Senior Palo Alto Networks Engineer

CELESTIAL INNOVATIONS GROUP LLC

Washington (District of Columbia)

Hybrid

USD 100,000 - 130,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

401(k)
Competitive salary
Health insurance
Paid time off
Training & development
Flexible work from home options

Job summary

A leading technology consulting firm in Washington DC is searching for an experienced Palo Alto Networks Professional Services Consultant to support federal clients. This role involves designing advanced network and cloud security solutions while ensuring compliance with federal standards like FedRAMP and NIST. Key qualifications include PCNSE and PCCSE certifications, along with a strong background in network security technologies. The position offers competitive compensation and opportunities for professional development in a mission-focused environment.

Qualifications

  • 5+ years of experience implementing enterprise network security solutions.
  • Proficiency in Prisma Access architecture and management.
  • Strong expertise in security compliance frameworks like NIST SP 800-53.

Responsibilities

  • Lead design and deployment of Palo Alto Networks solutions in government environments.
  • Conduct security assessments and deliver remediation roadmaps.
  • Mentor client IT and security teams for sustainable solutions.

Skills

Active PCNSE certification
Active PCCSE certification
Experience with Palo Alto technologies
Knowledge of cloud security principles
Strong communication skills

Tools

Terraform
Ansible

Job description

Benefits:
  • 401(k)
  • Competitive salary
  • Dental insurance
  • Health insurance
  • Paid time off
  • Training & development
  • Vision insurance
Position Overview

Celestial Innovations Group (CIG) is seeking an experienced Palo Alto Networks Professional Services Consultant to support our growing federal and government client portfolio. In this role, you will serve as a trusted security advisor and hands‑on technical lead, designing and implementing cutting‑edge network and cloud security solutions for civilian, defense, and intelligence community agencies. You will work closely with CIG's delivery team and government stakeholders to ensure that security architectures meet the stringent requirements of federal compliance frameworks including FedRAMP, FISMA, NIST SP 800-53, and CMMC.

Key Responsibilities
  • Strengthen and grow the CIG Palo Alto Networks services organization, acting as a technical lead and mentor to fellow engineers.
  • Lead end‑to‑end design, deployment, and configuration of Palo Alto Networks solutions (NGFW, Panorama, Prisma Access, Prisma Cloud) within secure government environments.
  • Architect Zero Trust Network Access (ZTNA) frameworks aligned with federal mandates (OMB M-22-09, EO 14028) using Prisma Access and SD‑WAN.
  • Configure and tune next‑generation firewall (NGFW) policies, App‑ID, User‑ID, and Threat Prevention profiles to enforce least‑privilege access and protect critical assets.
  • Implement Prisma Cloud to provide cloud security posture management (CSPM), cloud workload protection (CWP), and compliance monitoring against NIST, CIS, and DoD STIGs.
  • Conduct security assessments, gap analyses, and architecture reviews, delivering actionable findings and remediation roadmaps to stakeholders.
  • Develop and maintain security documentation including system security plans (SSPs), standard operating procedures (SOPs), and Authority to Operate (ATO) support artifacts.
  • Provide mentorship and knowledge transfer to client IT and security teams, building internal capability and ensuring long‑term solution sustainability.
  • Collaborate with CIG's business development and account management teams to identify expansion opportunities, support proposal development, and contribute to solution scoping and estimation.
  • Engage with Palo Alto Networks federal sales and engineering teams to coordinate pre‑sales support, licensing, and product roadmap alignment.
  • Stay current with the Palo Alto Networks portfolio, emerging threat landscape, and industry best practices, contributing to CIG's internal knowledge base and capability development.
Required Qualifications
  • Active PCNSE (Palo Alto Certified Network Security Engineer) certification.
  • Active PCCSE (Palo Alto Certified Cloud Security Engineer) certification.
  • Active Palo Alto Networks Prisma Access Specialization.
  • 5+ years of hands‑on experience designing and implementing enterprise network security solutions with Palo Alto Networks technologies.
  • Deep expertise in Panorama centralized management, policy orchestration, and log management.
  • Proficiency in Prisma Access architecture including GlobalProtect, service connections, remote network onboarding, and security policy enforcement.
  • Strong working knowledge of cloud security principles across AWS, Microsoft Azure, and/or Google Cloud Platform.
  • Demonstrated experience working within federal environments and familiarity with NIST SP 800-53, FedRAMP, FISMA, CMMC, and DoD STIG requirements.
  • Excellent communication skills with the ability to convey complex technical concepts to both technical teams and executive‑level stakeholders.
  • Must be eligible to obtain and maintain a Public Trust or Secret clearance; existing clearance preferred.
Preferred Qualifications
  • Active DoD Secret or TS/SCI clearance.
  • Experience with Xacta, eMASS, or other GRC platforms supporting ATO processes.
  • Professional certifications in cloud platforms: AWS Solutions Architect, Azure Security Engineer, or Google Professional Cloud Security Engineer.
  • Familiarity with CDM (Continuous Diagnostics and Mitigation) program requirements.
  • Experience with network automation and infrastructure‑as‑code tools such as Terraform, Ansible, or Palo Alto Panorama APIs.
  • Prior experience in a VAR, systems integrator, or managed security services provider (MSSP) environment.
Technical Competencies
  • Network Security
  • PA‑Series NGFW (hardware & VM)
  • Panorama policy & device management
  • GlobalProtect VPN & ZTNA
  • Threat Prevention, WildFire, URL Filtering
  • BGP, OSPF, SD‑WAN routing
  • Cloud & SASE
  • Prisma Access (SASE) architecture & deployment
  • Prisma Cloud CSPM / CWP / CIEM
  • AWS, Azure, GCP security services
  • Container & Kubernetes security
  • CI/CD pipeline security integration
What CIG Offers
  • Competitive compensation commensurate with experience and certifications.
  • Access to the latest Palo Alto Networks technologies, lab environments, and training resources.
  • Opportunities to work on high‑impact federal missions with direct national security implications.
  • A collaborative, mission‑driven culture where innovation and excellence are recognized and rewarded.
  • Support for ongoing professional development including Palo Alto Networks and broader cybersecurity certifications.
  • Flexible remote/hybrid work arrangements based on project requirements.
  • Flexible work from home options available.

Flexible work from home options available.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Palo Alto Integration Engineer - Mid
Palo Alto Integration Engineer - Mid

Koniag Government Services • Washington

Hybrid
USD 110,000 - 160,000
Health insurance (medical, dental, and
Palo Alto Subject Matter Expert
Palo Alto Subject Matter Expert

CACI International Inc • Springfield (VA)

On-site
USD 75,000 - 159,000
Comprehensive benefits package
Flexible time-off benefits
Learning and development opportunities
Palo Alto Subject Matter Expert
Palo Alto Subject Matter Expert

CACI • United States

On-site
USD 75,000 - 158,000
Palo Alto Firewall Engineer
Palo Alto Firewall Engineer

System One • Springfield (VA)

On-site
USD 150,000 - 170,000
Health benefits
401(k) plan
Onsite work
Firewall Engineer III
Firewall Engineer III

RISA • Springfield (VA)

On-site
USD 117,000 - 128,000
Medical insurance
Dental insurance
Vision insurance
+1
Palo Alto Firewall Engineer / SME (PCNSE)
Palo Alto Firewall Engineer / SME (PCNSE)

RISA • Springfield (VA)

On-site
USD 117,000 - 128,000
Medical, dental, and vision insurance
401(k) and Roth IRA
Paid time off
Senior Technical Support Engineer ( SASE | Prisma SD-WAN | CNGFW/VM )
Senior Technical Support Engineer ( SASE | Prisma SD-WAN | CNGFW/VM )

Palo Alto Networks • Town of Texas (WI)

On-site
USD 103,000 - 167,000
Network Security Engineer
Network Security Engineer

Credence • Illinois

On-site
USD 110,000 - 170,000
Palo Alto/Prisma Network Engineer
Palo Alto/Prisma Network Engineer

Revel IT • Columbus (OH)

Hybrid
USD 90,000 - 120,000
Competitive salary and benefits
Opportunities for professional growth
Staff InfoSec Engineer
Staff InfoSec Engineer

Palo Alto Networks • United States

On-site
USD 160,000 - 230,000
Healthcare plans
On-site gym
Equity grants
+3