This fully remote Network Security Engineer role supports enterprise network-security infrastructure and continuous improvement across firewall, switching, logging, and security analytics.
Responsibilities
- Lead the design, deployment, administration, and lifecycle management of Palo Alto Networks NGFW environments running PAN-OS.
- Own centralized firewall management using Palo Alto Panorama, including device groups, templates, template stacks, policy inheritance, upgrades, configuration backups, log monitoring, and firewall onboarding.
- Design and govern security policies using zero-trust, least-privilege, application-aware, and risk-based principles.
- Configure and troubleshoot security zones, NAT, virtual routers, static and dynamic routing, IPsec VPN, GlobalProtect, decryption, URL Filtering, Threat Prevention, WildFire, DNS Security, and App-ID policies.
- Drive enterprise network segmentation and microsegmentation using security zones, VLANs, subinterfaces, virtual routers, routing controls, and application-based security policies.
- Develop secure controls for traffic between users, servers, applications, management networks, guest networks, IoT/OT devices, data-center workloads, and cloud resources.
- Architect, configure, test, and troubleshoot Palo Alto High Availability deployments, including Active/Passive and Active/Active designs.
- Resolve complex HA failures across HA1 control links, HA2 session/state synchronization, HA3 packet forwarding, peer communications, configuration synchronization, monitoring failures, split-brain prevention, and failover recovery.
- Plan and execute HA failover testing, PAN-OS upgrades, disaster-recovery exercises, and maintenance procedures while minimizing service impact.
- Troubleshoot HA infrastructure dependencies including cables, transceivers, switch ports, port channels, VLANs, routing, MTU, latency, packet loss, and redundant-path failures.
- Lead configuration, support, and troubleshooting of Cisco Catalyst and Cisco Nexus switching environments.
- Design and support VLANs, trunking, STP/RSTP/MST, EtherChannel/port channels, HSRP/VRRP, Layer 2/Layer 3 switching, ACLs, QoS, switch security, routing, and access-control technologies.
- Diagnose complex connectivity and performance issues using firewall logs, session inspection, packet captures, CLI diagnostics, switch counters, flow data, and network-monitoring platforms.
- Analyze TCP/IP behavior including handshake failures, SYN/SYN-ACK/ACK flow, retransmissions, resets, timeouts, asymmetric routing, MTU/MSS issues, fragmentation, latency, and NAT translation problems.
- Verify packet flow across firewall policy, App-ID, routing, NAT, decryption, threat prevention, VPN, switching, and server/application layers.
- Monitor firewall management-plane and dataplane health including CPU, memory, session capacity, packet buffers, throughput, logging, and interface performance.
- Integrate Palo Alto NGFWs and Panorama with Strata Logging Service and Cortex XSIAM.
- Ensure reliable firewall log forwarding, cloud logging, log ingestion, data normalization, event availability, retention, and telemetry quality.
- Use Cortex XSIAM and XQL Search to investigate, correlate, and respond to firewall, endpoint, identity, cloud, and third-party security events.
- Partner with SOC teams to tune detections, investigate alerts, develop response procedures, improve visibility, and support incident containment and remediation.
- Lead root-cause analyses for major network or security incidents and deliver corrective and preventive action plans.
- Maintain network diagrams, firewall-policy documentation, HA designs, runbooks, change plans, architecture standards, and operational procedures.
- Mentor junior engineers and provide technical leadership during projects, production incidents, and security reviews.
Requirements
- Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field (three additional years if Bachelor’s degree); equivalent relevant experience may be considered.
- 10+ years of progressive experience in network engineering, network security, firewall administration, or security infrastructure operations.
- 6+ years of hands‑on Palo Alto Networks firewall experience in a production enterprise environment.
- Advanced operational experience with Palo Alto Panorama including multi‑device policy management, templates, device groups, upgrades, configuration management, and troubleshooting.
- Strong hands‑on experience designing, maintaining, and troubleshooting Palo Alto High Availability environments.
- Advanced understanding of HA1, HA2, HA3, configuration synchronization, session synchronization, failover behavior, link monitoring, path monitoring, peer health, and recovery processes.
- Strong expertise in TCP/IP, IPv4/IPv6, DNS, DHCP, ARP, routing, NAT, VPNs, and packet‑level troubleshooting.
- Demonstrated ability to investigate TCP handshakes, resets, retransmissions, MTU/MSS issues, asymmetric routing, connection timeouts, and firewall session behavior.
- Extensive experience with Cisco Catalyst and/or Cisco Nexus switching technologies.
- Strong knowledge of enterprise switching and routing including VLANs, trunking, STP/RSTP/MST, EtherChannel, HSRP/VRRP, routing protocols, ACLs, QoS, and switch‑security controls.
- Proven experience designing or implementing network segmentation and microsegmentation solutions.
- Working knowledge of Cortex XSIAM, Strata Logging Service, security‑event correlation, alert investigation, XQL Search, and firewall log ingestion.
- Ability to lead technical design discussions, independently manage complex workstreams, and communicate risks and recommendations to technical and nontechnical stakeholders.
- Strong documentation, change‑management, incident‑management, and root‑cause‑analysis skills.
- Clearance Required: Ability to obtain and maintain a Public Trust clearance.
Technologies
- Palo Alto Networks, PAN-OS, Palo Alto Panorama
- HA1, HA2, HA3
- Cisco Catalyst, Cisco Nexus
- GlobalProtect, IPsec VPN
- Cortex XSIAM, Strata Logging Service, XQL Search
- WildFire, App-ID, URL Filtering, Threat Prevention, DNS Security
- NAT
- STP, RSTP, MST, EtherChannel, HSRP, VRRP, VLANs, QoS
- MTU, MSS
- Python, Ansible, Terraform, REST APIs
- Prisma Access, Prisma Cloud, Cortex XDR, Cortex XSOAR
- Cisco ISE, Cisco ACI, SD-Access
- Fortinet Security Fabric, FortiGate, FortiManager, FortiAnalyzer
- AWS, Azure, Google Cloud Platform
- SIEM, SOAR, EDR/XDR, vulnerability‑management, NDR, network‑monitoring, ticketing platforms
Preferred Skills and Experience
- Palo Alto Networks certifications: PCNSA, PCNSE, PCCSE, or equivalent enterprise‑level experience.
- Cisco certifications: CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, CCIE Security, or comparable expertise.
- Experience with Palo Alto Prisma Access, Prisma Cloud, Cortex XDR, Cortex XSOAR, or cloud‑delivered security services.
- Experience with Cortex XSIAM alert triage, XQL queries, data‑source integrations, detection tuning, dashboards, reporting, and response automation.
- Experience with Cisco ISE, Cisco ACI, SD-Access, or enterprise network‑access‑control solutions.
- Familiarity with Fortinet Security Fabric, FortiGate, FortiManager, and FortiAnalyzer.
- Experience with AWS, Azure, Google Cloud Platform, hybrid‑cloud network design, and cloud‑security controls.
- Familiarity with SIEM, SOAR, EDR/XDR, vulnerability‑management, NDR, network‑monitoring, and ticketing platforms.
- Automation skills using Python, Ansible, Terraform, REST APIs, or related infrastructure‑as‑code and orchestration tools.
- Experience supporting 24x7 environments, participating in an on‑call rotation, leading critical incidents, and executing emergency changes.
Location and Compensation
- Location: Remote (United States)
- Salary: USD 125,000 to 150,000 per year