- Company Name
- Booker DiMaio
- Job Title
- Palo Alto Network Security Engineer - Hybrid Role in Baltimore, MD
- Job Description
-
**Job Title**
Senior Palo Alto Network Security Engineer – Hybrid
**Role Summary**
Senior engineer responsible for design, configuration, administration, optimization, and lifecycle management of Palo Alto Networks firewalls across a statewide, mission‑critical enterprise network. Ensures security policy compliance, high‑availability operation, log integration with SIEMs, and supports incident response and change‑management processes.
**Expectations**
- US citizen or Green Card holder; able to interview in person.
- 5‑7 years of enterprise firewall engineering experience.
- 3+ years hands‑on with Palo Alto firewalls in multi‑site environments.
- Ability to work within structured, SLA‑driven, 24 × 7 NOC/SOC environments.
- Strong documentation and communication skills for cross‑agency coordination.
**Key Responsibilities**
- Configure, administer, and maintain Palo Alto firewalls at enterprise scale.
- Manage and optimize security policies (App‑ID, User‑ID, NAT, Zone Protection, Threat Prevention).
- Implement firewall rule changes per change‑management procedures.
- Troubleshoot connectivity, routing, and policy issues.
- Operate Panorama for centralized device‑group, template, and baseline management.
- Ensure policy synchronization and HA (active/passive) validation.
- Monitor firewall logs, integrate with SIEM platforms, and support audit/compliance reporting.
- Perform PAN‑OS upgrades, firmware patching, and vulnerability remediation.
- Participate in incident investigations, root‑cause analysis, and escalation coordination with NOC and Security Operations.
- Contribute to Change Advisory Board (CAB) processes, impact assessments, and documentation maintenance.
- Support transition‑in activities and stakeholder coordination.
**Required Skills**
- Palo Alto Networks firewall configuration, Panorama management, HA design.
- Security policy engineering, rule optimization, NAT and routing integration.
- Threat Prevention, URL filtering, and firmware lifecycle management.
- Network fundamentals: TCP/IP, BGP, OSPF, VLANs, segmentation, security zoning.
- SIEM integration experience (e.g., Splunk, QRadar).
- Strong written and verbal communication; detailed documentation.
- Ability to operate in structured change‑management and SLA‑driven environments.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, Engineering, or related field (or equivalent experience).
- PCNSE (Palo Alto Certified Network Security Engineer) – strongly preferred.
- PCNSA (Palo Alto Certified Network Security Administrator) – preferred.