Principal Security Engineer - PAN and Panorama
Job Description
Lead the strategy, engineering, and modernization of a global firewall program as a hands-on Principal Security Engineer in Charlotte, NC onsite, driving policy governance and operational excellence.
Responsibilities
- Serve as the principal technical lead and SME for the enterprise firewall program.
- Define and deploy global firewall standards, policies, and governance mechanisms.
- Drive enterprise wide firewall policy standardization across regions, business units, and environments.
- Create scalable firewall design patterns to support cloud, data center, and hybrid architectures.
- Continuously improve firewall architecture, security controls, and day to day operations.
- Own the lifecycle of firewall rules, including design, implementation, validation, and ongoing maintenance.
- Develop policy sequencing strategies to optimize performance, manageability, and security effectiveness.
- Conduct rule reviews, policy tuning, cleanup, and recertification tasks.
- Identify and remediate redundant, orphaned, shadowed, and overly permissive firewall rules.
- Apply best practices for change management, policy governance, and compliance requirements.
- Analyze firewall environments to uncover gaps, risks, inefficiencies, and bottlenecks.
- Assess current state and develop strategic roadmaps to modernize firewall operations and architecture.
- Promote advanced security capabilities including application based policies, threat prevention, DNS security, SSL inspection, and zero trust adoption.
- Collaborate with architecture and engineering teams to enhance segmentation and overall security posture.
- Identify and implement automation opportunities to improve operations, policy deployment, compliance reporting, and vulnerability remediation.
- Leverage AI, analytics, and machine learning to streamline security workflows and boost efficiency where applicable.
- Target reductions in manual effort through intelligent automation and infrastructure as code practices.
- Work with vulnerability management to automate risk based remediation and policy recommendations.
- Serve as the senior technical advisor for firewall engineering initiatives and strategic security programs.
- Mentor engineers and provide guidance on firewall and network security best practices.
- Coordinate closely with network engineering, cloud, infrastructure, security operations, and compliance teams.
- Influence enterprise security standards and contribute to long term cybersecurity strategy.
Requirements
- Bachelor's degree in Information Security, Computer Science, Engineering, or equivalent experience.
- 10+ years of experience in network security engineering within large scale enterprise environments.
- 5+ years of advanced experience with Palo Alto Networks Firewalls and Panorama.
- Firewall policy design and implementation experience.
- Security policy optimization and sequencing expertise.
- Network segmentation experience.
- Proficiency with threat prevention technologies.
- Enterprise security architecture background.
- Experience with multi site / global firewall deployments.
- Strong TCP/IP networking knowledge, routing and switching skills.
- Knowledge of network security architectures across hybrid and cloud networking models.
- Experience with Zero Trust security frameworks.
- Proven track record leading enterprise security modernization initiatives.
- Strong analytical, troubleshooting, and communication skills; ability to translate findings into strategic recommendations.
- Certifications: PCNSA, PCNSE, and Palo Alto Cybersecurity Professional certifications.
Technologies
- Palo Alto Networks Firewalls
- Panorama
- Python
- Ansible
- Terraform
- AWS
- Azure
- GCP
- APIs
- SIEM
- SOAR