Network Security Engineer
Listed on 2026-09-02
-
IT/Tech
Cybersecurity, Network Security, Systems Engineer
Network Security Engineer — Juniper to Palo Alto Migration
Enterprise Engineering (EE) — Customer Migration Engagement
Location:
Denver, CO (hybrid — 3 days onsite / 2 days remote)
Role Description (Job Summary)
We are seeking an experienced Network Security Engineer to support a customer team migrating from Juniper SRX to Palo Alto Networks Next-Generation Firewalls (NGFW). This is a hybrid engagement based in the Denver area, requiring three days per week onsite at the customer location and two days remote.
The ideal candidate has hands-on experience performing Juniper-to-Palo Alto migrations and can translate legacy Juniper configurations into Palo Alto best practices, while operating confidently in large-scale, service provider-grade environments.
Your Impact (Responsibilities)
- Lead and support the migration of firewall infrastructure from Juniper SRX to Palo Alto NGFW
- Translate existing Juniper configurations into Palo Alto best-practice architectures
- Redesign legacy port/protocol-based security policies into application-aware security policies
- Configure and operate Security Policies, NAT Policies, Application-, User-, Content-, and Zone-Based Security
- Integrate Palo Alto firewalls into complex service provider routing environments, including MPLS, EVPN/VXLAN, and large-scale IP transit architectures
- Deploy Palo Alto NGFWs in active/passive and active/active high availability architectures
- Implement advanced threat prevention capabilities, including IPS, Anti-Malware, URL Filtering, DNS Security, and Wild Fire
- Perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
- Use Strata Cloud Manager (SCM) for centralized management, templates, device groups, policy management, and operational workflows
- Lead cutovers during maintenance windows, minimizing customer impact and ensuring rapid rollback capability if required
- Follow strong change management processes appropriate to large enterprise or service provider environments
- Mentor customer engineers on Palo Alto operational best practices following migration
- Communicate complex technical concepts clearly to both engineering and leadership audiences
Your Experience (Qualifications)
- Experience performing a Juniper SRX to Palo Alto NGFW migration is strongly preferred
- Expertise with Palo Alto Networks NGFW architecture, deployment, and operations in large-scale environments (service provider experience is a plus)
- Knowledge of Juniper architecture and the ability to translate Juniper configurations into Palo Alto best practices
- Advanced understanding of Security Policies, NAT Policies, Application-, User-, Content-, and Zone-Based Security
- Strong knowledge of dynamic routing protocols including BGP, OSPF, IS-IS, static routing, route redistribution, and ECMP
- Experience integrating Palo Alto firewalls into complex service provider routing environments with MPLS, EVPN/VXLAN, and large-scale IP transit architectures
- Experience deploying Palo Alto NGFWs in active/passive and active/active high availability architectures
- Experience implementing advanced threat prevention capabilities including IPS, Anti-Malware, URL Filtering, DNS Security, and Wild Fire
- Ability to perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
- Experience with SCM (Strata Cloud Manager) for centralized management, templates, device groups, policy management, and operational workflows
Key Competencies (Preferred / Other Qualifications)
- Ability to lead cutovers during maintenance windows while minimizing customer impact and ensuring rapid rollback if required
- Strong understanding of change management processes within large enterprise or service provider environments
- Ability to mentor customer engineers on Palo Alto operational best practices following migration
- Excellent communication skills, with the ability to translate complex technical concepts for both engineering and leadership audiences
- Familiarity with cloud integrations (AWS, Azure, GCP) and hybrid network security architectures is a plus
- Comfortable working in a hybrid onsite/remote schedule with a customer-embedded team
Education
No specific degree requirement is mandated. Relevant industry certifications (e.g., Palo Alto Networks PCNSE, JNCIA/JNCIS, or equivalent NGFW/routing certifications) are a plus and may be considered alongside equivalent hands-on professional experience.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).