Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and Transformation
Job Description
Join Deloitte’s Cyber Enterprise Security team in Costa Mesa as a Senior Consultant dedicated to modernizing network protection with Palo Alto Networks across on-premises and cloud environments. You will design, deploy, and operate NGFWs, Prisma Access, and SIEM/SOAR integrations to advance secure digital transformation for our clients.
Location
Costa Mesa, California (onsite)
Compensation
USD 105,400 - 207,800 per year
Experience
Minimum 3 years of progressively responsible experience in network security engineering, with demonstrated depth in Palo Alto Networks technologies and increasing technical ownership and leadership.
Education
BA/BS degree in a technical field
Responsibilities
- Architect, deploy, and manage Palo Alto Networks Next-Generation Firewalls across on‑premises and cloud environments (AWS, Azure, GCP).
- Implement and optimize Prisma Access capabilities, including GlobalProtect, Prisma Agent, and Prisma Browser for secure internet and remote access use cases.
- Administer Panorama and Strata Cloud Manager to enable centralized policy management, consistent configuration, and visibility across enterprise environments.
- Configure and tune security features such as Threat Prevention, IPS/IDS, Anti-Spyware, Antivirus, WildFire, DNS Security, and SSL/TLS decryption policies.
- Develop client solution designs and recommendations, integrating Palo Alto platforms with SIEM/SOAR and identity provider tools, and support automation via Terraform, Ansible, or Python.
Requirements
- BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology, or equivalent work experience).
- PCNSE certification.
- 5+ years of progressively responsible experience in network security engineering with demonstrated depth in Palo Alto Networks technologies and increasing technical ownership and leadership.
- 5+ years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs in both on‑premises and cloud environments (AWS, Azure, and/or GCP).
- 3+ years of experience designing, deploying, and managing Prisma Access, including GlobalProtect, Prisma Agent, and Prisma Browser.
- 3+ years of experience designing, deploying, and managing Panorama centralized management and Strata Cloud Manager.
- 3+ years configuring and tuning Threat Prevention features (IPS/IDS, Anti-Spyware, Antivirus, WildFire, DNS Security) and SSL/TLS decryption policies.
- 3+ years defining, managing, and reviewing security policies, including rule base optimization and policy lifecycle management.
- 3+ years with one or more cloud providers (AWS, GCP, Azure) and their native security toolsets, including VM-Series deployments.
- Ability to travel up to 50% on average.
- Limited immigration sponsorship may be available.
Technologies
- Palo Alto Networks NGFW, VM-Series
- AWS, Microsoft Azure, Google Cloud Platform (GCP)
- Prisma Access, GlobalProtect, Prisma Agent, Prisma Browser
- Panorama, Strata Cloud Manager
- Threat Prevention, IPS, IDS, Anti-Spyware, Antivirus, WildFire, DNS Security
- SSL/TLS decryption, forward proxy, inbound inspection
- Terraform, Ansible, Python
- SIEM, SOAR
- Zscaler, Netskope, Okta, Azure AD, Ping Identity
- Palo Alto Cloud Identity Engine (CIE), SAML, SCIM
Benefits
- Discretionary annual incentive program
The Team
Our Enterprise Security practice integrates security across all dimensions of digital transformation, securing the client’s technical backbone while enabling secure innovation. The team spans security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected devices.