Senior Network Security Engineer

Staffing Science

Austin (TX)

Hybrid

USD 140,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Staffing Science in Austin, TX seeks a Senior Network Security Engineer to secure connectivity across hybrid and multi-cloud environments with a focus on AWS. This is a hands-on, senior technical authority role for firewall services, cloud network security controls, and segmentation strategies.

Deep expertise with Palo Alto Networks firewalls and Panorama, GlobalProtect, and lifecycle management across 24x7 global operations is required.

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, or equivalent experience.
  • 8+ years of enterprise network engineering with a firewall focus.
  • Hands-on experience with Palo Alto Networks firewalls and Panorama in large-scale environments.
  • Strong knowledge of TCP/IP, routing, switching, VPNs, and segmentation at scale.
  • Experience supporting hybrid and multi-cloud networks, incl. AWS.

Responsibilities

  • Architect and operate enterprise-scale firewall solutions across on-prem data centers and multi-clouds.
  • Lead global firewall strategy for hybrid connectivity and cloud landing zones.
  • Design and enforce network segmentation and zero-trust principles at scale.
  • Develop automation for firewall provisioning and policy management using IaC.
  • Provide Tier 3/4 support and incident management for global environments.

Skills

Firewall design
Network security
Cloud networking
Zero trust

Education

Bachelor's degree in Computer Science, IT, Cybersecurity, or equivalent

Tools

Palo Alto Panorama
GlobalProtect

Job description

Location: Hybrid — 3 days/week on-site in Austin, TX. Candidates hybrid from Chandler, AZ will also be considered.

Job Summary

Our client, a global enterprise organization, is seeking a Senior Network Security Engineer to secure and enable connectivity across hybrid and multi-cloud environments, with a strong focus on AWS. This role is a senior technical authority for next-generation firewall services, cloud network security controls, and segmentation strategies across data centers, regional hubs, cloud landing zones, and remote access environments.

This is a hands-on role requiring deep expertise with Palo Alto Networks firewalls and Panorama, including large-scale policy management, GlobalProtect remote access architecture, advanced threat prevention, and global firewall lifecycle management across a 24x7, multi-region business.

Key Responsibilities
Global Firewall & Network Security Architecture
  • Architect, design, and operate enterprise-scale firewall solutions across on-premises data centers and multi-cloud environments (AWS-focused, with Azure exposure)
  • Lead global firewall strategy for hybrid connectivity, cloud landing zones, shared services, and inter-region connectivity
  • Design and enforce network segmentation, zero trust principles, and least-privilege access at global scale
  • Architect and manage Palo Alto Panorama for centralized policy management, device group hierarchy, and template-based configuration standardization
  • Design and implement scalable GlobalProtect VPN architectures, including multi-portal/multi-gateway deployments, HIP-based policy enforcement, and certificate-based authentication
  • Lead migration and consolidation of distributed firewall environments into centralized Panorama-managed platforms
Cloud Security (AWS-focused)
  • Implement and manage cloud-native and virtual firewall solutions within AWS environments
  • Partner with Cloud Platform teams to integrate network security services into cloud adoption frameworks and landing zones
  • Secure site-to-site, inter-VPC, and hybrid connectivity (VPN, Direct Connect)
  • Extend enterprise firewall policies and segmentation strategies consistently into cloud environments
  • Support automated, policy-driven firewall deployments using infrastructure-as-code and CI/CD pipelines
Operations, Reliability & Incident Management
  • Provide Tier 3/4 operational support for firewall and perimeter security services across global environments
  • Lead troubleshooting and root cause analysis of complex, multi-region network security incidents
  • Perform advanced diagnostics using packet capture, session flow analysis, and traffic logging within Palo Alto platforms
  • Troubleshoot NAT, VPN (IPsec and GlobalProtect), routing (BGP/OSPF), asymmetric traffic, and application-layer issues
  • Participate in a global on-call rotation supporting 24x7 business operations
  • Ensure firewall policies align with global security standards and regulatory requirements (PCI DSS, SOX, ISO 27001, NIST)
  • Enforce standardized security policies globally using Panorama device groups and templates
  • Leverage App-ID, User-ID, and Content-ID to enforce identity-aware, application-based security controls
  • Support internal/external audits, risk assessments, and compliance initiatives
  • Automate firewall provisioning and policy management using Panorama APIs, scripting, and IaC tools (Python, Terraform)
  • Integrate firewall configurations into CI/CD pipelines to reduce manual effort and configuration drift
  • Develop reporting and analytics leveraging Panorama logs and SIEM platforms
  • Act as senior technical mentor and escalation point for regional network and security engineering teams
  • Lead large-scale firewall lifecycle initiatives, including global hardware refresh programs and multi-site deployments
  • Collaborate with Cloud Engineering, Security Operations, Infrastructure, and Application teams
Required Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience
  • 8+ years of enterprise network engineering experience with a strong focus on firewall and network security
  • Deep hands-on experience with Palo Alto Networks firewalls and Panorama in large-scale, globally distributed environments
  • Strong knowledge of TCP/IP, routing, switching, VPNs, segmentation, and traffic inspection at scale
  • Proven experience supporting hybrid and multi-cloud enterprise networks, with meaningful AWS experience
Preferred Qualifications
  • Experience designing and operating GlobalProtect VPN solutions, including HIP profiles and ZTNA approaches
  • Strong expertise in Palo Alto advanced features: App-ID, User-ID, Content-ID, SSL decryption, threat prevention
  • Experience operating within multinational, multi-region enterprise environments
  • Industry certifications: PCNSE, CCNP Security, CCSE, CISSP, or equivalent
  • Experience with infrastructure-as-code and network security automation
  • Background in regulated or high-compliance industries
  • Global enterprise environment supporting multiple regions and time zones
  • Hybrid model: 3 days/week on-site in Austin, TX (hybrid from Chandler, AZ may also be considered)
  • Participation in global operational calls and scheduled maintenance windows as required
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Engineer
Senior Network Engineer

Talis Consulting Group • Seattle (WA)

Hybrid
USD 120,000 - 180,000
Health benefits
Paid time off
Hybrid work environment
Security Tool Engineer – Palo Alto
Security Tool Engineer – Palo Alto

electro soft • Atlanta (GA)

On-site
USD 130,000 - 150,000
Global Firewall & Cloud Security Engineer (AWS/Palo Alto)
Global Firewall & Cloud Security Engineer (AWS/Palo Alto)

Staffing Science • Austin (TX)

Hybrid
USD 140,000 - 210,000
Senior Security Engineer
Senior Security Engineer

MDS is now part of Secur-Serv • Princeton (NJ)

Hybrid
USD 120,000 - 140,000
Network Security Engineer
Network Security Engineer

Magnit Global • Denver (CO)

On-site
USD 125,000 - 150,000
Mid-Level Network Security Engineer - Palo Alto
Mid-Level Network Security Engineer - Palo Alto

Myriad360 • New York (NY)

On-site
USD 140,000 - 150,000
Unlimited PTO
Incentive compensation
401k contributions
+3
Security Tool Engineer – Palo Alto Electrosoft · Atlanta, GA Full-time · On-site $130,000–150,000 4 hours ago
Security Tool Engineer – Palo Alto Electrosoft · Atlanta, GA Full-time · On-site $130,000–150,000 4 hours ago

Emploive • Atlanta (GA)

Hybrid
USD 130,000 - 150,000
Sr. Firewall/Network Security Administrator
Sr. Firewall/Network Security Administrator

Calance • Tallapoosa (GA)

Hybrid
USD 90,000 - 130,000
EPO/PPO Medical Plans
401K Retirement vesting program
Flex Spending Plan
+1
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Socket.dev • California (MO)

On-site
USD 154,000 - 250,000
Principal Enterprise Network Security Architect
Principal Enterprise Network Security Architect

Palo Alto Networks • Santa Clara (CA)

On-site
USD 154,000 - 250,000