Senior Network Security Engineer
Job Description
GovCIO LLC is seeking a Senior Network & Security Engineer to lead enterprise network security infrastructure design, operations, troubleshooting, and continuous improvement.
Responsibilities
- Design, deploy, administer, and manage the lifecycle of Palo Alto Networks NGFW environments running PAN-OS.
- Own centralized firewall management with Palo Alto Panorama including device groups, templates, template stacks, policy inheritance, upgrades, configuration backups, log monitoring, and firewall onboarding.
- Design and govern security policies using zero-trust, least-privilege, application-aware, and risk-based principles.
- Configure and troubleshoot security zones, NAT, virtual routers, static and dynamic routing, IPsec VPN, GlobalProtect, decryption, URL Filtering, Threat Prevention, WildFire, DNS Security, and App-ID policies.
- Lead enterprise network segmentation and microsegmentation using security zones, VLANs, subinterfaces, virtual routers, routing controls, and application-based security policies.
- Develop secure controls for traffic across users, servers, applications, management networks, guest networks, IoT/OT devices, data-center workloads, and cloud resources.
- Architect, configure, test, and troubleshoot Palo Alto High Availability deployments including Active/Passive and Active/Active designs.
- Resolve complex HA failures across HA1 control links, HA2 session and state synchronization, HA3 packet forwarding, peer communications, configuration synchronization, monitoring failures, split-brain prevention, and failover recovery.
- Plan and execute HA failover testing, PAN-OS upgrades, disaster-recovery exercises, and maintenance procedures while minimizing service impact.
- Troubleshoot HA infrastructure dependencies including cables, transceivers, switch ports, port channels, VLANs, routing, MTU, latency, packet loss, and redundant-path failures.
- Lead configuration support and troubleshooting of Cisco Catalyst and Nexus switching environments.
- Design and support VLANs, trunking, STP/RSTP/MST, EtherChannel/port channels, HSRP/VRRP, Layer 2/Layer 3 switching, ACLs, QoS, switch security, routing, and access-control technologies.
- Diagnose complex connectivity and performance issues using firewall logs, session inspection, packet captures, CLI diagnostics, switch counters, flow data, and network-monitoring platforms.
- Analyze TCP/IP behavior including handshake failures, SYN/SYN-ACK/ACK flows, retransmissions, resets, timeouts, asymmetric routing, MTU/MSS issues, fragmentation, latency, packet loss, and NAT translation problems.
- Verify packet flow end-to-end across firewall policy, App-ID, routing, NAT, decryption, threat prevention, VPN, switching, and server/application layers.
- Monitor firewall management-plane and dataplane health including CPU, memory, session capacity, packet buffers, throughput, logging, and interface performance.
- Integrate NGFWs and Panorama with Strata Logging Service and Cortex XSIAM.
- Ensure reliable firewall log forwarding, cloud logging, log ingestion, data normalization, event availability, retention, and telemetry quality.
- Use Cortex XSIAM and XQL Search to investigate, correlate, and respond to firewall, endpoint, identity, cloud, and third-party security events.
- Partner with SOC teams to tune detections, investigate alerts, develop response procedures, improve visibility, and support incident containment and remediation.
- Lead root-cause analyses for major network or security incidents and deliver corrective and preventive action plans.
- Develop and maintain network diagrams, firewall-policy documentation, HA designs, runbooks, change plans, architecture standards, and operational procedures.
- Mentor junior engineers and provide technical leadership during projects, production incidents, and security reviews.
Requirements
- Bachelor’s degree with 8+ years (or commensurate experience).
- 7+ years progressive experience in network engineering, network security, firewall administration, or security infrastructure operations.
- 5+ years hands-on Palo Alto Networks firewall experience in a production enterprise environment.
- Advanced operational experience with Palo Alto Panorama including multi-device policy management, templates, device groups, upgrades, configuration management, and troubleshooting.
- Strong hands-on experience designing, maintaining, and troubleshooting Palo Alto High Availability environments.
- Advanced understanding of HA1, HA2, HA3, configuration synchronization, session synchronization, failover behavior, link monitoring, path monitoring, peer health, and recovery processes.
- Strong expertise in TCP/IP, IPv4/IPv6, DNS, DHCP, ARP, routing, NAT, VPNs, and packet-level troubleshooting.
- Demonstrated ability to investigate TCP handshakes, resets, retransmissions, MTU/MSS issues, asymmetric routing, connection timeouts, and firewall session behavior.
- Extensive experience with Cisco Catalyst and/or Nexus switching technologies.
- Strong knowledge of enterprise switching and routing including VLANs, trunking, STP/RSTP/MST, EtherChannel, HSRP/VRRP, routing protocols, ACLs, QoS, and switch-security controls.
- Proven experience designing or implementing network segmentation and microsegmentation solutions.
- Working knowledge of Cortex XSIAM, Strata Logging Service, security-event correlation, alert investigation, XQL Search, and firewall log ingestion.
- Ability to lead technical design discussions, independently manage complex workstreams, and communicate risks and recommendations to technical and nontechnical stakeholders.
- Strong documentation, change-management, incident-management, and root-cause-analysis skills.
- Must be able to attain and maintain AOUSC Public Trust.
Technologies
- Palo Alto Networks NGFW, PAN-OS, Palo Alto Panorama
- Cortex XSIAM, Strata Logging Service, Cortex XQL Search, XQL Search
- Cisco Catalyst, Cisco Nexus
- IPsec VPN, GlobalProtect, URL Filtering, Threat Prevention, WildFire, DNS Security, App-ID
- High Availability (Active/Passive and Active/Active)
- TCP/IP, NAT, STP/RSTP/MST, EtherChannel/port channels, HSRP/VRRP, VLANs
Role Location
- Remote within the United States
Compensation
- USD 120,000 - 140,000 per year
Preferred Skills and Education
- Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field (preferred).
- Palo Alto Networks certifications: PCNSA, PCNSE, PCCSE, or equivalent enterprise-level experience.
- Cisco certifications: CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, CCIE Security, or comparable expertise.
- Experience with Palo Alto Prisma Access, Prisma Cloud, Cortex XDR, Cortex XSOAR, or cloud-delivered security services.
- Experience with Cortex XSIAM alert triage, XQL queries, data-source integrations, detection tuning, dashboards, reporting, and response automation.
- Experience with Cisco ISE, Cisco ACI, SD-Access, or enterprise network-access-control solutions.
- Familiarity with Fortinet Security Fabric, FortiGate, FortiManager, and FortiAnalyzer.
- Experience with AWS, Azure, Google Cloud Platform, hybrid-cloud network design, and cloud-security controls.
- Familiarity with SIEM, SOAR, EDR/XDR, vulnerability-management, NDR, network-monitoring, and ticketing platforms.
- Automation skills using Python, Ansible, Terraform, REST APIs, or related infrastructure-as-code and orchestration tools.
- Experience supporting 24x7 environments, participating in an on-call rotation, leading critical incidents, and executing emergency changes.