Palo Alto Firewall Engineer

System One

Springfield (VA)

On-site

USD 150,000 - 170,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401(k) plan
Onsite work

Job summary

System One is seeking a Palo Alto Firewall Engineer in Springfield, VA for a contract-to-hire role. You will lead design, configuration, and operations of NGFWs, PAN-OS, and Panorama across a hybrid enterprise, with active TS/SCI clearance.

You will engineer secure network architectures, manage lifecycle, deploy in cloud environments (AWS/Azure/GCP), and coordinate with government authorities. This onsite role offers benefits and career growth within System One.

Qualifications

  • Active TS/SCI clearance required.
  • Bachelor's degree in IT, Cybersecurity or related field.

Responsibilities

  • Design, analyze, test, integrate, and implement secure network architectures around Palo Alto ecosystems.

Skills

TS/SCI clearance
Python automation
Ansible
Terraform
XML/REST APIs
PAN-OS
Panorama
VM-Series
AWS/Azure/GCP
TLS/SSL

Education

Bachelor's degree in IT or Cybersecurity

Tools

Panorama
Prisma Access
VM-Series
Palo Alto NGFWs
PAN-OS

Job description

Job Title: Palo Alto Firewall Engineer
Location: Springfield, VA
Type: Contract To Hire
Compensation: $80/hr. W2 Benefits available
Conversion Salary: $150,000 annually plus benefits
Work Model: Onsite
Security Clearance: Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph

Responsibilities
  • Lead the design, requirements analysis, testing, integration, and implementation of secure network architectures centered on the Palo Alto Networks ecosystem.
  • Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment.
  • Engineer and implement solutions for customer Change Requests (CRQs); assess impacts on enterprise transport and security activities and provide technically sound recommendations.
  • Serve as the technical representative for assigned projects and coordinate issues with the appropriate owners, organizations, contract leadership, and customer leadership.
  • Manage the full lifecycle of Palo Alto hardware and software, including complex hardware refreshes, PAN-OS upgrades, legacy-platform sustainment, physical troubleshooting, and line-card replacements.
  • Develop, oversee, and maintain configuration-management processes, network architecture diagrams, technical documentation, integration and test plans, and Standard Operating Procedures (SOPs) for Palo Alto security platforms.
  • Use Panorama for centralized policy management, including templates, device groups, inheritance, and consistent configuration across a diverse fleet of physical and virtual firewalls.
  • Configure and maintain advanced security capabilities and profiles, including App-ID, User-ID, Content-ID, SSL Decryption, WildFire, NAT, IPSec VPNs, and threat prevention.
  • Oversee security-incident reporting, documentation, investigation, and corrective-action development.
  • Act as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network-security status, policies, procedures, and risks.
  • Evaluate and report on new and emerging network-security and communications technologies to improve network capacity, performance, reliability, standardization, and security.
  • Provide mentorship and technical oversight to junior engineers and serve as an escalation point for complex troubleshooting.
  • Follow all customer network-security processes and procedures, maintain compliance with Government and QA standards, and ensure service-performance indicators are met or exceeded.
Requirements
  • Security Clearance: Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph.
  • A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments.
  • Active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification.
  • DoD 8140.01 and DoD 8570.01-M IAT Level II compliance (for example, Security+ CE).
  • Ability to obtain and maintain a CSSP Infrastructure Support certification within 120 days of the start date.
  • Deep practical knowledge of legacy Gen 2/Gen 3 Palo Alto hardware, including PA-3000 and PA-5000 series platforms, legacy CLI, hardware troubleshooting, and line-card replacements.
  • Experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and VM-Series virtual firewalls in cloud environments such as AWS, Azure, GCP, or private-cloud.
  • Proven expertise with Panorama for centralized policy management, template/device-group inheritance, and configuration deployment across a hybrid firewall fleet.
  • Advanced understanding of BGP, OSPF, IPSec VPNs, NAT, TLS/SSL, mutual TLS (mTLS), HTTP, SAML, OAuth, OCSP revocation, DoD PKI, Kerberos, LDAP, and Active Directory.
  • Experience with F5 technologies, including APM, AFM, and SSL Orchestrator (SSLO), and troubleshooting TLS/SSL handshake/connection issues.
  • Strong network design, engineering, implementation, and troubleshooting skills, including ROM equipment lists and cost estimates.
  • Knowledge of DISA and Intelligence Community security standards and requirements.
  • Excellent interpersonal skills and technical judgment with the ability to work independently and support weekend/evening work if needed.
  • Bachelor’s degree in IT, Cybersecurity, Computer Science, or a related field, with additional relevant experience considered in lieu of a degree.
Desired Qualifications
  • Active Palo Alto Networks Certified Network Security Consultant (PCNSC) or Prisma Certified SASE Professional (PCSAE).
  • F5 Networks Certified Technology Specialist (CTS).
  • Cisco CCNP, CCVP, CCNA, CCDP, or equivalent.
  • ITIL v3 Foundations and/or ISC2 CISSP Certification.
  • Proficiency in Python and automation tools such as Ansible, Terraform, or Palo Alto XML/REST APIs.
  • Hands-on experience with Cortex XDR or Cortex XSOAR.
  • Experience with Palo Alto Networks Expedition for migration and rule consolidation.
  • Knowledge of Zero Trust Network Access (ZTNA) architectures and additional security platforms (e.g., Juniper SRX, Cisco FTD/ASA).
  • Master’s degree in related fields is a plus.

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Firewall/Network Security Administrator
Sr. Firewall/Network Security Administrator

Calance • Tallapoosa (GA)

Hybrid
USD 90,000 - 130,000
EPO/PPO Medical Plans
401K Retirement vesting program
Flex Spending Plan
+1
Palo Alto Network Security Engineer
Palo Alto Network Security Engineer

Sedulous Consulting Services • Fort Belvoir (VA)

On-site
USD 90,000 - 160,000
401K
Life/Health/Dental/DisabilityInsurance
Flexible Paid Leave
+1
Palo Alto Network Security Engineer
Palo Alto Network Security Engineer

Sedulous Consulting Services, LLC • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
401K
Life/Health/Dental/Disability
Flexible Paid Leave
+1
Palo Alto Network Security Engineer
Palo Alto Network Security Engineer

Sedulous Consulting Services, LLC • Fort Meade (MD)

On-site
USD 90,000 - 130,000
401K
Life/Health/ Dental/Disability
Flexible Paid Leave
+1
Palo Alto Firewall Engineer / SME (PCNSE)
Palo Alto Firewall Engineer / SME (PCNSE)

RISA • Springfield (VA)

On-site
USD 117,000 - 128,000
Medical, dental, and vision insurance
401(k) and Roth IRA
Paid time off
Palo Alto Network Security Engineer
Palo Alto Network Security Engineer

Sedulous Consulting Services • Fort Meade (MD)

On-site
USD 92,000 - 165,000
401K
Life Insurance
Health Insurance
+4
Palo Alto Firewall Engineer - Hybrid/New York
Palo Alto Firewall Engineer - Hybrid/New York

Medisys Health Network, Inc. • Village of Garden City (NY)

Hybrid
USD 120,000 - 160,000
Competitive salary
Professional development opportunities
Supportive work environment
Palo Cloud Firewall Engineer SME
Palo Cloud Firewall Engineer SME

Ampcus, Inc • McLean (VA)

On-site
USD 100,000 - 140,000
Palo Alto Firewall Engineer
Palo Alto Firewall Engineer

Veriipro • Atlanta (GA)

On-site
USD 100,000 - 130,000
Mid-Level Network Security Engineer - Palo Alto
Mid-Level Network Security Engineer - Palo Alto

Socket.dev • New York (NY)

On-site
USD 140,000 - 150,000
Unlimited PTO
Health insurance
Company 401k plan
+3