Get AI-powered advice on this job and more exclusive features.
Direct message the job poster from Convergenz
Seeking an experienced Network Security Engineers with deep expertise in firewall technologies—particularly Palo Alto Networks—to support a comprehensive firewall rule audit, optimization, and compliance effort for a large-scale enterprise environment. This role involves reviewing and validating over 30,000 firewall rules across multiple platforms, ensuring alignment with internal cybersecurity policies and evolving industry audit standards.
Engineers in this role will also help integrate automation tools like FireMon and ServiceNow to streamline ongoing firewall compliance reviews and improve visibility into rule management across on-prem and cloud infrastructure.
Scope of Responsibilities
Firewall Rule Audit & Optimization
- Conduct comprehensive firewall policy reviews across multiple vendor platforms (e.g., Palo Alto, Cisco, Check Point)
- Validate and approve new firewall rule requests in accordance with organizational cybersecurity policies
- Identify, document, and recommend decommissioning of obsolete or unused rules
- Work closely with infrastructure and application teams to troubleshoot rule-related issues
- Identify business owners for existing firewall rules and validate necessity
- Support quarterly and annual audit preparation and compliance efforts
Security Engineering & Integration
- Provide integration support for FireMon with ITSM platforms (e.g., ServiceNow)
- Assist in integrating segmentation and visualization platforms (e.g., Illumio) to enhance security posture
- Track rule lifecycle, metrics, and change management workflows
- Maintain clear and up-to-date system and rule documentation
- Provide after-hours and on-call support as needed
- Review FireMon audit findings and assist in remediation planning
- Monitor and manage tickets in ServiceNow to ensure compliance with SLAs
- Develop procedures for ongoing firewall rule reviews and cleanup
- Participate in cross-functional communication with networking, cloud, and compliance teams
Required Skills and Experience
- 7–10 years of hands-on experience in network security engineering or similar field
- Strong expertise with Palo Alto Networks firewalls (Next-Gen Firewall configurations, SCM experience)
- Familiarity with Cisco ASA, Cisco CDO, and ASDM
- Proficiency with Check Point firewalls and associated tooling
- Experience using FireMon Security Manager for rule analysis and compliance reporting
- Experience with ServiceNow or equivalent ITSM systems
- Understanding of cloud security models, particularly in Microsoft Azure (preferred)
- Working knowledge of Splunk for security monitoring and analysis
- Strong troubleshooting, analytical, and documentation skills
Certifications (Required or Preferred)
- Palo Alto Networks certifications (PCNSE) preferred
- Any cloud-related or audit/compliance certifications are a plus
Ideal Candidate Profile
- Comfortable navigating large enterprise environments, preferably within regulated industries (e.g., finance, healthcare)
- Highly collaborative with excellent communication skills across technical and non-technical teams
- Detail-oriented, with a proactive approach to documentation, process development, and continuous improvement
Seniority level
Seniority level
Mid-Senior level
Employment type
Job function
Job function
Engineering and Information Technology
Referrals increase your chances of interviewing at Convergenz by 2x
Inferred from the description for this job
Medical insurance
Vision insurance
Get notified when a new job is posted.
Sign in to set job alerts for “Network Security Engineer” roles.
Washington DC-Baltimore Area $100,000.00-$120,000.00 1 day ago
Information Systems Security Officer (ISSO)
Network Security Engineer (CISSP Certified)
Bethesda, MD $120,000.00-$160,000.00 3 weeks ago
Cybersecurity Engineer II - Manassas, VA
Cybersecurity Network Security Engineer (CISSP certified)
Bethesda, MD $120,000.00-$150,000.00 3 weeks ago
Chantilly, VA $94,400.00-$198,200.00 2 weeks ago
Network Security Engineer, TS/SCI (Springfield, VA)
Cybersecurity and Network Security Engineer
Information Systems Security Engineer (5916)
Cybersecurity Engineer II - Crystal City, VA
Network Security Engineers (specializing in Palo Alto) - Remote
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.