Search

Network Security Engineer

PublishedPublished: 6/14/2022
Technology

Job Description

Network Security Engineer — Juniper to Palo Alto Migration

\n


\n

Enterprise Engineering (EE) — Customer Migration Engagement

\n

Location: Denver, CO (hybrid — 3 days onsite / 2 days remote)

\n


\n

Role Description (Job Summary)

\n

We are seeking an experienced Network Security Engineer to support a customer team migrating from Juniper SRX to Palo Alto Networks Next-Generation Firewalls (NGFW). This is a hybrid engagement based in the Denver area, requiring three days per week onsite at the customer location and two days remote.

\n

The ideal candidate has hands-on experience performing Juniper-to-Palo Alto migrations and can translate legacy Juniper configurations into Palo Alto best practices, while operating confidently in large-scale, service provider-grade environments.

\n

Your Impact (Responsibilities)

\n

    \n
  • Lead and support the migration of firewall infrastructure from Juniper SRX to Palo Alto NGFW
  • \n

  • Translate existing Juniper configurations into Palo Alto best-practice architectures
  • \n

  • Redesign legacy port/protocol-based security policies into application-aware security policies
  • \n

  • Configure and operate Security Policies, NAT Policies, Application-ID, User-ID, Content-ID, and Zone-Based Security
  • \n

  • Integrate Palo Alto firewalls into complex service provider routing environments, including MPLS, EVPN/VXLAN, and large-scale IP transit architectures
  • \n

  • Deploy Palo Alto NGFWs in active/passive and active/active high availability architectures
  • \n

  • Implement advanced threat prevention capabilities, including IPS, Anti-Malware, URL Filtering, DNS Security, and WildFire
  • \n

  • Perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
  • \n

  • Use Strata Cloud Manager (SCM) for centralized management, templates, device groups, policy management, and operational workflows
  • \n

  • Lead cutovers during maintenance windows, minimizing customer impact and ensuring rapid rollback capability if required
  • \n

  • Follow strong change management processes appropriate to large enterprise or service provider environments
  • \n

  • Mentor customer engineers on Palo Alto operational best practices following migration
  • \n

  • Communicate complex technical concepts clearly to both engineering and leadership audiences
  • \n

\n

Your Experience (Qualifications)

\n

    \n
  • Experience performing a Juniper SRX to Palo Alto NGFW migration is strongly preferred
  • \n

  • Expertise with Palo Alto Networks NGFW architecture, deployment, and operations in large-scale environments (service provider experience is a plus)
  • \n

  • Knowledge of Juniper architecture and the ability to translate Juniper configurations into Palo Alto best practices
  • \n

  • Advanced understanding of Security Policies, NAT Policies, Application-ID, User-ID, Content-ID, and Zone-Based Security
  • \n

  • Strong knowledge of dynamic routing protocols including BGP, OSPF, IS-IS, static routing, route redistribution, and ECMP
  • \n

  • Experience integrating Palo Alto firewalls into complex service provider routing environments with MPLS, EVPN/VXLAN, and large-scale IP transit architectures
  • \n

  • Experience deploying Palo Alto NGFWs in active/passive and active/active high availability architectures
  • \n

  • Experience implementing advanced threat prevention capabilities including IPS, Anti-Malware, URL Filtering, DNS Security, and WildFire
  • \n

  • Ability to perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
  • \n

  • Experience with SCM (Strata Cloud Manager) for centralized management, templates, device groups, policy management, and operational workflows
  • \n

\n

Key Competencies (Preferred / Other Qualifications)

\n

    \n
  • Ability to lead cutovers during maintenance windows while minimizing customer impact and ensuring rapid rollback if required
  • \n

  • Strong understanding of change management processes within large enterprise or service provider environments
  • \n

  • Ability to mentor customer engineers on Palo Alto operational best practices following migration
  • \n

  • Excellent communication skills, with the ability to translate complex technical concepts for both engineering and leadership audiences
  • \n

  • Familiarity with cloud integrations (AWS, Azure, GCP) and hybrid network security architectures is a plus
  • \n

  • Comfortable working in a hybrid onsite/remote schedule with a customer-embedded team
  • \n

\n

Education

\n

No specific degree requirement is mandated. Relevant industry certifications (e.g., Palo Alto Networks PCNSE, JNCIA/JNCIS, or equivalent NGFW/routing certifications) are a plus and may be considered alongside equivalent hands-on professional experience.

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...