About The Position

At Palo Alto Networks®, the mission is to protect our digital way of life by solving real-world problems with cutting-edge technology and bold thinking. The company values Disruption, Collaboration, Execution, Integrity, and Inclusion, and integrates AI into its operations. Collaboration is emphasized, with most teams working from the office full time, offering flexibility when needed, to foster real-time problem-solving and stronger relationships. The Information Security team is a diverse group of security professionals dedicated to protecting Palo Alto Networks and its customers, driving innovation in the cybersecurity industry. As a Staff Network Security Engineer on the Enterprise Security team, you will play a critical role in safeguarding the infrastructure across Enterprise, SaaS, and Public Cloud environments. This position requires leveraging expertise in networking, firewalls, and cloud platforms to design secure, scalable solutions and automate security controls. It offers an opportunity to provide technical leadership, contribute to strategic planning, and tackle complex challenges at scale, significantly impacting the future of cybersecurity.

Requirements

  • 5–8 years of hands-on experience in network and infrastructure security engineering.
  • 2+ years of experience managing enterprise firewall technologies, with strong working knowledge of Palo Alto Networks Next-Generation Firewalls (NGFW).
  • 2+ years of experience securing cloud environments (AWS, GCP, or Azure), including native security controls and multi-cloud connectivity.
  • Experience supporting or operating in public sector or FedRAMP-aligned environments, with familiarity implementing controls aligned to NIST 800-53.
  • Proficiency with scripting and automation using Python or Go, including experience with REST APIs and Infrastructure-as-Code (e.g., Terraform).
  • Strong understanding of IP networking fundamentals, including routing, switching, VPNs, DNS, and hybrid cloud networking design.

Nice To Haves

  • Professional certifications such as CISSP, PCNSE, AWS Security Specialty, or GCP Professional Cloud Security Engineer.
  • Experience securing and integrating Microsoft Active Directory (AD) environments, including Group Policy management and hybrid identity federation.
  • Working knowledge of PKI and certificate lifecycle management.
  • Experience supporting audit and compliance activities for SOC 2 or ISO 27001.

Responsibilities

  • Provide advanced network and cloud security engineering support across on-premises (GCP, AWS) and cloud environments, ensuring secure and compliant infrastructure.
  • Design and implement secure, Zero Trust network architectures, including network segmentation, identity-based access controls, and firewall policy management.
  • Ensure security controls meet FedRAMP and NIST 800-53 requirements by supporting implementation and continuous monitoring activities.
  • Develop and enforce hardened security baselines for infrastructure components like VMs, containers, and firewalls, aligning with CIS Benchmarks and internal policies.
  • Proactively collaborate with cross-functional teams including Network Engineering, Cloud Engineering, and SREs to integrate security controls into infrastructure and deployment workflows.
  • Develop and maintain automation using SOAR and Infrastructure-as-Code (IaC) to streamline security operations and ensure consistent control enforcement.
  • Support incident response efforts for network or cloud security events, including investigation, containment, root cause analysis, and documentation.
  • Prioritize and remediate critical vulnerabilities and data exposure risks in cloud and network environments using a risk-based approach.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service