Title: Senior Network Security Engineer (Palo Alto Specialist)
Location: Remote (USA-based)
Duration: 6-Month Contract
Key Responsibilities
Lead high-impact firewall initiatives, focusing on strategy and execution for:
Comprehensive policy audits and restructuring
Migrating legacy infrastructure to Palo Alto platforms
Facilitating Data Center-to-Cloud and DC-to-DC transitions
Re-engineering High Availability (HA) and network zone architectures
Oversee the change lifecycle, including risk profiling, impact modeling, rollback strategy, and post-implementation verification
Author technical documentation, specifically detailed Methods of Procedure (MOPs) and compliance records
Architect secure network boundaries across Internet edge, Data Center, Campus, and Cloud environments
Deploy and manage connectivity solutions:
Active/Passive and Active/Active HA configurations
GlobalProtect for both Remote Access and Site-to-Site requirements
Robust IPSec and SSL VPN tunnels
Drive firewall optimization:
Refining Security/NAT policies, decryption workflows, and threat profiles
Conducting rulebase hygiene, App-ID optimization, and custom signature development
Leveraging URL Filtering and WildFire for advanced threat defense
Orchestrate via Panorama, while supporting automation efforts (REST APIs, Ansible, or Python) and assisting with security audits
Mandatory Skills
10+ years of dedicated experience in Network Security
6+ years of direct, expert-level experience with Palo Alto NGFW
Deep technical proficiency in:
PAN-OS administration and feature sets
Complex Security and NAT policy logic
HA clusters, VPN architecture, and SSL Decryption
Advanced diagnostics using CLI and deep packet inspection
Proven track record operating within large-scale, enterprise-grade network environments
Technologies & Knowledge
Palo Alto Ecosystem: NGFW (Physical PA-Series & VM-Series), Panorama, GlobalProtect
Security Services: WildFire, URL Filtering, DNS Security
Traffic Inspection: SSL Forward Proxy and Inbound Decryption
Core Networking: Expert knowledge of TCP/IP, BGP, OSPF, VLANs, NAT, and Load Balancing
Certifications (Preferred)
PCNSE (Strongly preferred)
PCNSA
CCNP Security or equivalent industry credential
ITIL Foundation (focused on Change and Incident Management)