Palo Alto Integration Engineer, Senior
Location: Washington, DC – On-Site
Work Schedule: Full-Time, On-Site – Daily Commute Required
Employment Type: Full-Time
Clearance: Active security clearance or ability to obtain and maintain required Government background investigation and IT access
Salary Range: $135,000 – $160,000 annually
Position Summary
Digital Global Connectors (DGC) is seeking a Palo Alto Integration Engineer, Senior to serve as a senior technical authority responsible for the architecture, engineering, implementation, administration, and continuous improvement of enterprise Palo Alto Networks security infrastructure supporting a Federal Government IT environment.
This is a local, on-site position requiring a daily commute to the customer site in the Washington, DC area. Only candidates who currently reside within a reasonable daily commuting distance of the worksite will be considered. This position is not remote or hybrid, and candidates planning to relocate to the area at a later date will not be considered for this opening.
Key Responsibilities
Palo Alto Architecture & Technical Leadership
- Serve as a senior technical authority and subject matter expert for Palo Alto Networks security technologies.
- Lead the architecture, engineering, implementation, and optimization of enterprise Palo Alto Networks security solutions.
- Develop network security architectures, firewall zone models, security policy frameworks, data-flow diagrams, and platform configuration baselines.
- Lead security architecture reviews for new systems, applications, infrastructure changes, and cloud migrations.
- Design and implement Zero Trust network security architectures using Palo Alto Networks capabilities.
- Evaluate emerging Palo Alto Networks technologies and recommend improvements to security posture and operational effectiveness.
- Provide technical guidance and mentorship to junior and mid-level network security engineers.
Next-Generation Firewall Engineering
- Lead engineering and administration of Palo Alto Networks NGFW infrastructure across perimeter, internal segmentation, data center, and cloud environments.
- Design, implement, and maintain NGFW security policies using App-ID, User-ID, and Content-ID.
- Design and maintain advanced threat-prevention profiles, including antivirus, anti-spyware, vulnerability protection, URL filtering, file blocking, WildFire, and DNS Security.
- Design and implement SSL/TLS decryption policies.
- Lead firewall security-policy lifecycle management, optimization, rule-base cleanup, and policy audits.
- Identify overly permissive rules, unused policies, shadow rules, and policy gaps and implement appropriate remediation.
- Develop and maintain firewall engineering standards, operational runbooks, and troubleshooting procedures.
Panorama Engineering & Administration
- Lead engineering, implementation, and administration of Palo Alto Networks Panorama.
- Design and maintain Panorama device-group and template hierarchies.
- Develop scalable shared-policy, pre-rule, post-rule, and device-specific policy structures.
- Configure and maintain role-based administrative access.
- Lead Panorama upgrades, patches, configuration changes, and platform maintenance.
- Develop operational dashboards, security reports, and compliance reporting capabilities.
Prisma Access & SASE
- Lead engineering and administration of Palo Alto Networks Prisma Access.
- Design and implement GlobalProtect configurations, gateways, agent configurations, split-tunneling policies, and authentication integrations.
- Configure and maintain Prisma Access security policies, threat prevention, URL filtering, and other cloud-delivered security controls.
- Integrate Prisma Access with enterprise identity platforms such as Microsoft Entra ID and Okta.
- Troubleshoot complex remote-access, performance, connectivity, and security-policy issues.
- Optimize Prisma Access services to support secure and reliable access for distributed users.
Prisma Cloud
- Engineer and administer Palo Alto Networks Prisma Cloud capabilities across enterprise cloud environments.
- Support Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP) capabilities.
- Configure compliance frameworks, policies, alerts, and reporting.
- Develop cloud security policies aligned with Federal security requirements.
- Integrate Prisma Cloud findings with SIEM and vulnerability-management processes.
- Work with cloud operations teams to prioritize and remediate identified security issues.
- Support AWS GovCloud and/or Microsoft Azure Government environments.
Cortex XDR & Threat Detection
- Lead engineering and administration of Palo Alto Networks Cortex XDR.
- Configure prevention policies, behavioral threat protection, and detection analytics.
- Develop and tune detection rules and Behavioral Indicators of Compromise (BIOC).
- Align detection capabilities with the MITRE ATT&CK framework.
- Integrate Cortex XDR with SIEM, threat-intelligence, and SOAR capabilities.
- Support alert investigation, incident response, and threat-hunting activities.
- Monitor platform health, endpoint coverage, and detection effectiveness.
Threat Prevention & Security Operations
- Lead continuous improvement of threat-prevention capabilities across Palo Alto Networks technologies.
- Optimize WildFire, DNS Security, URL filtering, vulnerability protection, and other prevention capabilities.
- Analyze security events, threat intelligence, and platform telemetry to identify emerging threats and security gaps.
- Support incident-response containment, eradication, and recovery activities.
- Participate in purple-team and detection-validation activities.
- Develop security-effectiveness metrics and reports for program and Government leadership.
Change Management & Documentation
- Lead development of Palo Alto Networks change requests for Change Advisory Board (CAB) review.
- Develop technical impact assessments, implementation procedures, testing plans, and rollback procedures.
- Coordinate significant platform changes and maintenance activities.
- Conduct post-implementation reviews.
- Develop and maintain architecture documentation, SOPs, runbooks, troubleshooting guides, and knowledge-base materials.
- Ensure technical documentation accurately reflects current production configurations.
Federal Cybersecurity Compliance & ATO
- Ensure Palo Alto Networks technologies are configured and maintained in accordance with applicable Federal cybersecurity requirements.
- Support compliance with NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, applicable OMB requirements, DISA STIGs, and customer-specific cybersecurity requirements.
- Support ATO activities, including security-control documentation, SSP contributions, continuous-monitoring evidence, and audit artifacts.?? Wait I'm mixing. Actually need to correct.