Role: Cloud Firewall Architect
Location: Downey, CA (Hybrid)
Duration: 12 months + Potential to extend / convert
Position Description
Skills Required
- Advanced knowledge and proficiency with Palo Alto Networks security platforms.
- Advanced knowledge of Next-Generation Firewall (NGFW) technologies and security concepts.
- Advanced knowledge of cloud network security technologies and architectures across Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI).
- Advanced knowledge of enterprise firewall technologies and migration concepts associated with legacy platforms.
- Advanced knowledge of firewall security policy principles, access control, rule optimization, network segmentation, and security best practices.
- Advanced knowledge of routing and switching technologies.
- Strong knowledge of network services and security technologies.
- Strong knowledge of network security monitoring and threat analysis.
- Strong knowledge of high-availability and fault-tolerant network security concepts.
- Strong knowledge of firewall software and security content management.
- Working knowledge of private network interconnection technologies.
- Strong knowledge of network security automation and Infrastructure as Code (IaC) concepts.
Experience Required
- At least five (5) years of experience with Palo Alto Networks physical firewall appliances, VM-Series, Panorama, Device Groups, Templates, Template Stacks, and Strata Cloud Manager (SCM), or comparable.
- At least five (5) years of experience with Next-Generation Firewall (NGFW) technologies, Intrusion Prevention Systems (IPS), Application Identification (App-ID), User Identification (User-ID), URL and content filtering, and Secure Sockets Layer/Transport Layer Security (SSL/TLS) inspection, or comparable.
- At least three (3) years of experience with cloud network security technologies in Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI), including third-party and native cloud security controls, or comparable.
- At least five (5) years of experience with cloud traffic inspection architectures involving AWS Gateway Load Balancer (GWLB), AWS Transit Gateway (TGW), security Virtual Private Clouds (VPCs), Azure hub-and-spoke architectures, Network Virtual Appliances (NVAs), and User-Defined Routing (UDR), or comparable.
- At least four (4) years of experience in deploying and operating cloud-based firewalls, network virtual appliances, and native security controls in one or more of AWS, Azure, GCP, or OCI.
- At least five (5) years of experience in implementing and operating hybrid connectivity with dynamic routing (BGP), including AWS Transit Gateway, Azure ExpressRoute, or equivalent private interconnects.
Education Required
- Palo Alto Networks Certified Network Security Engineer (PCNSE) certification required.
Additional Information
Submitted candidates are expected to require minimal acclimation to the role.