Ansible, REST APIs, or Terraform
  • Experience with network monitoring and SIEM tools such as Splunk
  • Strong communication, documentation, and problem-solving skills.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Engineer
Network Security Engineer

Holistic Partners, Inc • Town of Florida (NY)

On-site
USD 85,000 - 110,000
Sr. Engineer - Network
Sr. Engineer - Network

CBTS • Tennessee

On-site
USD 80,000 - 115,000
PALO ALTO NETWORKS FIREWALL ENGINEER
PALO ALTO NETWORKS FIREWALL ENGINEER

Target Labs, Inc • Palo Alto (CA)

On-site
USD 90,000 - 120,000
Network Security Engineer
Network Security Engineer

Tata Consultancy Services • Sunnyvale (CA)

On-site
USD 90,000 - 140,000
Sr. Firewall/Network Security Administrator
Sr. Firewall/Network Security Administrator

Calance • Tallapoosa (GA)

Hybrid
USD 90,000 - 130,000
EPO/PPO Medical Plans
401K Retirement vesting program
Flex Spending Plan
+1
Lead Network Engineer
Lead Network Engineer

All Lines Technology Inc. • Moon (VA)

On-site
USD 120,000 - 150,000
Senior Network Security Engineer
Senior Network Security Engineer

Cypress HCM • Town of Texas (WI)

On-site
USD 120,000 - 150,000
Medical, dental, vision plans
Health Saving Accounts (HSA)
Flexible PTO
+1
Senior Network Security Engineer
Senior Network Security Engineer

NPO USA Inc • Chicago (IL)

Hybrid
USD 80,000 - 92,000
Structured training and certification plans
Corporate benefits: Welfare Plan, Smart Working
Palo Alto Engineer
Palo Alto Engineer

TEKsystems • Winston-Salem (NC)

Hybrid
USD 76,000 - 90,000
Medical, dental & vision
401(k)
Life Insurance
+5
Remote Palo Alto Security Engineer
Remote Palo Alto Security Engineer

Insight Global • Fenton (MO)

Remote
USD 110,000 - 165,000