Senior Network Security Architect -
Location Onsite in San Jose, CA
and EAD
JD:
Client is seeking an experienced Senior Network Security Architect to design, implement, manage, and optimize enterprise network security infrastructure with a strong focus on Palo Alto Networks NGFW, Panorama, Strata Cloud Manager (SCM), and Zscaler (ZIA/ZPA) technologies. The ideal candidate will serve as a senior technical resource responsible for securing enterprise networks, cloud environments, remote access, and Zero Trust architectures while ensuring operational excellence and compliance with security standards.
The role requires hands-on expertise in enterprise security operations, firewall policy management, threat prevention, cloud security, secure remote access, and troubleshooting complex network security issues. Experience with Palo Alto centralized management platforms including Panorama and Strata Cloud Manager, along with Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA), is essential.
Key Responsibilities
Palo Alto Security Administration
- Design, deploy, and support Palo Alto Next-Generation Firewalls (NGFW) across enterprise environments.
- Manage and troubleshoot:
- Security policies
- NAT
- VPNs
- Routing
- App-ID / User-ID
- SSL Decryption
- URL Filtering
- DNS Security
- WildFire
- Threat Prevention
- Perform firewall upgrades, migrations, hardware refreshes, and HA deployments.
- Conduct rule reviews, policy optimization, and security audits.
- Lead troubleshooting and root cause analysis for security incidents.
Panorama & Strata Cloud Manager (SCM)
- Manage large-scale firewall environments using Panorama and SCM.
- Develop centralized policy management and governance standards.
- Manage device onboarding, logging, policy consistency, and visibility.
- Utilize SCM policy analyzer and posture management features.
- Support security compliance and posture improvement initiatives.
Zscaler Administration
- Design, deploy, and administer Zscaler ZIA and ZPA solutions.
- Configure and manage:
- Application Segments
- App Connectors
- Service Edges
- Access Policies
- Browser Access
- Security Policies
- SSL Inspection
- Cloud Firewall
- Data Protection Controls
- Support Zero Trust initiatives.
- Troubleshoot connectivity, authentication, and application access issues.
- Lead migrations from traditional VPN solutions to ZPA.
Security Operations & Cloud Integration
- Monitor and respond to security incidents and vulnerabilities.
- Perform threat hunting and security investigations.
- Collaborate with SOC, Cloud, Infrastructure, and Application teams.
- Support compliance frameworks including:
- Secure Azure and AWS environments using Palo Alto and cloud-native controls.
- Deploy and support Palo Alto VM-Series firewalls.
- Integrate security platforms with SIEM and ticketing tools.
- Automate security operations using APIs, Python, PowerShell, or Terraform.
Required Qualifications
Experience
- 12+ years of Network Security / Security Engineering experience.
- 10+ years of hands-on Palo Alto Networks firewall experience.
- 10+ years managing Panorama environments.
- Hands-on experience with Strata Cloud Manager (SCM).
- 4+ years supporting Zscaler ZIA and ZPA solutions.
- Experience supporting enterprise-scale security operations.
Core Technical Skills
Palo Alto Technologies
- Palo Alto NGFW Administration
- Panorama Management
- Strata Cloud Manager (SCM)
- Palo Alto Logging Service
- SSL Decryption
- Threat Prevention
- WildFire
- DNS Security
- URL Filtering
- NAT & Security Policy Management
- Site-to-Site VPN & IPSec VPN
Zscaler Technologies
- ZIA (Zscaler Internet Access)
- ZPA (Zscaler Private Access)
- Zscaler Client Connector (ZCC)
- Zero Trust Architecture
- Cloud Firewall
- SSL Inspection
- Application Segmentation
- Identity-Based Access Control
Networking
- TCP/IP
- DNS
- DHCP
- VLANs
- Network Segmentation
- Routing & Switching
- BGP
- OSPF
- MPLS
- IPSec
Cloud & Automation
- Microsoft Azure
- AWS
- Cloud Security Architecture
- SASE / SSE Platforms
- Python
- PowerShell
- Terraform
Preferred Qualifications
- PCNSE (Palo Alto Certified Network Security Engineer)
- Palo Alto Strata Cloud Manager Certification
- Zscaler Certified Administrator (ZCCA)
- Zscaler Certified Architect (ZCCA / ZCCA-IA)
- CISSP, CISM, or CCSP
- Experience with Terraform and/or Ansible
- Scripting and automation experience
Key Competencies
- Advanced troubleshooting and analytical skills.
- Strong communication and stakeholder management abilities.
- Experience leading security projects and major incident response efforts.
- Deep understanding of Zero Trust, SASE, and enterprise security architecture.
- Ability to work independently in a large enterprise environment.
- Experience mentoring junior engineers and promoting security best practices.
Navnish kumar
Sr. IT Technical Recruiter
Stellent IT Phone:
Email: navnish
Gtalk: navnishom
