Palo Alto SME

Abile Group, Inc.Springfield, VA

About The Position

Abile Group has an exciting and challenging opportunity for a Palo Alto SME on a contract providing Network and Cybersecurity services supporting an Intelligence Community customer. All the personnel on the team will work together to support transport and cybersecurity information technology (IT) services on multiple networks and security domains, at multiple locations worldwide, inclusive of new facilities and building constructions to support the IC mission. The right candidate will possess the below skills and qualifications and be ready to handle all responsibilities independently and professionally.

Requirements

  • Clearance Required: TS/SCI with ability to obtain a CI Poly.
  • Bachelor’s degree in a related field (e.g., IT, Cybersecurity, Computer Science). Additional years of relevant experience may be considered in lieu of a degree.
  • A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments.
  • Must hold an active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification.
  • Must be DoD 8140.01 and DoD 8570.01-M IAT Level II compliant (e.g., Security+ CE).
  • Must be able to successfully obtain/maintain a CSSP Infrastructure Support certification within 120 days of the start date.
  • Legacy Systems Management: Deep, practical knowledge of legacy Gen 2/Gen 3 hardware (e.g., PA-3000, PA-5000 series), including legacy CLI, physical hardware troubleshooting, and line-card replacements.
  • Next-Gen & Cloud Security: Direct experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and virtual firewalls (VM-Series) in public/private cloud environments (AWS, Azure, or GCP).
  • Centralized Administration: Proven expertise utilizing Panorama for centralized policy management, template/device group inheritance, and pushing configurations across a hybrid fleet.
  • Network Foundations: Advanced understanding of core networking protocols critical to firewall routing and legacy-to-modern transitions, specifically BGP, OSPF, IPSec VPNs, and NAT.

Nice To Haves

  • Advanced Certifications: Active Palo Alto Networks Certified Network Security Consultant (PCNSC) or Prisma Certified SASE Professional (PCSAE).
  • Automation & Scripting: Proficiency in Python and experience automating firewall deployment, policy changes, and configuration backups using Ansible, Terraform, or Palo Alto XML/REST APIs.
  • Security Orchestration: Hands-on experience with Cortex XDR or Cortex XSOAR for automated threat response.
  • Migration Tools: Proficiency using Palo Alto Networks Expedition to migrate and consolidate legacy rules to modern App-ID-based policies.
  • Enterprise Architecture: Background in designing Zero Trust Network Access (ZTNA) architectures across complex, segment-isolated enterprise environments.
  • Broader Experience: Experience with other security platforms and technologies such as F5 (APM, AFM), Juniper SRX, and Cisco FTD/ASA.

Responsibilities

  • Leads the design, analysis, testing, and implementation of state-of-the-art secure network architectures centered on the Palo Alto Networks ecosystem.
  • Serves as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment.
  • Manages the full lifecycle of Palo Alto hardware and software, including executing complex hardware refreshes and PAN-OS upgrades, especially on legacy platforms.
  • Develops, oversees, and maintains configuration management processes and Standard Operating Procedures (SOPs) for all Palo Alto security platforms.
  • Utilizes Panorama for centralized policy management, ensuring consistent and efficient configuration across a diverse fleet of physical and virtual firewalls.
  • Configures and maintains master-level security profiles, including App-ID, User-ID, Content-ID, SSL Decryption, and WildFire threat prevention.
  • Oversees the reporting, documentation, and investigation of security-related incidents, and leads the development of corrective measures.
  • Acts as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network security status, policies, and procedures.
  • Evaluates and reports on new and emerging network security technologies to enhance the capabilities, performance, and reliability of the network.
  • Provides mentorship and technical oversight to junior engineers, and acts as an escalation point for complex troubleshooting efforts.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service