Jobs · Information Technology · California

Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and Transformation

Deloitte · San Francisco, CA · 1 wk ago
HybridInformation Technology$105k–$208k/yrFull-time

About the role

Deloitte's Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative approach. We collaborate with teams from across our organization in order to bring the full breadth of Deloitte, its commercial and public sector expertise, to best support our clients. Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape.

Responsibilities

  • Designing, deploying, and managing Palo Alto Networks Next-Generation Firewalls (NGFW) across on-premises and cloud environments, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP)
  • Implementing and optimizing Prisma Access capabilities, including GlobalProtect, Prisma Agent, and Prisma Browser, to support secure internet access and remote access use cases
  • Administering Panorama and Strata Cloud Manager to support centralized policy management, device configuration, visibility, and operational consistency across enterprise environments
  • Configuring and tuning security capabilities including Threat Prevention, intrusion prevention system/intrusion detection system (IPS/IDS), Anti-Spyware, Antivirus, WildFire, Domain Name System (DNS) Security, and Secure Sockets Layer/Transport Layer Security (SSL/TLS) decryption policies
  • Developing client solution designs and recommendations, integrating Palo Alto platforms with security information and event management/security orchestration, automation, and response (SIEM/SOAR) and identity provider tools, and supporting automation through Terraform, Ansible, or Python

Requirements

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology, or equivalent work experience)
  • PNCSE (Palo Alto Networks Certified Network Security Engineer) certification
  • 5+ years of progressively responsible experience in network security engineering, with demonstrated depth in Palo Alto Networks technologies and increasing levels of technical ownership and leadership over time
  • 3+ years of experience designing, deploying, and managing Palo Alto Networks Next-Generation Firewalls (NGFW) in both on-premises and cloud environments (AWS, Azure, and/or GCP)
  • 3+ years of experience designing, deploying, and managing Prisma Access, including configuration of GlobalProtect, Prisma Agent, and Prisma Browser for Internet and secure remote access use cases
  • 3+ years of experience designing, deploying, and managing Panorama centralized management, and Strata Cloud Manager
  • 3+ years of experience configuring and tuning Palo Alto Threat Prevention features, including IPS/IDS, Anti-Spyware, Antivirus, WildFire, and DNS Security
  • 3+ years of experience implementing and troubleshooting SSL/TLS Decryption policies, including forward proxy and inbound inspection, certificate management, and decryption exclusion handling
  • 3+ years of hands-on experience defining, managing, and reviewing security policies, including rule base optimization, policy lifecycle management, and periodic access reviews
  • 3+ years of experience with one or more major cloud service providers (AWS, GCP, Azure) and their native security toolsets, including deployment of VM-Series firewalls within cloud-native architectures
  • Advanced cybersecurity certifications such as CISSP, CCIE Security, CCNP Security, or GIAC equivalents (e.g., GPEN, GCSA)
  • Experience with automation tooling (e.g., Terraform, Ansible, Python) for provisioning, policy management, and configuration-as-code workflows
  • Experience integrating Palo Alto Firewalls and Prisma with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response workflows
  • Experience designing and presenting Palo Alto network solution architectures (ideally tailored to client requirements, translating technical concepts for executive and non-technical stakeholders)
  • Demonstrated experience working in large, complex enterprise environments with stringent security, compliance, and availability requirements
  • Familiarity with identity provider integrations (e.g., Okta, Azure AD, Ping Identity) for SAML/SCIM-based authentication within Palo Alto Cloud Identity Engine (CIE)
  • Experience conducting SASE vendor competitive analysis and advising clients on solution selection based on specific use cases and requirements (e.g., Zscaler vs. Palo Alto Prisma vs. Netskope)
  • Experience conducting Zero Trust Architecture assessments and developing roadmaps aligning Zscaler capabilities to NIST SP 800-207 or CISA Zero Trust Maturity Model frameworks
  • Previous consulting or "Big 4" experience, with a track record of delivering enterprise network security or SASE transformation engagements

Qualifications

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology, or equivalent work experience)
  • PNCSE (Palo Alto Networks Certified Network Security Engineer) certification
  • 5+ years of progressively responsible experience in network security engineering, with demonstrated depth in Palo Alto Networks technologies and increasing levels of technical ownership and leadership over time
  • 3+ years of experience designing, deploying, and managing Palo Alto Networks Next-Generation Firewalls (NGFW) in both on-premises and cloud environments (AWS, Azure, and/or GCP)
  • 3+ years of experience designing, deploying, and managing Prisma Access, including configuration of GlobalProtect, Prisma Agent, and Prisma Browser for Internet and secure remote access use cases
  • 3+ years of experience designing, deploying, and managing Panorama centralized management, and Strata Cloud Manager
  • 3+ years of experience configuring and tuning Palo Alto Threat Prevention features, including IPS/IDS, Anti-Spyware, Antivirus, WildFire, and DNS Security
  • 3+ years of experience implementing and troubleshooting SSL/TLS Decryption policies, including forward proxy and inbound inspection, certificate management, and decryption exclusion handling
  • 3+ years of hands-on experience defining, managing, and reviewing security policies, including rule base optimization, policy lifecycle management, and periodic access reviews
  • 3+ years of experience with one or more major cloud service providers (AWS, GCP, Azure) and their native security toolsets, including deployment of VM-Series firewalls within cloud-native architectures
  • Advanced cybersecurity certifications such as CISSP, CCIE Security, CCNP Security, or GIAC equivalents (e.g., GPEN, GCSA)
  • Experience with automation tooling (e.g., Terraform, Ansible, Python) for provisioning, policy management, and configuration-as-code workflows
  • Experience integrating Palo Alto Firewalls and Prisma with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response workflows
  • Experience designing and presenting Palo Alto network solution architectures (ideally tailored to client requirements, translating technical concepts for executive and non-technical stakeholders)
  • Demonstrated experience working in large, complex enterprise environments with stringent security, compliance, and availability requirements
  • Familiarity with identity provider integrations (e.g., Okta, Azure AD, Ping Identity) for SAML/SCIM-based authentication within Palo Alto Cloud Identity Engine (CIE)
  • Experience conducting SASE vendor competitive analysis and advising clients on solution selection based on specific use cases and requirements (e.g., Zscaler vs. Palo Alto Prisma vs. Netskope)
  • Experience conducting Zero Trust Architecture assessments and developing roadmaps aligning Zscaler capabilities to NIST SP 800-207 or CISA Zero Trust Maturity Model frameworks
  • Previous consulting or "Big 4" experience, with a track record of delivering enterprise network security or SASE transformation engagements

Pay

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.

Schedule

A reasonable estimate of the current range is $105,400 to $207,800.

Benefits

At Deloitte, we offer a comprehensive benefits package designed to support your total well-being. This includes medical, dental, vision, retirement savings plans, paid time off, and more. For more details, please visit our career site.

Application Instructions

To apply for this role, please visit our career site and submit your application. Limited immigration sponsorship may be available.

Similar jobs