Senior Network Security Engineer
Milestone Technologies, Inc. · Torrance, CA · 1 wk ago
Information Technology$65–$75/hrContract
ON-SITE - Torrance, California. 3 - 6 month W2 contract (no C2C or 3rd parties). Free parking.
Pay
$65 - $75/hr.
Must Haves
- 5+ years’ experience in network engineering and network security
- Proven hands-on experience with Palo Alto Networks firewalls (policy creation, NAT, routing, troubleshooting)
- Experience configuring and supporting GlobalProtect VPN
- Experience building site-to-site VPN tunnels with Azure and AWS
- Working knowledge of 802.1X authentication (wired/wireless) and certificate-based network access
- Experience with Ruckus switch configuration and routing
What Success Looks Like
- Firewall policies and routing are well-organized, documented, and optimized for security and performance
- GlobalProtect VPN provides reliable, secure remote access for all authorized users
- Site-to-site tunnels to Azure and AWS are stable and properly monitored
- Certificate-based authentication (EZPKI/EZRadius) is integrated smoothly with minimal access disruptions
- IoT devices and cameras are securely onboarded via 802.1X/TLS with minimal friction
- Ruckus switch routing is stable and correctly segmented across the network
Responsibilities
- Firewall & Network Security
- Configure and manage Palo Alto Networks firewall security policies, NAT rules, and threat prevention profiles
- Design and implement Palo Alto Firewall routing (static, dynamic, and policy-based routing)
- Monitor, troubleshoot, and optimize firewall performance and rule sets
- VPN & Cloud Connectivity
- Build, configure, and maintain GlobalProtect VPN for secure remote access
- Create and manage site-to-site VPN tunnels between on-premises infrastructure and Azure and AWS environments
- Troubleshoot VPN connectivity, tunnel stability, and routing issues across hybrid cloud environments
- Identity, Certificates & Access Control
- Integrate and manage EZPKI and EZRadius (Azure-based SaaS RADIUS and SaaS TLS/PKI services) for certificate-based network authentication
- Deploy and support TLS-based 802.1X authentication for IP cameras and other IoT devices
- Configure 802.1X network access control policies across wired and wireless infrastructure
- Switching & LAN Infrastructure
- Configure and maintain routing on Ruckus switches
- Support VLAN segmentation, inter-VLAN routing, and network access policies for IoT and camera device segments
- Cross-Functional / Nice-to-Have
- Support Prisma (Prisma Access / Prisma Cloud) initiatives as needed
- Support Palo Alto CASB deployment and policy configuration as needed
Requirements
- 5+ years’ experience in network engineering and network security
- Proven hands-on experience with Palo Alto Networks firewalls (policy creation, NAT, routing, troubleshooting)
- Experience configuring and supporting GlobalProtect VPN
- Experience building site-to-site VPN tunnels with Azure and AWS
- Working knowledge of 802.1X authentication (wired/wireless) and certificate-based network access
- Experience with Ruckus switch configuration and routing
- Strong understanding of enterprise routing concepts (static routing, VLANs, inter-VLAN routing)
- Solid troubleshooting skills across firewall, VPN, and switching layers
- Performed root-cause analysis on wireless access point failures, adjusted AP placement and power/range settings to optimize coverage, and resolved intermittent Wi-Fi connectivity issues
- Skilled in wireless access point diagnostics, RF coverage tuning, and troubleshooting client connectivity and signal degradation issues
Preferred Qualifications
- Experience with Prisma Access and/or Prisma Cloud
- Experience with Palo Alto CASB
- Experience with EZPKI / EZRadius or similar Azure-based SaaS RADIUS/PKI/TLS certificate services
- Experience deploying TLS/802.1X authentication for IoT devices and IP cameras
- Relevant certifications such as PCNSE (Palo Alto Certified Network Security Engineer), CCNP/CCNP Security, or similar
- Light automation such as Ansible, Terraform, SaltStack