Job Description
Network Security Engineer — Juniper to Palo Alto Migration
\n
\n
Enterprise Engineering (EE) — Customer Migration Engagement
\n
Location: Denver, CO (hybrid — 3 days onsite / 2 days remote)
\n
\n
Role Description (Job Summary)
\n
We are seeking an experienced Network Security Engineer to support a customer team migrating from Juniper SRX to Palo Alto Networks Next-Generation Firewalls (NGFW). This is a hybrid engagement based in the Denver area, requiring three days per week onsite at the customer location and two days remote.
\n
The ideal candidate has hands-on experience performing Juniper-to-Palo Alto migrations and can translate legacy Juniper configurations into Palo Alto best practices, while operating confidently in large-scale, service provider-grade environments.
\n
Your Impact (Responsibilities)
\n
- \n
- Lead and support the migration of firewall infrastructure from Juniper SRX to Palo Alto NGFW
- Translate existing Juniper configurations into Palo Alto best-practice architectures
- Redesign legacy port/protocol-based security policies into application-aware security policies
- Configure and operate Security Policies, NAT Policies, Application-ID, User-ID, Content-ID, and Zone-Based Security
- Integrate Palo Alto firewalls into complex service provider routing environments, including MPLS, EVPN/VXLAN, and large-scale IP transit architectures
- Deploy Palo Alto NGFWs in active/passive and active/active high availability architectures
- Implement advanced threat prevention capabilities, including IPS, Anti-Malware, URL Filtering, DNS Security, and WildFire
- Perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
- Use Strata Cloud Manager (SCM) for centralized management, templates, device groups, policy management, and operational workflows
- Lead cutovers during maintenance windows, minimizing customer impact and ensuring rapid rollback capability if required
- Follow strong change management processes appropriate to large enterprise or service provider environments
- Mentor customer engineers on Palo Alto operational best practices following migration
- Communicate complex technical concepts clearly to both engineering and leadership audiences
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
Your Experience (Qualifications)
\n
- \n
- Experience performing a Juniper SRX to Palo Alto NGFW migration is strongly preferred
- Expertise with Palo Alto Networks NGFW architecture, deployment, and operations in large-scale environments (service provider experience is a plus)
- Knowledge of Juniper architecture and the ability to translate Juniper configurations into Palo Alto best practices
- Advanced understanding of Security Policies, NAT Policies, Application-ID, User-ID, Content-ID, and Zone-Based Security
- Strong knowledge of dynamic routing protocols including BGP, OSPF, IS-IS, static routing, route redistribution, and ECMP
- Experience integrating Palo Alto firewalls into complex service provider routing environments with MPLS, EVPN/VXLAN, and large-scale IP transit architectures
- Experience deploying Palo Alto NGFWs in active/passive and active/active high availability architectures
- Experience implementing advanced threat prevention capabilities including IPS, Anti-Malware, URL Filtering, DNS Security, and WildFire
- Ability to perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
- Experience with SCM (Strata Cloud Manager) for centralized management, templates, device groups, policy management, and operational workflows
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
Key Competencies (Preferred / Other Qualifications)
\n
- \n
- Ability to lead cutovers during maintenance windows while minimizing customer impact and ensuring rapid rollback if required
- Strong understanding of change management processes within large enterprise or service provider environments
- Ability to mentor customer engineers on Palo Alto operational best practices following migration
- Excellent communication skills, with the ability to translate complex technical concepts for both engineering and leadership audiences
- Familiarity with cloud integrations (AWS, Azure, GCP) and hybrid network security architectures is a plus
- Comfortable working in a hybrid onsite/remote schedule with a customer-embedded team
\n
\n
\n
\n
\n
\n
\n
Education
\n
No specific degree requirement is mandated. Relevant industry certifications (e.g., Palo Alto Networks PCNSE, JNCIA/JNCIS, or equivalent NGFW/routing certifications) are a plus and may be considered alongside equivalent hands-on professional experience.
