Network Security Engineer Master
GovCIO - United States
Hiring: Network Security Engineer Master Company: GovCIO Location: United States Job Posted Time: 2026-09-17 07:32:21 Employment Type: Remote Target Skills & Keywords : AWS, Ansible, Azure, Configuration Management, DNS, GCP, Prisma Cloud, Python, REST, SIEM, SOC, TCP/IP, Terraform, VPN About the job Experience: •Operational familiarity with Fortinet Security Fabric, FortiGate, FortiManager, and FortiAnalyzer. •Operational familiarity with SIEM, SOAR, EDR/XDR, vulnerability-management, NDR, network-monitoring, and ticketing platforms. •Automation skills using Python, Ansible, Terraform, REST APIs, or related infrastructure-as-code and orchestration tools. Required Skills: •Lead the design, deployment, administration, and lifecycle management of Palo Alto Networks NGFW environments running PAN-OS. •Own centralized firewall management through Palo Alto Panorama, including device groups, templates, template stacks, policy inheritance, upgrades, configuration backups, log monitoring, and firewall onboarding. •Design and govern security policies using zero-trust, least-privilege, application-aware, and risk-based principles. •Configure and troubleshoot security zones, NAT, virtual routers, static and dynamic routing, IPsec VPN, GlobalProtect, decryption, URL Filtering, Threat Prevention, WildFire, DNS Security, and App-ID policies. •Lead enterprise network-segmentation and microsegmentation initiatives using security zones, VLANs, subinterfaces, virtual routers, routing controls, and application-based security policies. •Develop secure controls for traffic between users, servers, applications, management networks, guest networks, IoT/OT devices, data-center workloads, and cloud resources. •Architect, configure, test, and troubleshoot Palo Alto High Availability deployments, including Active/Passive and Active/Active designs as required. •Resolve complex HA failures involving HA1 control links, HA2 session/state synchronization, HA3 packet forwarding, peer communications, configuration synchronization, monitoring failures, split-brain prevention, and failover recovery. Qualifications: •Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field (three additional years if Bachelor’s degree); equivalent relevant experience may be considered. •10+ years of progressive experience in network engineering, network security, firewall administration, or security infrastructure operations. •6+ years of hands-on Palo Alto Networks firewall experience in a production enterprise environment. •Advanced operational experience with Palo Alto Panorama, including multi-device policy management, templates, device groups, upgrades, configuration management, and troubleshooting. •Strong hands-on experience designing, maintaining, and troubleshooting Palo Alto High Availability environments. •Advanced understanding of HA1, HA2, HA3, configuration synchronization, session synchronization, failover behavior, link monitoring, path monitoring, peer health, and recovery processes. •Strong expertise in TCP/IP, IPv4/IPv6, DNS, DHCP, ARP, routing, NAT, VPNs, and packet-level troubleshooting. •Demonstrated ability to investigate TCP handshakes, resets, retransmissions, MTU/MSS issues, asymmetric routing, connection timeouts, and firewall session behavior. •Extensive experience with Cisco Catalyst and/or Nexus switching technologies. •Strong knowledge of enterprise switching and routing, including VLANs, trunking, STP/RSTP/MST, EtherChannel, HSRP/VRRP, routing protocols, ACLs, QoS, and switch-security controls. Compensation: •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!