Palo Alto Firewall Architect

Hybrid in Dallas, TX, US • Posted 7 hours ago • Updated 7 hours ago
Contract Independent
Contract W2
6 Months
No Travel Required
Remote
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Palo Alto Firewall Architect
  • Panorama
  • GlobalProtect
  • Cisco AnyConnect
  • VPN technologies
  • PKI and certificate authorities
  • TLS and certificate-based authentication
  • Cryptographic key-management platforms and processes
  • NAT
  • routing
  • security zones
  • and network segmentation
  • Data-center
  • cloud
  • and distributed network environments

Summary

Palo Alto Firewall Architect to provide enterprise-wide ownership and technical oversight of a large, mission-critical firewall environment supporting a healthcare customer. This hands-on role will retain internal accountability for architecture, standards, security, risk management, and service performance while providing technical governance of a Managed Service Provider (MSP). The successful candidate will independently drive complex initiatives to completion and perform engineering and troubleshooting, not only high-level architecture and recommendations.

Onsite: 1x a week (wednesdays)

Location: Dallas, TX 75246

Responsibilities:

  • Own the enterprise firewall architecture, standards, lifecycle, and technical roadmap.
  • Provide technical governance and oversight of the MSP performing firewall, virtual private network (VPN), certificate, and key-management operations.
  • Design and implement network segmentation supporting mission-critical services and enterprise security initiatives.
  • Lead complex firewall deployments, migrations, upgrades, data-center initiatives, and new-site integrations.
  • Configure, maintain, and optimize Palo Alto Networks next-generation firewalls (NGFW), Panorama, GlobalProtect, and related security services through the MSP.
  • Oversee the transition from legacy Cisco AnyConnect VPN services to Palo Alto GlobalProtect, including planning, testing, user migration, communications, and decommissioning.
  • Develop, review, and optimize security policies, Network Address Translation (NAT), security zones, objects, routing, and firewall configurations.
  • Establish and maintain standards for firewall, VPN, GlobalProtect, web, device, authentication, encryption, and service certificates.
  • Govern the certificate lifecycle, including discovery, inventory, issuance, installation, renewal, replacement, revocation, expiration monitoring, and decommissioning.
  • Oversee secure generation, storage, protection, rotation, backup, recovery, escrow, and retirement of cryptographic keys.
  • Coordinate certificate and key changes with the MSP, cybersecurity, Identity and Access Management (IAM), application owners, and service owners.
  • Serve as the senior escalation point for complex firewall, VPN, certificate, key-management, and network-security issues.
  • Establish MSP support standards for incident response, change control, service levels, maintenance, documentation, and escalation procedures.
  • Review MSP work for technical quality, security compliance, adherence to standards, and alignment with enterprise architecture.
  • Partner with network, cybersecurity, infrastructure, IAM, application, and technology teams to deliver secure solutions.
  • Maintain accurate architecture diagrams, configuration standards, support procedures, certificate and key inventories, and technical documentation.
  • Provide technical leadership, mentoring, and knowledge transfer to engineering and operations teams.

Qualifications:

  • Extensive experience designing, implementing, and supporting Palo Alto Networks firewalls in an enterprise environment.
  • Strong hands-on experience with Palo Alto NGFW, Panorama, GlobalProtect, firewall policy, NAT, routing, and security zones.
  • Experience with GlobalProtect and Cisco AnyConnect VPN environments, including VPN migration or decommissioning activities.
  • Experience overseeing MSP or managed-services delivery in a complex enterprise environment.
  • Strong knowledge of enterprise certificate management, Public Key Infrastructure (PKI), certificate authorities, certificate chains, Transport Layer Security (TLS), certificate-based authentication, and cryptographic key management.
  • Experience with secure key storage, rotation, access control, backup and recovery, and protection of private keys and sensitive cryptographic material.
  • Experience leading firewall migrations, data-center deployments, segmentation projects, and complex technical initiatives.
  • Strong network-security architecture background across data-center, cloud, and distributed environments.
  • Knowledge of zero-trust principles, secure remote access, and hybrid connectivity.
  • Strong troubleshooting, communication, documentation, and stakeholder-management skills.
  • Ability to work independently, take ownership, and drive initiatives through completion.
  • Palo Alto Networks Certified Network Security Engineer (PCNSE) certification highly preferred.
  • Cisco Certified Internetwork Expert (CCIE) Security, Certified Information Systems Security Professional (CISSP), or comparable senior security certification highly preferred.
  • Experience supporting healthcare, highly regulated, or mission-critical environments preferred.
  • Experience establishing MSP governance, operational standards, service-level expectations, and performance metrics preferred.
  • Experience developing technical standards and mentoring engineering teams preferred.

Tools and Technologies:

  • Palo Alto Networks NGFW
  • Panorama
  • GlobalProtect
  • Cisco AnyConnect
  • VPN technologies
  • PKI and certificate authorities
  • TLS and certificate-based authentication
  • Cryptographic key-management platforms and processes
  • NAT, routing, security zones, and network segmentation
  • Data-center, cloud, and distributed network environments
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91097117
  • Position Id: 5450
  • Posted 7 hours ago

Company Info

About Cloud Destinations LLC

One of the leading US-based staffing and IT consulting partner. Experience exceptional service and top-tier talent across industries. Count on us for staffing solutions that cater to the unique demands of the American market.

Our experienced recruiters ensure a seamless fit within your team, accelerating success. But we go beyond staffing and empower employees with fully sponsored certification programs, keeping them ahead. Experience comprehensive benefits including health, wellness coverage, dental insurance, vision insurance, as well as flexible hours, remote work options, and a robust 401K plan to ensure a secure future at the companies we represent.

At Cloud Destinations, we bring industry expertise and a passion for excellence. From Enterprise Cloud Strategy to Managed Infrastructure Services, Digital Transformation, BI & Data Analytics, Security, Data Engineering, and more, we navigate the IT landscape with finesse. Choose us as your trusted partner, witness transformative talent and exceptional service. Let's unlock new possibilities and drive your success in the dynamic world of IT together.

About_Company_One
Contact the job poster
AU

Akash Unnikrishnan

Recruiter @ Cloud Destinations LLC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs