Cybersecurity Systems Engineering Analyst
Job Description
Vertage is seeking a Cybersecurity Systems Engineering Analyst to support a 24x7 CSOC environment by engineering and improving Secure Access Service Edge and legacy Inspection Zone capabilities.
Responsibilities
- Participate in implementation, support, and lifecycle management of Palo Alto Networks Secure Access Service Edge (SASE) solutions in a large-scale enterprise environment, including Prisma Access, Global Protect, and Strata Cloud Manager
- Maintain integration between SASE platforms and Inspection Zone technologies (including F5 BIG-IP and SWG/Proxy)
- Design, deploy, and continuously optimize cloud-delivered security controls aligned to Palo Alto SASE architecture, including SWG, CASB, ZTNA, and threat prevention
- Provide advanced engineering support for SASE and Inspection Zone security platforms in partnership with Security Operations, Network Engineering, and Incident Response
- Drive security monitoring, telemetry integration, and policy enforcement across SASE and on-prem inspection environments to support consistent visibility and threat detection
- Perform system hardening, high availability design, and resilience engineering for SASE and Inspection Zone environments, including failover strategy and service continuity planning
- Apply understanding of the global threat landscape using Palo Alto threat intelligence and best practices to proactively reduce enterprise risk exposure
- Improve detection and response capabilities by leveraging SASE telemetry to enhance incident analysis, threat hunting, and mitigation effectiveness
- Develop and report operational and security metrics (example: policy effectiveness, threat prevention performance, user activity visibility) to support leadership decisions and operational maturity
- Collaborate with cross-functional teams and leadership to align SASE strategy with enterprise security architecture and modernization initiatives (example: legacy proxy replacement) and business objectives
Requirements
- Bachelor of Science or Bachelor of Arts degree, preferably in Cybersecurity, Information Security, Computer Science, Management Information Systems, or a closely related field
- Alternative: 4+ years of Cybersecurity and/or IT experience in military information security and/or system administration roles may substitute for a degree
- If holding a degree: 3+ years of experience in cybersecurity fields or roles focused on cybersecurity or IT functions
- Hands-on experience with Palo Alto Networks SASE (Prisma Access), including Mobile Users, Remote Networks, and Service Connections
- Strong understanding of Security Service Edge (SSE) capabilities, including SWG, CASB, ZTNA, DNS Security, and SaaS security
- Expertise in policy design, traffic steering, and segmentation within cloud-delivered security platforms
- Strong knowledge of network protocols and SASE connectivity design, including BGP, IPSec, routing, and NAT
- Experience integrating SASE with on-prem Inspection Zone and hybrid cloud architecture
- Proficiency with Global Protect and remote access/VPN solutions
Technologies
- Palo Alto Prisma Access
- Global Protect
- Strata Cloud Manager
- Palo Alto Networks Secure Access Service Edge (SASE)
- Palo Alto threat intelligence
- F5 BIG-IP
- SWG/Proxy
- Secure web gateway (SWG), CASB, ZTNA, DNS Security, SaaS security
- IPSec, BGP, Routing, Network Address Translation (NAT)
- Python, scripting, APIs, Terraform
- Remote access/VPN
Nice-to-have / Preferred Skills
- Experience with automation and scalability (APIs, scripting, infrastructure-as-code such as Python or Terraform)
- Strong background in high availability design, system hardening, and performance optimization
- Experience leading or supporting migration from legacy proxy or multi-vendor environments to SASE platforms
- Strong understanding of cybersecurity frameworks and best practices (NIST, CIS, Zero Trust)
- Proven ability to collaborate cross-functionally, communicate risk effectively, and provide leadership-ready updates
- Multiple industry-standard certifications such as SANS GIAC/GCIA/GCIH/GCFA, CISSP, CISA, CISM, or other network/system security certifications
Employment Details
- Employment type: Temporary to permanent; intent to convert to full-time after approximately 6 months
- Location: United States (onsite), Charlotte (no relocation provided)
- Travel: 5%-10%
- Compensation: USD 50 - 55 per hour
- Minimum experience: 3 years
- Language: English (professional working proficiency)
Similar Jobs
S