Senior Network Engineer SME (Palo Alto) - Phaxis LLC
Houston, TX 77046
About the Job
The Sr. Network Engineer SME (Palo Alto) is the global corporate network teams firewall and security SME in the analysis, assessment, development, and evaluation of network security solutions and architectures to secure networks, applications, operating systems and databases. This is position is a SME position on the network architect and engineering team and is the security liaison for the team. This role is hands on design and implementation of various network security stack architectures with a primary focus on Palo Alto firewalls. Additionally, the Sr. Network Firewall Security Engineer assists in the development of network security requirements, assists in technical regulatory compliance efforts, evaluates security services and technologies, and reviews and documents information security policies and procedures as well as provides monitoring and oversight for alerts in this environment to hand off to Operations.
The Sr. Network Engineer SME has a broad, generalist knowledge of on-prem infrastructure security and knowledge in public cloud infrastructure and automation. They will ideally have a specialist area in network security (Palo Alto firewalls, DMZ , Segmentation, Client, WAF, DDOS, redundancy architectures, end point security, etc) , but are able to turn their attention to and learn something new rapidly. This role will include capabilities on presenting network security solution design options for securing Internet and Partner facing architectures, container security, multi-cloud and end point security awareness.
Responsibilities:
The Sr. Network Engineer SME has a broad, generalist knowledge of on-prem infrastructure security and knowledge in public cloud infrastructure and automation. They will ideally have a specialist area in network security (Palo Alto firewalls, DMZ , Segmentation, Client, WAF, DDOS, redundancy architectures, end point security, etc) , but are able to turn their attention to and learn something new rapidly. This role will include capabilities on presenting network security solution design options for securing Internet and Partner facing architectures, container security, multi-cloud and end point security awareness.
Responsibilities:
- Strong Understanding of Palo Alto Firewalls.
- Deploying Palo Alto firewalls in AWS and Azure (VM, NGFW and CN).
- Understands network and cloud firewall deployments and architectures.
- Architecting and Engineering DMZ security for Internet facing web applications.
- Network segmentation of non-prod and production environments.
- Understanding various vendor solutions that are used to secure various architectures.
- Proactively identify and determine priority for any network security gaps.
- Mentors other Network Engineers for security best practices.
- Point of Contact for all escalations from engineering and ops teams.
- Firewall standards and tools used to audit standards are applied.
- Firewall rule cleanup tools and procedures.
- Works with security teams to create and/or steer processes for identifying and remediating vulnerabilities and risk.
- Serve as point of escalation point for network security solutions.
- Keep abreast of new cloud and automation developments, evaluate alternative approaches, and recommend new software or modifications which enhance operations and development activities.
- Identify opportunities and make recommendations to improve availability, reliability, efficiency, performance and overall service within the distributed computing environment and associated departments.
- Provide clear documentation of technical solutions and communicate plans to management and customers.
- Perform related duties as required or assigned.
Required Skills:
- 7-10+ years' experience managing various network architectures.
- 5+ years' experience on Palo Alto firewalls and securing Internet facing applications.
- 3+ years of experience in Public Cloud technologies including AWS and Microsoft Azure specifically in networking and security solutions and implementation.
- 5+ years of technical experience with network security technologies (ex. Firewalls, proxy and network segmentation).
- 5+ years experience working with routing protocols BGP and OSPF.
Preferred Skills:
- Experience in DevOps scripting and automation using tools such as Ansible, Puppet, Chef, and/or Terraform.
- Understanding of Openshift, Docker and Kubernetes container environment.
- Experience with DLP, WAF, DDOS, IPS/IDS.
- Experience with Palo Cloud, SOAR, Twistlock, Redlock and Prisma Access.
- Experience with various endpoint security solutions.
- Information Technology/Cisco Certified Network Associate (CCNA).
- Information Technology/Cisco Certified Network Professional Security (CCNP).
Required Education:
- Bachelor's degree or equivalent experience in Computer Science.
Source : Phaxis LLC