Senior Network Security Engineer
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Network Security, Network Engineer, Systems Engineer
United States
Suitability/Public Trust
Fully remote
Information Technology
OverviewGovCIO is seeking a highly experienced Senior Network & Security Engineer to lead the design, operation, troubleshooting, and continuous improvement of enterprise network-security infrastructure. This role is responsible for Palo Alto Networks next-generation firewalls, Panorama, High Availability, Cisco switching, network segmentation, Cortex XSIAM, and Strata Logging Service.
The Senior Engineer will serve as a technical escalation point for complex network and security incidents, lead architecture and implementation initiatives, establish standards, and partner with SOC, infrastructure, cloud, application, and leadership teams to reduce risk and maintain highly available services.
This position will be located within the United States and will be a fully remote opportunity.
ResponsibilitiesThe successful Senior Network & Security Engineer will be a hands‑on technical leader with deep expertise in Palo Alto Networks firewalls, Panorama, HA, and Cisco enterprise networking. This person will lead firewall‑policy and microsegmentation design, troubleshoot complex TCP/IP and packet‑flow issues, ensure resilient HA operations, and integrate security telemetry with Cortex XSIAM and Strata Logging Service. The candidate must be able to independently lead technical projects, resolve high‑impact incidents, improve security controls, and mentor other engineering team members.
Lead the design, deployment, administration, and lifecycle management of Palo Alto Networks NGFW environments running PAN-OS.
Own centralized firewall management through Palo Alto Panorama, including device groups, templates, template stacks, policy inheritance, upgrades, configuration backups, log monitoring, and firewall onboarding.
Design and govern security policies using zero‑trust, least‑privilege, application‑aware, and risk‑based principles.
Configure and troubleshoot security zones, NAT, virtual routers, static and dynamic routing, IPsec VPN, Global Protect, decryption, URL Filtering, Threat Prevention, Wild Fire, DNS Security, and App‑.
Lead enterprise network‑segmentation and microsegmentation initiatives using security zones, VLANs, subinterfaces, virtual routers, routing controls, and application‑based security policies.
Develop secure controls for traffic between users, servers, applications, management networks, guest networks, IoT/OT devices, data‑center workloads, and cloud resources.
Architect, configure, test, and troubleshoot Palo Alto High Availability deployments, including Active/Passive and Active/Active designs as required.
Resolve complex HA failures involving HA1 control links, HA2 session/state synchronization, HA3 packet forwarding, peer communications, configuration synchronization, monitoring failures, split‑brain prevention, and failover recovery.
Plan and execute HA failover testing, PAN-OS upgrades, disaster‑recovery exercises, and maintenance procedures while minimizing service impact.
Troubleshoot HA infrastructure dependencies, including cables, transceivers, switch ports, port channels, VLANs, routing, MTU, latency, packet loss, and redundant‑path failures.
Lead the configuration, support, and troubleshooting of Cisco Catalyst and Nexus switching environments.
Design and support VLANs, trunking, STP/RSTP/MST, Ether Channel/port channels, HSRP/VRRP, Layer 2/Layer 3 switching, ACLs, QoS, switch security, routing, and access‑control technologies.
Diagnoses complex connectivity and performance issues through firewall logs, session inspection, packet captures, CLI diagnostics, switch counters, flow data, and network‑monitoring platforms.
Analyze TCP/IP behavior, including handshake failures, SYN/SYN‑ACK/ACK flow,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).