Sr. Security Engineer
Job Description: Network Security Engineer
Position Summary
We are seeking a skilled and motivated Network Security Engineer with 3-5 years of hands-on experience in designing, implementing, and supporting enterprise network security solutions, with a strong focus on Palo Alto Networks firewalls. The ideal candidate will be responsible for managing firewall infrastructure, ensuring network security compliance, troubleshooting security incidents, and supporting security transformation initiatives across the enterprise.
Key Responsibilities
- Deploy, configure, administer, and support Palo Alto Next-Generation Firewalls (NGFW) across enterprise environments.
- Manage firewall policies, NAT configurations, security profiles, URL filtering, IPS/IDS, anti-malware, and SSL decryption.
- Perform firewall rule reviews, optimization, recertification, and policy cleanup activities.
- Troubleshoot network connectivity, security incidents, and firewall-related issues.
- Support implementation and management of GlobalProtect VPN solutions for remote access users.
- Perform network traffic analysis and security event investigation.
- Collaborate with SOC, Infrastructure, Cloud, and Application teams to resolve security-related issues.
- Participate in security assessments, vulnerability remediation, and audit activities.
- Support change management activities and maintain technical documentation.
- Monitor firewall health, performance, capacity utilization, and security alerts.
- Provide operational support for production network security infrastructure while adhering to SLA requirements.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- 3-5 years of experience in Network Security Engineering.
- Hands-on experience with Palo Alto Firewalls, including PA-Series appliances.
- Strong understanding of Layer 2 and Layer 3 networking, TCP/IP, DNS, DHCP, BGP, OSPF, routing, switching, segmentation, and VPN technologies.
- Experience managing security policies, NAT policies, application control, URL filtering, and threat prevention profiles.
- Knowledge of security concepts including Zero Trust, Defense in Depth, and network segmentation.
- Experience with troubleshooting tools such as Wireshark, traceroute, netstat, and packet capture analysis.
Preferred Skills
- Experience with Panorama centralized management.
- Knowledge of cloud security controls in Azure or AWS.
- Experience with Cisco, Fortinet, Check Point, or Zscaler technologies.
- Familiarity with SIEM platforms such as Microsoft Sentinel or Splunk.
- Understanding of vulnerability management and remediation processes.
- Exposure to Infrastructure as Code using Terraform and automation scripting using Python or PowerShell is a plus.