Responsibilities
- Own full lifecycle management of PAN OS firewalls including policy development, optimization, upgrades, and performance tuning
- Administer and enhance Prisma Access and GlobalProtect VPN infrastructure to ensure secure and reliable remote connectivity
- Lead enterprise browser strategy including policy configuration, URL filtering, and security integration
- Design and implement network security architectures across routing, switching, and segmentation layers
- Support secure deployment of office networks in coordination with facilities and IT teams
- Identify gaps in security posture and lead remediation of risks related to access control and traffic visibility
- Collaborate with identity and access management teams to support Zero Trust initiatives and least privilege access models
- Develop and maintain documentation including runbooks, standards, and operating procedures.
Required Qualifications
- Bachelor degree or equivalent experience with at least 8 years of experience in network engineering or network security
- Expert level experience managing Palo Alto Networks PAN OS firewalls including policy configuration, NAT, application identification, and threat prevention
- Strong experience with Prisma Access or GlobalProtect VPN in enterprise environments
- Experience managing enterprise browser platforms such as Prisma Browser, Island, Talon, or equivalent
- Solid understanding of networking fundamentals including routing protocols such as BGP and OSPF, switching, VLANs, SD WAN concepts, and segmentation
- Experience deploying secure office networks including cabling and access layer design
- Experience with automation or scripting tools such as Python, Ansible, or Terraform
- Experience using AI tools within network engineering or security operations workflows.
Preferred Qualifications
- Experience implementing SSL and TLS decryption at scale including certificate management and traffic exemptions
- Familiarity with identity platforms such as Okta and integration with network access controls
- Experience with Zero Trust Network Access frameworks
- Relevant certifications such as PCNSE or CCNP Security.
