Network Security Administrator – Palo Alto & Cisco ASA
Location: Remote within Colorado
Candidate Location Requirement: Candidates must currently reside in Colorado
Employment Type: Contract
Number of Openings: 1
Expected Start Date: September 1, 2026
Expected End Date: June 30, 2027
Schedule: Monday–Friday, 8:00 AM–5:00 PM MST
Hours: 40 hours per week
On-Call: Required – weekly rotation
After-Hours Work: Required for scheduled maintenance and emergency response as needed
Expenses: Not reimbursable
Submission Deadline: August 12, 202
Position Overview
We are seeking a Network Security Administrator / Cyber Security Administrator to provide specialized network and cybersecurity administration support across a large public-sector technology environment.
This role focuses on maintaining secure, compliant, and modern network infrastructure through day-to-day firewall administration, security-request processing, incident resolution, hardware lifecycle management, infrastructure modernization, and regulatory compliance activities.
The selected consultant will work extensively with Palo Alto and Cisco ASA firewalls and will be responsible for reviewing and implementing firewall changes, troubleshooting network-security issues, supporting end-of-life hardware replacement, and maintaining configurations that align with applicable security and regulatory requirements.
This position is remote; however, candidates must reside in Colorado.
Key Responsibilities
Firewall Administration & Security Operations
- Review and execute Firewall Service Requests (FSRs).
- Process firewall configuration and security-rule changes.
- Review and implement formal change requests.
- Troubleshoot and resolve break-fix incidents and network-security tickets.
- Maintain firewall rules, policies, objects, and configurations.
- Investigate firewall and network-security connectivity issues.
- Support day-to-day network-security administration across multiple environments.
Palo Alto Firewall Administration
- Configure and administer Palo Alto next-generation firewalls.
- Configure and maintain security zones.
- Create, modify, and troubleshoot security policies.
- Configure and support Site-to-Site VPN connections.
- Configure and troubleshoot NAT policies.
- Support basic threat-prevention functionality.
- Troubleshoot firewall connectivity and policy issues.
- Maintain secure firewall configurations according to established standards.
Cisco ASA Administration
- Configure and administer Cisco ASA firewalls.
- Create and modify firewall rules.
- Troubleshoot Cisco ASA configuration and connectivity issues.
- Support firewall policy management.
- Perform ongoing firewall maintenance and configuration changes.
Network Security Support
- Apply foundational networking concepts when troubleshooting security and connectivity problems.
- Troubleshoot network routing and firewall-related issues.
- Work with IP addressing and subnetting.
- Apply knowledge of the OSI model during troubleshooting.
- Support network infrastructure and security teams with issue resolution.
- Analyze network-security problems and recommend corrective actions.
Infrastructure Modernization
- Support recurring replacement and refresh of End-of-Life network and security hardware.
- Assist with decommissioning outdated firewall and network-security infrastructure.
- Configure replacement hardware.
- Support migration from legacy infrastructure to updated technology.
- Validate configurations and connectivity following hardware replacements.
- Assist with planned infrastructure-maintenance activities.
Security & Regulatory Compliance
- Implement security controls and configurations required to maintain compliance.
- Support environments governed by requirements associated with:
- IRS
- FBI
- Criminal Justice Information-related standards
- Review security configurations for alignment with established compliance requirements.
- Support remediation of identified configuration or compliance issues.
- Maintain secure network configurations across supported environments.
Incident & Change Management
- Respond to assigned break-fix tickets.
- Troubleshoot network and firewall incidents.
- Participate in formal change-management processes.
- Implement approved firewall and infrastructure changes.
- Document changes and technical resolutions.
- Coordinate with infrastructure, cybersecurity, and agency technical teams as required.
On-Call & After-Hours Support
- Participate in a weekly on-call rotation.
- Respond to after-hours incidents when assigned.
- Participate in scheduled maintenance windows outside normal business hours.
- Provide emergency-response support when required.
- Maintain availability comparable to a full-time technical team member during assigned rotations.
Required Technical Qualifications
Candidates should demonstrate working knowledge and hands-on experience with the following:
Palo Alto Firewalls
- Palo Alto Networks firewalls
- Security zones
- Security policies
- Site-to-Site VPN
- NAT/NATing
- Firewall rule management
- Basic threat prevention
- Firewall troubleshooting
Cisco ASA
- Cisco ASA firewall configuration
- Cisco ASA troubleshooting
- Firewall-rule administration
- Security-policy management
Networking Fundamentals
- TCP/IP networking
- Routing concepts
- Subnetting
- IP addressing
- OSI model
- Network troubleshooting
- Firewall and network connectivity analysis
Required Operational Experience
The ideal candidate should be comfortable with:
- Firewall Service Requests
- Firewall change requests
- Break-fix support
- Incident troubleshooting
- Change-management processes
- Firewall policy administration
- Network-security hardware management
- End-of-Life hardware replacement
- Infrastructure refresh projects
- Security compliance
- On-call production support
- After-hours maintenance
Compliance & Background Requirements
Candidates must be able to successfully complete required screening, including:
- Criminal background check
- Financial background check
- Drug screening
Ideal Candidate Profile
The ideal candidate is a hands-on Network Security Administrator or Firewall Administrator with practical experience supporting enterprise Palo Alto and Cisco ASA environments.
The strongest candidate will demonstrate:
- Hands-on Palo Alto firewall administration.
- Cisco ASA configuration and troubleshooting experience.
- Experience managing firewall rules, security policies, zones, NAT, and Site-to-Site VPNs.
- Strong network troubleshooting fundamentals.
- Experience handling firewall service requests and formal production changes.
- Experience supporting break-fix incidents in an enterprise environment.
- Experience replacing or refreshing end-of-life network-security hardware.
- Experience working in security-conscious or regulated environments.
- Familiarity with IRS, FBI, CJI, or similar security-compliance requirements.
- Experience participating in on-call rotations and after-hours maintenance.
- Ability to work independently in a remote environment while coordinating with multiple technical teams.
Core Technical Skills
- Palo Alto Firewalls
- Cisco ASA
- Firewall Administration
- Network Security
- Security Policies
- Firewall Rules
- Site-to-Site VPN
- NAT
- Threat Prevention
- TCP/IP
- Routing
- Subnetting
- OSI Model
- Network Troubleshooting
- Incident Management
- Change Management
- Hardware Lifecycle Management
- Security Compliance
Work Arrangement
This position is remote, but candidates must reside in Colorado.
The normal work schedule is Monday through Friday, 8:00 AM–5:00 PM MST. The consultant must also participate in a weekly on-call rotation and be available for scheduled after-hours maintenance or emergency-response situations when required.