Remote Senior Network & Security Engineer

GovCIO

Montpelier (VT)

Remote

USD 120,000 - 140,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Employee Assistance Program
Corporate Discounts
Learning & Development platform
Training, Education and Certification
Referral Bonus Program
Internal Mobility Program
Paw Insurance
Flexible Work Environment

Job summary

GovCIO is seeking a Senior Network & Security Engineer to lead design, operation, troubleshooting, and continuous improvement of enterprise network-security infrastructure. The role centers on Palo Alto NGFWs, Panorama, HA, Cisco switching, and Cortex XSIAM integration.

You will act as the technical escalation point for complex incidents, drive architecture initiatives, and partner with SOC, infrastructure, cloud, and leadership teams to reduce risk and ensure highly available services.

Qualifications

  • Bachelor’s degree with 8+ years (or commensurate experience).
  • 7+ years of progressive experience in network engineering, network security, firewall administration, or security infrastructure operations.
  • 5+ years of hands‑on Palo Alto Networks firewall experience in a production enterprise environment.
  • Advanced operational experience with Palo Alto Panorama, including multi‑device policy management, templates, device groups, upgrades, configuration management, and troubleshooting.
  • Strong hands‑on experience designing, maintaining, and troubleshooting Palo Alto High Availability environments.
  • Advanced understanding of HA1, HA2, HA3, configuration synchronization, session synchronization, failover behavior, link monitoring, path monitoring, peer health, and recovery processes.
  • Strong expertise in TCP/IP, IPv4/IPv6, DNS, DHCP, ARP, routing, NAT, VPNs, and packet‑level troubleshooting.
  • Demonstrated ability to investigate TCP handshakes, resets, retransmissions, MTU/MSS issues, asymmetric routing, connection timeouts, and firewall session behavior.
  • Extensive experience with Cisco Catalyst and/or Nexus switching technologies.
  • Strong knowledge of enterprise switching and routing, including VLANs, trunking, STP/RSTP/MST, EtherChannel, HSRP/VRRP, routing protocols, ACLs, QoS, and switch‑security controls.
  • Proven experience designing or implementing network segmentation and microsegmentation solutions.
  • Working knowledge of Cortex XSIAM, Strata Logging Service, security‑event correlation, alert investigation, XQL Search, and firewall log ingestion.
  • Ability to lead technical design discussions, independently manage complex workstreams, and communicate risks and recommendations to technical and nontechnical stakeholders.
  • Strong documentation, change‑management, incident‑management, and root‑cause‑analysis skills.

Responsibilities

  • Lead the design, deployment, administration, and lifecycle management of Palo Alto Networks NGFW environments running PAN-OS.
  • Own centralized firewall management through Palo Alto Panorama, including device groups, templates, template stacks, policy inheritance, upgrades, configuration backups, log monitoring, and firewall onboarding.
  • Design and govern security policies using zero-trust, least-privilege, application‑aware, and risk‑based principles.
  • Configure and troubleshoot security zones, NAT, virtual routers, static and dynamic routing, IPsec VPN, GlobalProtect, decryption, URL Filtering, Threat Prevention, WildFire, DNS Security, and App‑ID policies.
  • Lead enterprise network‑segmentation and microsegmentation initiatives using security zones, VLANs, subinterfaces, virtual routers, routing controls, and application‑based security policies.
  • Develop secure controls for traffic between users, servers, applications, management networks, guest networks, IoT/OT devices, data‑center workloads, and cloud resources.
  • Architect, configure, test, and troubleshoot Palo Alto High Availability deployments, including Active/Passive and Active/Active designs as required.
  • Resolve complex HA failures involving HA1 control links, HA2 session/state synchronization, HA3 packet forwarding, peer communications, configuration synchronization, monitoring failures, split‑brain prevention, and failover recovery.
  • Plan and execute HA failover testing, PAN-OS upgrades, disaster‑recovery exercises, and maintenance procedures while minimizing service impact.
  • Troubleshoot HA infrastructure dependencies, including cables, transceivers, switch ports, port channels, VLANs, routing, MTU, latency, packet loss, and redundant‑path failures.
  • Lead the configuration, support, and troubleshooting of Cisco Catalyst and Nexus switching environments.
  • Design and support VLANs, trunking, STP/RSTP/MST, EtherChannel/port channels, HSRP/VRRP, Layer 2/Layer 3 switching, ACLs, QoS, switch security, routing, and access‑control technologies.
  • Diagnoses complex connectivity and performance issues through firewall logs, session inspection, packet captures, CLI diagnostics, switch counters, flow data, and network‑monitoring platforms.
  • Analyze TCP/IP behavior, including handshake failures, SYN/SYN‑ACK/ACK flow, retransmissions, resets, timeouts, asymmetric routing, MTU/MSS issues, fragmentation, latency, packet loss, and NAT translation problems.
  • Verify packet flow across firewall policy, App‑ID, routing, NAT, decryption, threat prevention, VPN, switching, and server/application layers.
  • Monitor firewall management‑plane and dataplane health, including CPU, memory, session capacity, packet buffers, throughput, logging, and interface performance.
  • Integrate Palo Alto NGFWs and Panorama with Strata Logging Service and Cortex XSIAM.
  • Ensure reliable firewall log forwarding, cloud logging, log ingestion, data normalization, event availability, retention, and telemetry quality.
  • Use Cortex XSIAM and XQL Search to investigate, correlate, and respond to firewall, endpoint, identity, cloud, and third‑party security events.
  • Partner with SOC teams to tune detections, investigate alerts, develop response procedures, improve visibility, and support incident containment and remediation.
  • Lead root‑cause analyses for major network or security incidents and deliver corrective and preventive action plans.
  • Develop and maintain network diagrams, firewall‑policy documentation, HA designs, runbooks, change plans, architecture standards, and operational procedures.
  • Mentor junior engineers and provide technical leadership during projects, production incidents, and security reviews.

Skills

Palo Alto Networks
Firewall administration
Network security engineering
PAN-OS
Cortex XSIAM
Strata Logging Service
HA deployments
Cisco switching
Zero-trust security
SOC collaboration

Education

Bachelor's degree

Tools

Palo Alto Panorama
Strata Logging Service
Cortex XSIAM

Job description

GovCIO is seeking a Senior Network & Security Engineer to lead design, operation, troubleshooting, and continuous improvement of enterprise network-security infrastructure. The role centers on Palo Alto NGFWs, Panorama, HA, Cisco switching, and Cortex XSIAM integration.

You will act as the technical escalation point for complex incidents, drive architecture initiatives, and partner with SOC, infrastructure, cloud, and leadership teams to reduce risk and ensure highly available services.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Network Security Engineer - Remote, Palo Alto Expert
Senior Network Security Engineer - Remote, Palo Alto Expert

GovCIO • Augusta (ME)

Remote
USD 120,000 - 140,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Senior Network & Security Engineer - Remote
Senior Network & Security Engineer - Remote

GovCIO • Boise (ID)

Remote
USD 120,000 - 140,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Remote Senior Network & Security Engineer (Palo Alto NGFW)
Remote Senior Network & Security Engineer (Palo Alto NGFW)

GovCIO • Augusta (ME)

Remote
USD 125,000 - 150,000
Employee Perks: EAP
Corporate Discounts
Learning & Development platform
+5
Remote Senior Palo Alto Network & Security Engineer
Remote Senior Palo Alto Network & Security Engineer

GovCIO • Honolulu (HI)

Remote
USD 120,000 - 140,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Remote Senior Network & Security Engineer – Palo Alto
Remote Senior Network & Security Engineer – Palo Alto

GovCIO • Helena (MT)

Remote
USD 120,000 - 140,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+1
Senior Master Network & Security Engineer — Remote
Senior Master Network & Security Engineer — Remote

GovCIO • Juneau (AK)

Remote
USD 125,000 - 150,000
EAP
Corporate Discounts
Learning & Development
+5
Remote Senior Network & Security Engineer | PAN-OS Expert
Remote Senior Network & Security Engineer | PAN-OS Expert

Cybersecurity Jobs • United States

Remote
USD 120,000 - 140,000
Remote Master Network & Security Engineer
Remote Master Network & Security Engineer

GovCIO • Cheyenne (WY)

Remote
USD 125,000 - 150,000
Employee Assistance Program
Corporate Discounts
Learning & Development platform
+5
Remote Master Network & Security Engineer
Remote Master Network & Security Engineer

GovCIO • Montpelier (VT)

Remote
USD 125,000 - 150,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5
Remote Master Network & Security Engineer
Remote Master Network & Security Engineer

GovCIO • Salt Lake City (UT)

Remote
USD 125,000 - 150,000
Employee Assistance Program (EAP)
Corporate Discounts
Learning & Development platform
+5