Location: Hybrid — 3 days/week on-site in Austin, TX. Candidates hybrid from Chandler, AZ will also be considered.
Job Summary
Our client, a global enterprise organization, is seeking a Senior Network Security Engineer to secure and enable connectivity across hybrid and multi-cloud environments, with a strong focus on AWS. This role is a senior technical authority for next-generation firewall services, cloud network security controls, and segmentation strategies across data centers, regional hubs, cloud landing zones, and remote access environments.
This is a hands-on role requiring deep expertise with Palo Alto Networks firewalls and Panorama, including large-scale policy management, GlobalProtect remote access architecture, advanced threat prevention, and global firewall lifecycle management across a 24x7, multi-region business.
Key Responsibilities
Global Firewall & Network Security Architecture
- Architect, design, and operate enterprise-scale firewall solutions across on-premises data centers and multi-cloud environments (AWS-focused, with Azure exposure)
- Lead global firewall strategy for hybrid connectivity, cloud landing zones, shared services, and inter-region connectivity
- Design and enforce network segmentation, zero trust principles, and least-privilege access at global scale
- Architect and manage Palo Alto Panorama for centralized policy management, device group hierarchy, and template-based configuration standardization
- Design and implement scalable GlobalProtect VPN architectures, including multi-portal/multi-gateway deployments, HIP-based policy enforcement, and certificate-based authentication
- Lead migration and consolidation of distributed firewall environments into centralized Panorama-managed platforms
Cloud Security (AWS-focused)
- Implement and manage cloud-native and virtual firewall solutions within AWS environments
- Partner with Cloud Platform teams to integrate network security services into cloud adoption frameworks and landing zones
- Secure site-to-site, inter-VPC, and hybrid connectivity (VPN, Direct Connect)
- Extend enterprise firewall policies and segmentation strategies consistently into cloud environments
- Support automated, policy-driven firewall deployments using infrastructure-as-code and CI/CD pipelines
Operations, Reliability & Incident Management
- Provide Tier 3/4 operational support for firewall and perimeter security services across global environments
- Lead troubleshooting and root cause analysis of complex, multi-region network security incidents
- Perform advanced diagnostics using packet capture, session flow analysis, and traffic logging within Palo Alto platforms
- Troubleshoot NAT, VPN (IPsec and GlobalProtect), routing (BGP/OSPF), asymmetric traffic, and application-layer issues
- Participate in a global on-call rotation supporting 24x7 business operations
- Ensure firewall policies align with global security standards and regulatory requirements (PCI DSS, SOX, ISO 27001, NIST)
- Enforce standardized security policies globally using Panorama device groups and templates
- Leverage App-ID, User-ID, and Content-ID to enforce identity-aware, application-based security controls
- Support internal/external audits, risk assessments, and compliance initiatives
- Automate firewall provisioning and policy management using Panorama APIs, scripting, and IaC tools (Python, Terraform)
- Integrate firewall configurations into CI/CD pipelines to reduce manual effort and configuration drift
- Develop reporting and analytics leveraging Panorama logs and SIEM platforms
- Act as senior technical mentor and escalation point for regional network and security engineering teams
- Lead large-scale firewall lifecycle initiatives, including global hardware refresh programs and multi-site deployments
- Collaborate with Cloud Engineering, Security Operations, Infrastructure, and Application teams
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience
- 8+ years of enterprise network engineering experience with a strong focus on firewall and network security
- Deep hands-on experience with Palo Alto Networks firewalls and Panorama in large-scale, globally distributed environments
- Strong knowledge of TCP/IP, routing, switching, VPNs, segmentation, and traffic inspection at scale
- Proven experience supporting hybrid and multi-cloud enterprise networks, with meaningful AWS experience
Preferred Qualifications
- Experience designing and operating GlobalProtect VPN solutions, including HIP profiles and ZTNA approaches
- Strong expertise in Palo Alto advanced features: App-ID, User-ID, Content-ID, SSL decryption, threat prevention
- Experience operating within multinational, multi-region enterprise environments
- Industry certifications: PCNSE, CCNP Security, CCSE, CISSP, or equivalent
- Experience with infrastructure-as-code and network security automation
- Background in regulated or high-compliance industries
- Global enterprise environment supporting multiple regions and time zones
- Hybrid model: 3 days/week on-site in Austin, TX (hybrid from Chandler, AZ may also be considered)
- Participation in global operational calls and scheduled maintenance windows as required