Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)

AT&T

City of Middletown (NY)

On-site

USD 150,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

AT&T is seeking a Principal Cybersecurity Engineer to join our global cybersecurity team in person. This hands-on, deeply technical role focuses on firewall policy operations, optimization, and automation at enterprise scale.

You will work onsite five days a week in the Charlotte, NC hub, with potential consideration for other strong matches; expects 7+ years in firewall policies and PAN-OS expertise, and strong collaboration across IT and security teams.

Qualifications

  • 7+ years’ experience operating and maintaining Firewall Policies (Rule Sets).
  • Extensive hands-on experience managing enterprise Firewall Policy in production environments.
  • Strong operational discipline: change control validation, closely following documented processes, rollback planning, and post-change verification.
  • Proven ability to troubleshoot Network/Security and Firewall Policy issues under time pressure.
  • Experience in large-scale, complex environments with multiple stakeholders.

Responsibilities

  • Optimize and implement firewall rules to mitigate risk and protect data.
  • Own day-to-day firewall policy operations, tuning, cleanup, and hardware decommissions.
  • Safely apply approved firewall policy changes with validation and post-change verification.
  • Troubleshoot connectivity and security policy issues and outages with cross-team collaboration.
  • Drive automation and AI opportunities to reduce manual work and improve accuracy.

Skills

Firewall Policy
Palo Alto
PAN-OS
Automation
AI/AIops
Change Management
Troubleshooting
Cross-functional Collaboration

Education

Bachelor's degree in a technical field

Tools

Palo Alto CLI
Panorama
GitHub Copilot

Job description

Role Summary:

We are looking for aPrincipal Cybersecurity Engineer (Firewall Policy Implementation), with demonstrated AI experienceto join our high-performing cybersecurity Team. This is ahands-on, deeply technical, engineering role for firewall experts withreal-world Firewall Policy operations and management experienceat thelarge-scale enterprise level. This position is not people management and is not intended for junior or mid-level candidates. Supervisory-only or Advisory-only level experience will not suffice for this role. You will be responsible foroperating, maintaining, and optimizing Firewall Platforms, drivingpolicy quality and consistency. Additionally, you will support troubleshooting and operational excellence across a complex, global environment. Over time, you will also help applyOperational Artificial Intelligence (AI) capabilities to improve efficiency, reliability, and security.

This is not a remote or hybrid position. This role requires onsite presence5 days per weekin the Charlotte, NC hub location. However, other hub locations, such as Dallas, TX; Bothell, WA; Middletown, NJ; or Alpharetta, GA may be considered for exceptionally strong candidate matches.

Key Responsibilities:

Typical tasks may include, but are not limited to the following:

  • Security Implementation and Management: Optimize and implement firewall rules to mitigate risk, harden perimeter defenses, and protect systems, critical infrastructure, and customer data.
  • Firewall Policy Lifecycle Management: Own day-to-day firewall policy operations, management, tuning, cleanup, insertions, removals, and hardware decommissions.
  • Execute Configuration Change Management: Safely apply approved firewall policy changes within defined change processes, including validation and post-change verification to ensure changes are properly approved, documented, and meet intended outcomes.
  • Troubleshoot Connectivity and Security Policy Issues and Outages: Collaborate with architecture, engineering, and operations teams to troubleshoot outages and security incidents through identification, triage, analysis, containment, recovery, and root cause determination.
  • Identify and Drive Automation and AIOpportunities: Leverage AT&T-owned and managed instances of Copilot, ChatGPT, GitHub, Gemini Claude, etc., to reduce tedious manual process and improve accuracy.
  • Risk Assessment and Strategic Planning: Perform risk assessments and analyze complex security issues to develop mitigation strategies and reduce attack surface exposure, supporting forward-looking research, planning, and innovation in cybersecurity.
  • Technical Support and Collaboration: Provide technical support and expertise for security-related rollouts and issues. Work closely with IT, network, and business units to integrate security measures, and support various cyber-related projects.
Ramp-Up / Initial Focus:
  • Learn the team’s environment, offerings, tooling, processes, and operating models.
  • Complete structured onboarding: mentoring, coaching sessions, proficiency checks, and shadowing.
  • Earn authorization/sign-off to independently execute Firewall policy changes and operational tasks as directed and participate in an on-call rotation for troubleshooting in coordination with AT&T’s Global Technology Operations Center (GTOC).
Long-Term Focus & Scope:

Once fully integrated into the operational rotation, you will execute changes and navigate processes and systems to deliver Firewall policy updates, removals, monitoring/soak, and incident troubleshooting at enterprise scale as directed.

As proficiency grows, you will help introduce and mature AI-assisted operations to improve throughput, reduce risk, and strengthen defense layers.

Required Qualifications:

This is a Principal Position requiring direct, recent experience implementing, validating, and troubleshooting Firewall Policies.

  • 7+ years’ experience operating and maintaining Firewall Policies (Rule Sets).
  • Extensive hands-on experience managingenterprise Firewall Policyin production environments.
  • Strong operational discipline: change control validation, closely following documented processes, rollback planning, and post-change verification.
  • Proven ability to troubleshoot Network/Security and Firewall Policy issues under time pressure.
  • Experience working in large-scale, complex environments with multiple stakeholders.
Preferred Qualifications:
  • Certified Information Systems Security Professional (CISSP) or equivalent cybersecurity certification (CISM, CISA, CRISC, etc.).
  • Any Palo Alto certifications such asPCNSE / PCNSA(or equivalent demonstrated experience).
  • Experience withPalo Alto CLIpolicy automation, orchestration, or "policy as code" approaches andPythonpolicy scripting.
  • Experience with Visual Studio Code, Jupyter Notebook, and Agentic coding using GitHub Copilot, Claude Code, OpenAI Codex (ChatGPT).
  • 8+ years of hands-on cybersecurity/network security engineering experience, including enterprise operations.
  • 5+ years ofPalo Alto Networks (PAN-OS)Firewall platform and policy management in production environments.
  • Exposure to AI/ML-enabled operations, AIOps, or using AI tooling for incident reduction and efficiency.
  • Familiarity with metrics-driven operations (usage, hit counts, error rates, change success, MTTR, policy hygiene)
  • Experience with AlgoSec, URL Filtering,WildFire,Threat Prevention,DNS Security, and security profile tuning.
  • Experience withSSL decryptionstrategy/operations, including break/fix and exception handling.
  • Exposure toAIOps / Operational AIuse cases (e.g., anomaly detection, change risk scoring, incident summarization, knowledge retrieval, workflow automation).
  • Experience integrating Firewall operations with ITSM and CI/CD tooling (e.g., ServiceNow workflows, change gates, automated validation).
  • Familiarity with network fundamentals at scale: BGP/OSPF basics, VRFs, VLANs, IPsec concepts, DNS, and load-balancing impacts on traffic paths.
Success Looks Like:
  • Safe, accurate, and timely delivery of Firewall changes per SLA requirements with minimal rework.
  • Strong troubleshooting outcomes and reduced incident recurrence.
  • Improved operational efficiency through automation and AI-assisted workflows.
  • Clear documentation and process contributions that scale across the team.
  • Demonstrated expertise withPalo Alto Firewall policy lifecycle: rule creation/updates, cleanup/removals, recertification, and audit-ready documentation.
  • Strong working knowledge ofApp-ID, User-ID, Content-ID, zones, security policies, NAT policies, and service objects.
  • Hands-on experience troubleshooting and resolving issues involving:
    • Security/NAT rule matching and shadowing
    • Routing impacts on policy enforcement
    • Decryption/policy interactions (where applicable)
    • Application behavior vs. port-based assumptions
  • Operational rigor with enterprise change processes: risk assessment, implementation plans, validation/testing, rollback planning, and post-change verification.
  • Experience using centralized management such asPanorama(templates, device groups, commits, commit validation, log collection basics.)
  • Proficiency analyzing logs and traffic flows usingTraffic logs
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)
Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)

AT&T • Alpharetta (GA)

On-site
USD 140,000 - 200,000
Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)
Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)

AT&T • Bothell (WA)

On-site
USD 150,000 - 230,000
Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)
Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)

AT&T • Dallas (TX)

On-site
USD 140,000 - 190,000
Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)
Principal Cybersecurity Engineer – Firewall Policy Implementation (Artificial Intelligence (AI) Experienced)

AT&T • Charlotte (NC)

On-site
USD 155,000 - 261,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement
+4
Junior Palo Alto Integration Technician
Junior Palo Alto Integration Technician

VIATEQ Corporation • Washington

Hybrid
USD 55,000 - 75,000
Principal Firewall Policy Engineer – Onsite
Principal Firewall Policy Engineer – Onsite

AT&T • Charlotte (NC)

On-site
USD 155,000 - 261,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement
+4
Palo Alto Engineer
Palo Alto Engineer

TEKsystems • Winston-Salem (NC)

Hybrid
USD 76,000 - 90,000
Medical, dental & vision
401(k)
Life Insurance
+5
Palo Alto Integration Engineer, Senior
Palo Alto Integration Engineer, Senior

Digital-Global-Connectors • McLean (VA)

On-site
USD 135,000 - 160,000
Palo Alto Integration Engineer, Senior
Palo Alto Integration Engineer, Senior

Digital Global Connectors • McLean (VA)

On-site
USD 135,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Secur-Serv • Charlotte (NC)

On-site
USD 120,000 - 135,000