Staff Network Security Engineer (Information Security)

Palo Alto NetworksSanta Clara, CA
3d

About The Position

The Team Information Security - We’re not your ordinary Information Security team. We’re a diverse group of security professionals who challenge the status quo in order to protect Palo Alto Networks and our customers. Driving innovation on the Information Security team of the fastest-growing high-tech cybersecurity company is a once-in-a-lifetime opportunity. You’ll be joined by the brightest minds in technology, and our global teams are on the front line of defense against cyberattacks. Job Summary As a Staff Network Security Engineer on our Enterprise Security team, you will play a critical role in protecting the infrastructure behind our Enterprise, SaaS, and Public Cloud environments. You will leverage your expertise in networking, firewalls, and cloud platforms to design secure, scalable solutions and drive the automation of security controls. This is an opportunity to provide technical leadership, contribute to strategic planning, and work on complex challenges at scale, making a meaningful impact on the future of cybersecurity.

Requirements

  • 5–8 years of hands-on experience in network and infrastructure security engineering.
  • 2+ years of experience managing enterprise firewall technologies, with strong working knowledge of Palo Alto Networks Next-Generation Firewalls (NGFW).
  • 2+ years of experience securing cloud environments (AWS, GCP, or Azure), including native security controls and multi-cloud connectivity.
  • Experience supporting or operating in public sector or FedRAMP-aligned environments, with familiarity implementing controls aligned to NIST 800-53.
  • Proficiency with scripting and automation using Python or Go, including experience with REST APIs and Infrastructure-as-Code (e.g., Terraform).
  • Strong understanding of IP networking fundamentals, including routing, switching, VPNs, DNS, and hybrid cloud networking design.

Nice To Haves

  • Professional certifications such as CISSP, PCNSE, AWS Security Specialty, or GCP Professional Cloud Security Engineer.
  • Experience securing and integrating Microsoft Active Directory (AD) environments, including Group Policy management and hybrid identity federation.
  • Working knowledge of PKI and certificate lifecycle management.
  • Experience supporting audit and compliance activities for SOC 2 or ISO 27001.

Responsibilities

  • Provide advanced network and cloud security engineering support across on-premises (GCP, AWS) and cloud environments, ensuring secure and compliant infrastructure.
  • Design and implement secure, Zero Trust network architectures, including network segmentation, identity-based access controls, and firewall policy management.
  • Ensure security controls meet FedRAMP and NIST 800-53 requirements by supporting implementation and continuous monitoring activities.
  • Develop and enforce hardened security baselines for infrastructure components like VMs, containers, and firewalls, aligning with CIS Benchmarks and internal policies.
  • Proactively collaborate with cross-functional teams including Network Engineering, Cloud Engineering, and SREs to integrate security controls into infrastructure and deployment workflows.
  • Develop and maintain automation using SOAR and Infrastructure-as-Code (IaC) to streamline security operations and ensure consistent control enforcement.
  • Support incident response efforts for network or cloud security events, including investigation, containment, root cause analysis, and documentation.
  • Prioritize and remediate critical vulnerabilities and data exposure risks in cloud and network environments using a risk-based approach.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service