Position : Palo Alto Firewall Specialist
Experience : 6.5 - 10 Years
Location : PAN India
Employment Type : Contract
Support Window : US Business Hours (24x7)
Job Summary :
We are seeking an experienced Network Security Professional with a mandatory 6.5-10 years of strong, hands-on expertise in Palo Alto Networks Firewalls to manage and secure enterprise-level network environments.
This contract role requires proficiency in the design, implementation, and management of both physical and virtual Palo Alto devices, coupled with experience in Cisco Firewalls and F5 Load Balancers. The specialist will be crucial for firewall migrations, security policy fine-tuning, integration with Panorama, and providing 24x7 support during US business hours.
Job Description :
Palo Alto Firewall Deployment and Management :
- Design, implement, configure, and manage high-availability clusters of Palo Alto Networks Firewalls (both hardware and virtualized forms, e.g., VM-Series) at an enterprise scale.
- Perform all aspects of firewall administration, including mandatory operating system patching, maintenance, and major version upgrades with minimal service disruption.
- Execute complex firewall migration or upgrade projects, successfully transitioning from legacy firewalls (e.g., Cisco ASA) to Palo Alto platforms while ensuring seamless policy translation and rule optimization.
- Mandatorily manage and configure centralized policy and device management using Palo Alto Panorama, ensuring consistent security posture across the entire firewall fleet.
- Proactively conduct regular device hardening and performance monitoring on all Palo Alto assets, aligning configurations with industry benchmarks and specific customer security policies.
Network Security Architecture and Protocols :
Apply a deep, technical understanding of foundational network security concepts, including effective deployment strategies for DMZ architectures and configuring stateful inspection policies.Implement and manage various tunneling mechanisms, including configuring robust site-to-site VPNs (IPSec, IKEv2) and supporting remote access solutions via GlobalProtect.Manage and implement network segmentation strategies, defining granular firewall zones, configuring intricate NATing rules (Source / Destination NAT), and managing IP addressing using routing protocols and subnetting.Configure and fine-tune critical Next-Generation Firewall (NGFW) features, including IPS / IDS, URL Filtering / Web Filtering, and application control to enforce zero-trust network principles.Load Balancing and Operations :
Manage, configure, and troubleshoot F5 Load Balancers (LTM / GTM) and their integration points with the firewall security stack to ensure efficient traffic distribution and high application availability.Execute ongoing firewall rule fine-tuning based on traffic analysis, reducing the attack surface, and rapidly implementing emergency rule applications as dictated by immediate security threats or compliance mandates.Participate in a 24x7 support rotation covering US Business Hours, demonstrating a responsive and proactive approach to incident response and security operations.Required Skills & Qualifications :
Experience : Mandatory 6.5 - 10 years of hands-on experience in Network Security Engineering, with specific expertise in Palo Alto Firewalls.Firewall Expertise : Mandatory strong experience in the configuration, management, and troubleshooting of Palo Alto Networks Firewalls (both hardware and virtual) and exposure to Cisco Firewalls.Key Technologies : Proficiency in managing and configuring F5 Load Balancers and mandatory experience integrating Palo Alto Firewalls with Panorama.Security Concepts : Deep understanding of network segmentation, NATing, routing, VPNs (Site-to-Site & GlobalProtect), Web Filtering, and IPS / IDS.Support : Ability to provide technical support on a 24x7 rotation model covering US Business Hours.Core Skills : Excellent technical communication and complex problem-solving skills.Preferred Skills :
Certification : Current or demonstrable history of achieving Palo Alto Network Certification (PCNSE or PCNSA).Scripting : Experience with automation and scripting (e.g., Python, Ansible) for firewall rule base analysis, policy deployment, or configuration management.Cloud Security : Experience with cloud firewall deployments and native cloud security services (e.g., AWS Security Hub, Azure Firewall).Self-Reliance : Proven track record of being self-driven and demonstrating a proactive approach to security maintenance and project delivery.Endpoint Security : Exposure to Palo Alto's broader security ecosystem, such as Cortex XDR or related cloud security products.(ref : hirist.tech)