We are an equal opportunity employer and do not discriminate based upon an individual’s race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.
Senior Technical Consultant
We are seeking a Senior Technical Consultant to lead firewall, network access control, and SASE engagements across diverse enterprise environments. This role spans three core technology pillars: next‑generation firewall design and deployment (Cisco Secure Firewall, Palo Alto Networks), Cisco ISE‑based network access control and identity services, and SASE/Zero Trust architectures (Zscaler, Palo Alto Prisma Access, Cisco Secure Access, Netskope). The ideal candidate combines deep hands‑on expertise across these platforms with strong consulting skills, owning end‑to‑end delivery from discovery and design through implementation, testing, and knowledge transfer. This is a client‑facing role that requires the ability to lead technical workstreams, produce professional documentation, and communicate complex security strategies to both technical and executive audiences.
Responsibilities
- Design and deploy Cisco Secure Firewall Threat Defense (FTD) with FMC, including high‑availability pairs, threat policies (Snort IPS, malware defense, URL filtering), and site‑to‑site and remote‑access VPN configurations.
- Configure and manage Palo Alto Networks next‑generation firewalls running PAN‑OS, security profiles (Antivirus, Anti‑Spyware, Vulnerability Protection, WildFire), App‑ID, User‑ID, SSL/TLS decryption, and centralized management via Panorama.
- Lead firewall migration projects including legacy Cisco ASA to FTD conversions, cross‑vendor migrations, and policy translation with rule optimization during cutover.
- Design network segmentation architectures using firewall zones, virtual routers, VRFs, and policy‑based routing to enforce least‑privilege east‑west and north‑south traffic controls.
- Deploy cloud‑native firewall solutions including Palo Alto Cloud NGFW for AWS and Azure, and Cisco Secure Firewall Cloud Native for containerized and cloud workload environments.
- Implement high‑availability designs (active/standby failover, active/active clustering) and multi‑context deployments for service provider and large enterprise environments.
- Configure centralized logging, SIEM integration (Splunk, Microsoft Sentinel, syslog), and NetFlow/IPFIX for traffic analytics, threat correlation, and compliance reporting.
- Perform firewall rule base optimization, policy cleanup, and compliance auditing for PCI‑DSS, HIPAA, NIST.
- Integrate Cisco Secure Firewall with Cisco XDR for cross‑platform threat detection, event correlation, and automated incident response.
- Automate firewall provisioning, configuration backup, and policy deployment using Terraform, Ansible, and vendor APIs.
- Deploy Cisco Identity Services Engine (ISE) for 802.1X wired and wireless authentication, MAC Authentication Bypass (MAB), and RADIUS/TACACS+ device administration.
- Design and implement ISE authorization policies (Security Group Tags, downloadable ACLs, VLAN assignment, Adaptive Network Control).
- Configure ISE profiling services, posture assessment, and compliance enforcement.
- Integrate ISE with Cisco network infrastructure (Catalyst switches, wireless LAN controllers, Secure Firewall) and third‑party devices for consistent policy enforcement.
- Deploy ISE guest portals, BYOD onboarding workflows, and certificate‑based authentication (EAP‑TLS).
- Implement pxGrid integrations to share identity and session context between ISE, Secure Firewall, Splunk, and third‑party platforms.
- Design ISE distributed deployments spanning Policy Administration Nodes, Policy Service Nodes, and Monitoring and Troubleshooting Nodes.
- Perform ISE upgrades, migrations (legacy ACS to ISE), and advanced troubleshooting.
- Design and implement SASE and Zero Trust architectures for remote user, branch office, cloud workload, and data center connectivity.
- Configure and deploy Zscaler Internet Access (ZIA) and Private Access (ZPA) including secure web gateway, SSL inspection, URL filtering, sandbox policies, and ZTNA segments.
- Deploy Palo Alto Prisma Access (GlobalProtect, explicit proxy, Strata Cloud Manager or Panorama integration).
- Implement Cisco Secure Access (SSE) including Zero Trust Network Access, Secure Web Gateway, CASB, and resource connector.
- Configure Netskope Security Cloud including Next‑Gen SWG, CASB, NPA, traffic steering, real‑time protection policies, and DLP controls.
- Leverage Guardicore micro‑segmentation for east‑west traffic control and application ring‑fencing.
- Deploy identity‑based access controls integrating with Okta, Microsoft Entra ID, SAML 2.0, and SCIM provisioning.
- Develop and maintain Zero Trust maturity roadmaps.
- Lead client‑facing discovery sessions, design workshops, and architecture reviews; own creation of HLD and LLD documents, network diagrams, implementation runbooks, and as‑built documentation.
- Develop migration and cutover plans with rollback procedures, change management workflows, and CAB review packages.
- Conduct knowledge transfer sessions and train client operations teams on day‑2 management, policy administration, platform operations, and incident response.
- Manage project workstreams, track milestones and deliverables, and proactively elevate risks.
- Serve as the technical escalation point for junior engineers and provide mentorship.
- Contribute to internal practice development including reusable templates, runbooks, and automation playbooks.
Qualifications
- 7+ years of network security, infrastructure security, or security engineering experience, with at least 3 years in a consulting or client‑facing delivery role.
- Hands‑on experience designing and deploying Cisco Secure Firewall (FTD/FMC) and Palo Alto Networks NGFW (PAN‑OS/Panorama) in enterprise production environments.
- Production experience deploying Cisco ISE for 802.1X authentication, TACACS+ device administration, and network access policy enforcement.
- Production experience with at least one SASE platform (Zscaler ZIA/ZPA, Palo Alto Prisma Access, Cisco Secure Access, or Netskope).
- Strong understanding of routing protocols (BGP, OSPF, EIGRP), VPN technologies (IPsec, SSL/TLS), network segmentation, and Zero Trust architecture principles.
- Experience with cloud platforms (AWS VPC, Azure VNet, GCP VPC) including security groups, network firewalls, and hybrid connectivity architectures.
- Experience with identity and access management platforms (Okta, Microsoft Entra ID, SAML 2.0, SCIM) and their integration with firewall, NAC, and SASE solutions.
- Experience integrating security platforms with SIEM (Splunk, Microsoft Sentinel), syslog infrastructure, and automation tools (Terraform, Ansible).
Preferred Certifications
- CCIE Security or CCNP Security certification.
- Palo Alto PCNSE or PCNSC certification; Zscaler ZCCA/ZCCP; Cisco Secure Access or Netskope certifications.
- CISSP, CompTIA Security+, or equivalent industry security certification.
- Firewall migration experience including ASA to FTD conversions and cross‑vendor platform migrations.
Benefits
- Medical, Dental, and Vision Insurance
- 401(k) plan
- Paid company holidays
- Paid time off
- Paid parental and caregiver leave
- Additional benefits; for more details see benefits for additional details.
- Compensation: The compensation range indicated in this posting reflects the On‑Target Earnings (OTE) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.