Cybersecurity Architect
Apolis · Orange, CA · Yesterday
HybridOTHRFull-time
Duties and Responsibilities
- Design, Implement and maintain Palo Alto Network firewalls (NGFW), Panorama Central Management and related security services (Wildfire, Threat Prevention, URL Filtering, Anti-Virus, etc.)
- Develop and enforce high-level security policies, rule sets and zone segmentation to align with Zero Trust principles across the entire network.
- Serve as the top-tier subject matter expert for all Palo-Alto related security engineering, configuration and troubleshooting.
- Architect and optimize secure remote access solutions leveraging solutions such as Palo Alto GlobalProtect or other enterprise VPN technologies ensuring least privilege and MFA requirements are enforced and properly implemented.
- Develop and enforce security policies for corporate and guest wireless networks, ensuring segmentation, use of secure authentication protocols and encryption methodology.
- Design and implement secure DNS architecture utilizing DNSSEC or private DNS Services.
- Lead the design and tuning of the enterprise SIEM.
- Lead the design and tuning of device log integration into enterprise SIEM.
- Develop advanced correlation rules, alerts, dashboards and reporting to identify, prioritize and track security threats and anomalies.
- Develop, maintain and test the Incident Response Plan and playbooks.
- Act as a lead resource during critical security incidents, providing technical expertise to guide the incident response lifecycle (Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned).
- Conduct post-incident reviews to identify architectural gaps and define immediate and long-term security enhancements.
- Ensure all security architectures, policies and operational procedures strictly comply with local, state and federal mandates, specifically the CJIS requirements.
- Create and maintain enterprise-wide security standards, security control baselines, and reference architecture to dictate how technology is securely implemented across the organization.
- Conduct regular security assessments to identify control deficiencies and define remediation strategies.
Required Qualifications
- BS in Cybersecurity or related technical field, 7+ years relevant industry experience,
- or MS in Cybersecurity or related technical field, 5+ years relevant industry experience,
- or PhD in Cybersecurity or related technical field with 4+ years industry experience.
Required Certifications
- Certified Information Systems Security Professional (CISSP)
- Giac Reverse Engineering Malware (GREM)