Palo Alto Subject Matter Expert

CACI

Springfield (VA)

On-site

USD 75,000 - 158,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CAC I seeks a Palo Alto NSS SME to lead enterprise network security initiatives, integrating legacy Gen 2/3 hardware with Prisma Access and Cortex XSOAR. You will drive secure, modern architectures and oversee firewall infrastructure across a hybrid enterprise.

You will design, deploy, and upgrade PAN-OS across devices, manage policies via Panorama, and mentor junior engineers while coordinating with government stakeholders to ensure compliance and reliability.

Qualifications

  • Active TS/SCI clearance with polygraph ability.
  • 7+ years managing Palo Alto NGFWs in large enterprises.
  • PCNSE certification; DoD 8140.01/8570.01-M IAT II compliant.
  • CSSP Infrastructure Support certification within 120 days.

Responsibilities

  • Lead design, analysis, testing and implementation of Palo Alto security architectures.
  • Administer, configure, and troubleshoot NGFWs across a hybrid environment.
  • Manage hardware/software lifecycles including PAN-OS upgrades.
  • Develop and maintain SOPs for Palo Alto security platforms.
  • Use Panorama for centralized policy management across devices.
  • Configure master security profiles (App-ID, User-ID, Content-ID, SSL Decryption, WildFire).
  • Oversee incident investigations and corrective actions.
  • Collaborate with government and contract leadership on security status and policies.
  • Mentor junior engineers and escalate complex issues.

Skills

TS/SCI clearance
PCNSE cert
Security+ or DoD 8570.01-M
Cortex XSOAR familiarity
PAN-OS expertise

Education

Bachelor’s degree in IT/Cybersecurity/CS

Tools

Palo Alto NGFW
PAN-OS
Panorama
Prisma Access
VM-Series

Job description

The Opportunity:

As a Palo Alto Subject Matter Expert (SME) on the Network Security Services (NSS) team, you will be the focal point for all Palo Alto-related tasks, operations, and projects. You will work with both corporate and customer leadership to research, analyze, and implement enterprise-wide network security solutions that bridge legacy and next-generation architectures. This role requires a unique blend of deep, hands-on expertise with traditional Gen 2/Gen 3 hardware platforms and modern, cloud-native solutions like Prisma Access (SASE) and Cortex XSOAR. You will provide critical technical oversight, ensuring the stability, security, and modernization of our firewall infrastructure.

Responsibilities:
  • Lead the design, analysis, testing, and implementation of state-of-the-art secure network architectures centered on the Palo Alto Networks ecosystem.
  • Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment.
  • Manage the full lifecycle of Palo Alto hardware and software, including executing complex hardware refreshes and PAN-OS upgrades, especially on legacy platforms.
  • Develop, oversee, and maintain configuration management processes and Standard Operating Procedures (SOPs) for all Palo Alto security platforms.
  • Utilize Panorama for centralized policy management, ensuring consistent and efficient configuration across a diverse fleet of physical and virtual firewalls.
  • Configure and maintain master-level security profiles, including App-ID, User-ID, Content-ID, SSL Decryption, and WildFire threat prevention.
  • Oversee the reporting, documentation, and investigation of security-related incidents, and lead the development of corrective measures.
  • Act as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network security status, policies, and procedures.
  • Evaluate and report on new and emerging network security technologies to enhance the capabilities, performance, and reliability of the network. Provide mentorship and technical oversight to junior engineers, and act as an escalation point for complex troubleshooting efforts.
Qualifications:
Required:
  • Security Clearance: Must possess an active TS/SCI clearance and be able to successfully pass/maintain a U.S. Government Polygraph.
  • A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments.
  • Must hold an active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. Must be DoD 8140.01 and DoD 8570.01-M IAT Level II compliant (e.g., Security+ CE).
  • Must be able to successfully obtain/maintain a CSSP Infrastructure Support certification within 120 days of the start date.
  • Deep, practical knowledge of legacy Gen 2/Gen 3 hardware (e.g., PA-3000, PA-5000 series), including legacy CLI, physical hardware troubleshooting, and line-card replacements.
  • Next-Gen & Cloud Security: Direct experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and virtual firewalls (VM-Series) in public/private cloud environments (AWS, Azure, or GCP).
  • Proven expertise utilizing Panorama for centralized policy management, template/device group inheritance, and pushing configurations across a hybrid fleet.
  • Network Foundations: Advanced understanding of core networking protocols critical to firewall routing and legacy-to-modern transitions, specifically BGP, OSPF, IPSec VPNs, and NAT.
  • Bachelor’s degree in a related field (e.g., IT, Cybersecurity, Computer Science). Additional years of relevant experience may be considered in lieu of a degree.
Desired:
  • Advanced Certifications: Active Palo Alto Networks Certified Network Security Consultant (PCNSC) or Prisma Certified SASE Professional (PCSAE).
  • Automation & Scripting: Proficiency in Python and experience automating firewall deployment, policy changes, and configuration backups using Ansible, Terraform, or Palo Alto XML/REST APIs.
  • Security Orchestration: Hands-on experience with Cortex XDR or Cortex XSOAR for automated threat response.
  • Migration Tools: Proficiency using Palo Alto Networks Expedition to migrate and consolidate legacy rules to modern App-ID-based policies.
  • Enterprise Architecture: Background in designing Zero Trust Network Access (ZTNA) architectures across complex, segment-isolated enterprise environments.
  • Broader Experience: Experience with other security platforms and technologies such as F5 (APM, AFM), Juniper SRX, and Cisco FTD/ASA.
What You Can Expect:

A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose – to ensure the safety of our nation.

An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

A focus on continuous growth.

Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.

Pay Range:

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

Since this position can be worked in more than one location, the range shown is the national average for the position.

The proposed salary range for this position is: $75,200-$158,100

CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Palo Alto Subject Matter Expert
Palo Alto Subject Matter Expert

CACI International Inc • Springfield (VA)

On-site
USD 75,000 - 159,000
Comprehensive benefits package
Flexible time-off benefits
Learning and development opportunities
Palo Alto Subject Matter Expert Springfield, VA, US + 1 more
Palo Alto Subject Matter Expert Springfield, VA, US + 1 more

CACI International Inc. • Springfield (VA)

On-site
USD 75,000 - 159,000
Flexible time off
Comprehensive benefits
Learning and development opportunities
Network Firewall Lead
Network Firewall Lead

CACI • Sterling (VA)

On-site
USD 121,000 - 266,000
Network Firewall Engineer
Network Firewall Engineer

CACI • Sterling (VA)

On-site
USD 121,000 - 266,000
Senior Firewall Engineer
Senior Firewall Engineer

CACI International Inc • Springfield (VA)

On-site
USD 75,000 - 158,000
Network Firewall Lead
Network Firewall Lead

CACI International Inc • Sterling (VA)

On-site
USD 120,000 - 266,000
Healthcare
Wellness benefits
Financial benefits
+2
Lead Firewall Engineer Arnold, MO, US
Lead Firewall Engineer Arnold, MO, US

CACI International Inc. • Arnold (MO)

On-site
USD 90,000 - 190,000
Senior Firewall Engineer
Senior Firewall Engineer

CACI • Springfield (VA)

On-site
USD 75,000 - 158,000
Principal Network Engineering Lead
Principal Network Engineering Lead

CACI • Arlington (VA)

On-site
USD 121,000 - 266,000
Senior Network Engineer
Senior Network Engineer

CACI • Columbia (MD)

On-site
USD 121,000 - 266,000