Jobs · Information Technology

Principal Technical Consultant - Network Security

AHEAD · United States · 1 wk ago
RemoteRemoteInformation Technology$210k–$240k/yrFull-time

About the role

AHEAD builds platforms for digital business by weaving together advances in cloud infrastructure, automation and analytics, and software delivery to help enterprises deliver on the promise of digital transformation. As a Principal Technical Consultant, you will serve as the senior technical leader for network security engagements across four core pillars:

  • Next-generation firewall design and deployment (Palo Alto Networks, Cisco Secure Firewall, Fortinet)
  • Cisco ISE-based network access control and identity services
  • Load balancing and application delivery (F5 BIG-IP, including web application firewall and global server load balancing)
  • SASE and Zero Trust architectures (Zscaler, Palo Alto Prisma Access)

You will design, deploy, and troubleshoot highly complex environments spanning multiple networking and security domains. This role owns end-to-end delivery from discovery and architecture through implementation, testing, cutover, and knowledge transfer. You will also mentor engineers, support sales campaigns as a subject matter expert, and build reusable assets and industry content to advance the practice.

Responsibilities

Firewall Design

  • Design and deploy Palo Alto Networks next-generation firewalls running PAN-OS, including App-ID, User-ID, Content-ID enforcement, security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, WildFire), SSL/TLS decryption, and centralized management through Panorama or Strata Cloud Manager.
  • Design and deploy Fortinet FortiGate firewalls running FortiOS, including security profiles, inspection modes, virtual domains (VDOMs), centralized policy management through FortiManager, and logging/reporting through FortiAnalyzer.
  • Design and deploy Cisco Secure Firewall Threat Defense (FTD) managed by on-premises or cloud-delivered Firewall Management Center, including Snort 3 intrusion policies, malware defense, URL filtering, and high-availability pairs.
  • Lead firewall migration programs, including legacy Cisco ASA to FTD conversions and cross-vendor migrations to Palo Alto, Fortinet, or Cisco platforms, owning policy translation, rule base optimization, phased cutover, and rollback planning.
  • Design network segmentation architectures using firewall zones, virtual routers, VDOMs, VRFs, and policy-based routing to enforce least-privilege north-south and east-west traffic controls.
  • Implement firewall high availability designs, including active/standby failover, active/active clustering, multi-context and multi-VDOM deployments, and state synchronization for large enterprise and service provider environments.
  • Deploy cloud-native and virtual firewall solutions, including Palo Alto Cloud NGFW for AWS and Azure, FortiGate virtual appliances across AWS/Azure/GCP, and Cisco Secure Firewall Threat Defense Virtual for hybrid and cloud workloads.
  • Design and deploy site-to-site IPsec VPN and remote access VPN architectures using GlobalProtect, FortiClient, and Cisco Secure Client, including route-based and policy-based tunnel selection and redundant termination.
  • Configure centralized logging, SIEM integration (Splunk, Microsoft Sentinel, syslog), and NetFlow/IPFIX export for traffic analytics, threat correlation, and compliance reporting.
  • Perform firewall rule base optimization, policy cleanup, and compliance auditing to reduce attack surface and align with regulatory frameworks (PCI-DSS, HIPAA, NIST 800-53).
  • Automate firewall provisioning, configuration backup, and policy deployment using infrastructure-as-code tooling (Terraform, Ansible) and vendor APIs (PAN-OS REST/XML, FortiOS REST, Firewall Management Center REST API).

Network Access Control

  • Deploy Cisco Identity Services Engine (ISE) for 802.1X wired/wireless authentication, MAC Authentication Bypass (MAB), and RADIUS/TACACS+ device administration across campus, branch, and data center environments.
  • Design and implement ISE authorization policies, including Security Group Tags (SGTs) with TrustSec, downloadable ACLs (dACLs), dynamic VLAN assignment, and Adaptive Network Control for automated threat response.
  • Configure ISE profiling services, posture assessment, and compliance enforcement to establish endpoint visibility and confirm devices meet security baselines before access is granted.
  • Integrate ISE with Cisco network infrastructure (Catalyst switches, wireless LAN controllers, Secure Firewall) and third-party network access devices for consistent policy enforcement.
  • Deploy ISE guest portals, BYOD onboarding workflows, and certificate-based authentication (EAP-TLS) integrated with internal/external certificate authorities for secure device enrollment.
  • Implement pxGrid integrations to share identity and session context between ISE, Cisco Secure Firewall, SIEM platforms, and third-party security tooling for unified policy enforcement.
  • Design ISE distributed deployments spanning Policy Administration Nodes, Policy Service Nodes, and Monitoring/Troubleshooting Nodes to meet scale, redundancy, and geographic distribution requirements.
  • Extend identity-based segmentation beyond the access layer by propagating SGTs into firewall and fabric policy through SGACLs and SXP, aligning NAC policy with broader segmentation architecture.
  • Lead ISE upgrades and migrations, including legacy ACS to ISE transitions and major version upgrades, and perform advanced troubleshooting using RADIUS live logs, policy trace, packet capture, and debug utilities.
  • Deliver HPE Aruba ClearPass engagements for clients standardized on ClearPass, including policy design, device profiling, and onboarding workflows.

Load Balancing & Application Delivery

  • Design and deploy F5 BIG-IP Local Traffic Manager, including virtual servers, pools, health monitors, persistence profiles, SSL offload/re-encryption, local traffic policies, and iRules for advanced traffic steering and content switching.
  • Implement global server load balancing with F5 BIG-IP DNS, including wide IPs, GSLB pools, topology records, static/dynamic load balancing methods, iQuery synchronization, and DNS TTL strategies tuned to failover requirements.
  • Deploy and tune F5 BIG-IP Advanced WAF, including OWASP Top 10 protection, attack signature tuning, positive/negative security models, Policy Builder learning workflows, behavioral DoS, bot defense, credential stuffing protection, and DataGuard response masking.
  • Implement API security controls, including OpenAPI specification import, schema enforcement, JSON/XML payload validation, and discovery of undocumented endpoints through policy learning.
  • Design BIG-IP high availability using Device Service Clustering, sync-failover device groups, traffic groups, and network failover for active/standby and active/active deployments across data centers and cloud regions.
  • Deploy F5 BIG-IP Access Policy Manager for application access and identity federation, and F5 BIG-IP SSL Orchestrator for policy-based SSL/TLS decryption with dynamic service chaining to next-gen firewalls, IPS, DLP, and sandbox inspection services.
  • Deliver NGINX Plus and NGINX App Protect deployments, including Kubernetes ingress controller integration, WAF policy via APPolicy custom resource definitions, and container-native application protection for microservices architectures.
  • Implement F5 Distributed Cloud services, including Web Application and API Protection, bot defense, multi-cloud application connectivity, and DNS-based global load balancing as a managed service.
  • Architect cloud-native load balancing and application protection using AWS Application/Network Load Balancers with AWS WAF, and Azure Application Gateway/Front Door with Azure WAF, including hybrid patterns spanning on-premises BIG-IP and cloud-native services.
  • Automate application delivery configuration using the F5 Automation Toolchain (AS3, Declarative Onboarding, Telemetry Streaming), iControl REST, and the F5 Terraform provider, integrating declarative application services into CI/CD pipelines.
  • Lead application delivery controller refresh, consolidation, and migration programs, including application discovery, dependency mapping, virtual server translation, and phased cutover with validated rollback.

SASE & Zero Trust

  • Design and implement SASE and Zero Trust architectures covering remote user, branch office, cloud workload, and data center connectivity under a unified security policy framework.
  • Configure and deploy Zscaler Internet Access (Secure Web Gateway, SSL inspection, URL filtering, cloud firewall, sandboxing, inline DLP) and Zscaler Private Access (ZTNA application segments, App Connectors, browser-based access).
  • Deploy Palo Alto Prisma Access (GlobalProtect remote user connectivity, explicit proxy for branch offices, service connections to on-premises infrastructure) managed through Strata Cloud Manager or Panorama, and extend coverage to unmanaged devices with Prisma Access Browser.
  • Design traffic forwarding and steering architectures (GRE tunnels, IPsec tunnels, PAC files, client connectors) with failover behavior and bandwidth planning validated against site topology.
  • Implement identity-based access controls integrating with Okta, Microsoft Entra ID, SAML 2.0, and SCIM provisioning, combined with device posture and trust signals, to enforce conditional access consistently across SASE platforms.
  • Design SASE and SD-WAN convergence strategies across Fortinet Secure SD-WAN, Palo Alto Prisma SD-WAN, and Cisco Catalyst SD-WAN, maintaining policy consistency across direct internet access and backhauled traffic paths.
  • Deploy Cloud Access Security Broker and Data Loss Prevention controls in both inline and API-based modes to protect sanctioned/unsanctioned application usage.
  • Design east-west segmentation to complement SASE north-south controls, using firewall zones/VRFs, ISE TrustSec SGTs, and data center fabric segmentation (Cisco ACI contracts, VMware NSX distributed firewall policy).
  • Develop and maintain Zero Trust maturity roadmaps for clients, mapping current-state gaps to phased adoption plans across identity, device, network, application, and data pillars.

Architecture, Delivery & Documentation

  • Lead client-facing discovery sessions, design workshops, and architecture reviews to define firewall, network access control, application delivery, and SASE strategies aligned to business objectives and compliance requirements.
  • Own the creation of High-Level Design and Low-Level Design documents, network diagrams, policy matrices, implementation runbooks, and as-built documentation across all technology domains.
  • Develop migration plans, test cases, and operational handoff procedures to ensure smooth transition to production and sustained operational readiness.

Similar jobs