Network Security Engineer - Palo Alto
About the Role
WEI is a service and solution technology provider that focuses on building quality relationships with clients. Our sales and engineering teams work closely with clients to optimize their environments and work efficiently by using cutting-edge technologies and best practices. Clients benefit from our technical talents, value-added services, demonstration labs, knowledge transfer center, integration/testing labs, proof-of-concept labs, and commitment to quality. From solution design through implementation, our sales and technical team provides unwavering support throughout the project. WEI is your strategic IT partner delivering custom, innovative business technology solutions that drive real business outcomes.
This role is project-focused, working both independently and with a team. The candidate will primarily focus on Palo Alto design and implementation and should be familiar with a broad range of security features. The ideal candidate has a broad skill set within the security space and is flexible enough to learn and implement complementary solutions.
Responsibilities
- Conversion and configuration of firewall security policies (local, SCM, and Panorama managed)
- Design and configuration of layer 3 for NGFW and Prisma Access
- Interfaces, routing (Static, BGP, OSPF), tunnels (GRE, IPSec), and remote access (Client, Clientless, Prisma)
- Design and configuration of security profiles:
- Anti-virus | spyware | DNS Security
- Vulnerability
- Data filtering
- URL Filtering (header insertion, tenant restrictions)
- Troubleshooting of NGFW and Prisma Access infrastructure
- Assessments of NGFW and Prisma Access infrastructure
- Documentation of NGFW and Prisma Access infrastructure
Requirements
- Panorama
- URL filtering
- IPS
- User-ID
- App-ID
- BGP and OSPF routing in PAN-OS
- Inspection of SSL encrypted traffic
- VM-Series / Physical PA400 up to PA7500
- Expedition
- HA clustering
- Experience in large enterprise environments (100+ firewalls)
- Packet capture analysis and troubleshooting
- Thorough understanding of TCP/IP and the OSI model
- PCNSE certification preferred
- Global Protect / Prisma SASE
- Prisma Access / Prisma SD-WAN
- SD-WAN / IPSEC site-to-site
Experience
- Panorama/PAN-OS: 5 years
- Strata Cloud Manager / Prisma Access: 3 years
- BGP and OSPF routing in PAN-OS: 5 years
- Inspection of SSL encrypted traffic: 5 years
- Palo Alto NGFW/Panorama in a large (100+ firewalls) environment: 5 years
- Understanding of TCP/IP and the OSI model: 5 years
Ideally (not required), experience with Palo Alto's cloud-based IoT services for NGFWs and managing NGFWs through Strata Cloud Manager.
Qualifications
Bachelor's degree in a computer-related field.