Senior Technical Consultant - Network Security

Thinkahead

United States

Hybrid

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, and Vision Insurance
401(k) plan
Paid time off
Paid parental leave
Paid company holidays

Job summary

Thinkahead is seeking a Senior Technical Consultant to lead firewall, network access control, and SASE engagements across diverse enterprise environments. This client-facing role requires deep expertise in Cisco Secure Firewall, Palo Alto Networks, and SASE architectures.

The ideal candidate will manage project workstreams and deliverables, ensuring successful implementation and knowledge transfer to client teams. This role also involves optimizing network security designs and guiding junior engineers.

Qualifications

  • 7+ years of experience in network security or security engineering.
  • Production experience with Cisco Secure Firewall and Palo Alto Networks.
  • Experience with SASE platforms and identity management solutions.

Responsibilities

  • Lead firewall and NAC engagements in enterprise environments.
  • Configure and deploy cloud-native firewall solutions.
  • Manage project workstreams and deliverables.

Skills

Network security
Firewall configuration
Consulting skills
Identity management
SASE architecture

Tools

Cisco Secure Firewall
Palo Alto Networks NGFW
Cisco ISE
Zscaler
Terraform

Job description

We are an equal opportunity employer and do not discriminate based upon an individual’s race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.

Senior Technical Consultant

We are seeking a Senior Technical Consultant to lead firewall, network access control, and SASE engagements across diverse enterprise environments. This role spans three core technology pillars: next‑generation firewall design and deployment (Cisco Secure Firewall, Palo Alto Networks), Cisco ISE‑based network access control and identity services, and SASE/Zero Trust architectures (Zscaler, Palo Alto Prisma Access, Cisco Secure Access, Netskope). The ideal candidate combines deep hands‑on expertise across these platforms with strong consulting skills, owning end‑to‑end delivery from discovery and design through implementation, testing, and knowledge transfer. This is a client‑facing role that requires the ability to lead technical workstreams, produce professional documentation, and communicate complex security strategies to both technical and executive audiences.

Responsibilities
  • Design and deploy Cisco Secure Firewall Threat Defense (FTD) with FMC, including high‑availability pairs, threat policies (Snort IPS, malware defense, URL filtering), and site‑to‑site and remote‑access VPN configurations.
  • Configure and manage Palo Alto Networks next‑generation firewalls running PAN‑OS, security profiles (Antivirus, Anti‑Spyware, Vulnerability Protection, WildFire), App‑ID, User‑ID, SSL/TLS decryption, and centralized management via Panorama.
  • Lead firewall migration projects including legacy Cisco ASA to FTD conversions, cross‑vendor migrations, and policy translation with rule optimization during cutover.
  • Design network segmentation architectures using firewall zones, virtual routers, VRFs, and policy‑based routing to enforce least‑privilege east‑west and north‑south traffic controls.
  • Deploy cloud‑native firewall solutions including Palo Alto Cloud NGFW for AWS and Azure, and Cisco Secure Firewall Cloud Native for containerized and cloud workload environments.
  • Implement high‑availability designs (active/standby failover, active/active clustering) and multi‑context deployments for service provider and large enterprise environments.
  • Configure centralized logging, SIEM integration (Splunk, Microsoft Sentinel, syslog), and NetFlow/IPFIX for traffic analytics, threat correlation, and compliance reporting.
  • Perform firewall rule base optimization, policy cleanup, and compliance auditing for PCI‑DSS, HIPAA, NIST.
  • Integrate Cisco Secure Firewall with Cisco XDR for cross‑platform threat detection, event correlation, and automated incident response.
  • Automate firewall provisioning, configuration backup, and policy deployment using Terraform, Ansible, and vendor APIs.
  • Deploy Cisco Identity Services Engine (ISE) for 802.1X wired and wireless authentication, MAC Authentication Bypass (MAB), and RADIUS/TACACS+ device administration.
  • Design and implement ISE authorization policies (Security Group Tags, downloadable ACLs, VLAN assignment, Adaptive Network Control).
  • Configure ISE profiling services, posture assessment, and compliance enforcement.
  • Integrate ISE with Cisco network infrastructure (Catalyst switches, wireless LAN controllers, Secure Firewall) and third‑party devices for consistent policy enforcement.
  • Deploy ISE guest portals, BYOD onboarding workflows, and certificate‑based authentication (EAP‑TLS).
  • Implement pxGrid integrations to share identity and session context between ISE, Secure Firewall, Splunk, and third‑party platforms.
  • Design ISE distributed deployments spanning Policy Administration Nodes, Policy Service Nodes, and Monitoring and Troubleshooting Nodes.
  • Perform ISE upgrades, migrations (legacy ACS to ISE), and advanced troubleshooting.
  • Design and implement SASE and Zero Trust architectures for remote user, branch office, cloud workload, and data center connectivity.
  • Configure and deploy Zscaler Internet Access (ZIA) and Private Access (ZPA) including secure web gateway, SSL inspection, URL filtering, sandbox policies, and ZTNA segments.
  • Deploy Palo Alto Prisma Access (GlobalProtect, explicit proxy, Strata Cloud Manager or Panorama integration).
  • Implement Cisco Secure Access (SSE) including Zero Trust Network Access, Secure Web Gateway, CASB, and resource connector.
  • Configure Netskope Security Cloud including Next‑Gen SWG, CASB, NPA, traffic steering, real‑time protection policies, and DLP controls.
  • Leverage Guardicore micro‑segmentation for east‑west traffic control and application ring‑fencing.
  • Deploy identity‑based access controls integrating with Okta, Microsoft Entra ID, SAML 2.0, and SCIM provisioning.
  • Develop and maintain Zero Trust maturity roadmaps.
  • Lead client‑facing discovery sessions, design workshops, and architecture reviews; own creation of HLD and LLD documents, network diagrams, implementation runbooks, and as‑built documentation.
  • Develop migration and cutover plans with rollback procedures, change management workflows, and CAB review packages.
  • Conduct knowledge transfer sessions and train client operations teams on day‑2 management, policy administration, platform operations, and incident response.
  • Manage project workstreams, track milestones and deliverables, and proactively elevate risks.
  • Serve as the technical escalation point for junior engineers and provide mentorship.
  • Contribute to internal practice development including reusable templates, runbooks, and automation playbooks.
Qualifications
  • 7+ years of network security, infrastructure security, or security engineering experience, with at least 3 years in a consulting or client‑facing delivery role.
  • Hands‑on experience designing and deploying Cisco Secure Firewall (FTD/FMC) and Palo Alto Networks NGFW (PAN‑OS/Panorama) in enterprise production environments.
  • Production experience deploying Cisco ISE for 802.1X authentication, TACACS+ device administration, and network access policy enforcement.
  • Production experience with at least one SASE platform (Zscaler ZIA/ZPA, Palo Alto Prisma Access, Cisco Secure Access, or Netskope).
  • Strong understanding of routing protocols (BGP, OSPF, EIGRP), VPN technologies (IPsec, SSL/TLS), network segmentation, and Zero Trust architecture principles.
  • Experience with cloud platforms (AWS VPC, Azure VNet, GCP VPC) including security groups, network firewalls, and hybrid connectivity architectures.
  • Experience with identity and access management platforms (Okta, Microsoft Entra ID, SAML 2.0, SCIM) and their integration with firewall, NAC, and SASE solutions.
  • Experience integrating security platforms with SIEM (Splunk, Microsoft Sentinel), syslog infrastructure, and automation tools (Terraform, Ansible).
Preferred Certifications
  • CCIE Security or CCNP Security certification.
  • Palo Alto PCNSE or PCNSC certification; Zscaler ZCCA/ZCCP; Cisco Secure Access or Netskope certifications.
  • CISSP, CompTIA Security+, or equivalent industry security certification.
  • Firewall migration experience including ASA to FTD conversions and cross‑vendor platform migrations.
Benefits
  • Medical, Dental, and Vision Insurance
  • 401(k) plan
  • Paid company holidays
  • Paid time off
  • Paid parental and caregiver leave
  • Additional benefits; for more details see benefits for additional details.
  • Compensation: The compensation range indicated in this posting reflects the On‑Target Earnings (OTE) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Technical Consultant - Network Security
Senior Technical Consultant - Network Security

AHEAD • United States

On-site
USD 100,000 - 140,000
Medical, Dental, and Vision Insurance
401(k)
Paid time off
Sr. Firewall/Network Security Administrator
Sr. Firewall/Network Security Administrator

Calance • Tallapoosa (GA)

Hybrid
USD 90,000 - 130,000
EPO/PPO Medical Plans
401K Retirement vesting program
Flex Spending Plan
+1
Senior Security Engineer
Senior Security Engineer

MDS is now part of Secur-Serv • Dallas (TX)

On-site
USD 120,000 - 140,000
Principal Technical Consultant - Network Security
Principal Technical Consultant - Network Security

AHEAD • United States

On-site
USD 210,000 - 240,000
Medical, Dental, Vision Insurance
401(k)
Paid time off
+1
Principal Technical Consultant - Network Security
Principal Technical Consultant - Network Security

AHEAD • Northern (KY)

Hybrid
USD 210,000 - 240,000
Medical Insurance
401(k) Plan
Paid Holidays
+1
Sr Network Security Engineer
Sr Network Security Engineer

Worldpac • Flower Mound (TX)

On-site
USD 76,000 - 101,000
Firewall OPS Engineer - Palo Alto
Firewall OPS Engineer - Palo Alto

Tata Consultancy Services • Plano (TX)

On-site
USD 115,000 - 125,000
Discretionary Annual Incentive
Medical Coverage
Parental Leaves
+4
Senior Network Engineer
Senior Network Engineer

Tenth Revolution Group • Menlo Park (CA)

On-site
USD 180,000 - 240,000
Senior Network Security Engineer
Senior Network Security Engineer

NPO USA Inc • Chicago (IL)

Hybrid
USD 80,000 - 92,000
Structured training and certification plans
Corporate benefits: Welfare Plan, Smart Working
Staff Technical Support Engineer, Focused Services, NGFW
Staff Technical Support Engineer, Focused Services, NGFW

Palo Alto Networks, Inc. • Plano (TX)

On-site
USD 117,000 - 190,000