×
Register Here to Apply for Jobs or Post Jobs. X

Palo Alto Subject Matter Expert Security Clearance

Job in Springfield, Fairfax County, Virginia, 22150, USA
Listing for: CACI
Full Time position
Listed on 2026-07-21
Job specializations:
  • IT/Tech
    Cybersecurity, Network Security, Systems Engineer
Job Description & How to Apply Below
Position: Palo Alto Subject Matter Expert with Security Clearance
Job Title:

Palo Alto Subject Matter Expert Job Category:
Information Technology Time Type:
Full time Minimum Clearance Required to Start: TS/SCI Employee Type:
Regular Percentage of

Travel Required:

Up to 10% Type of Travel:
Local *
*
* The Opportunity:

The Opportunity As a Palo Alto Subject Matter Expert (SME) on the Network Security Services (NSS) team, you will be the focal point for all Palo Alto-related tasks, operations, and projects. You will work with both corporate and customer leadership to research, analyze, and implement enterprise-wide network security solutions that bridge legacy and next-generation architectures. This role requires a unique blend of deep, hands-on expertise with traditional Gen 2/Gen 3 hardware platforms and modern, cloud-native solutions like Prisma Access (SASE) and Cortex XSOAR.

You will provide critical technical oversight, ensuring the stability, security, and modernization of our firewall infrastructure. Responsibilities:
* Lead the design, analysis, testing, and implementation of state-of-the-art secure network architectures centered on the Palo Alto Networks ecosystem.

* Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment.

* Manage the full lifecycle of Palo Alto hardware and software, including executing complex hardware refreshes and PAN-OS upgrades, especially on legacy platforms.

* Develop, oversee, and maintain configuration management processes and Standard Operating Procedures (SOPs) for all Palo Alto security platforms.

* Utilize Panorama for centralized policy management, ensuring consistent and efficient configuration across a diverse fleet of physical and virtual firewalls.

* Configure and maintain master-level security profiles, including App-, User-, Content-, SSL Decryption, and Wild Fire threat prevention.

* Oversee the reporting, documentation, and investigation of security-related incidents, and lead the development of corrective measures.

* Act as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network security status, policies, and procedures.

* Evaluate and report on new and emerging network security technologies to enhance the capabilities, performance, and reliability of the network.
• Provide mentorship and technical oversight to junior engineers, and act as an escalation point for complex troubleshooting efforts.

Qualifications:

Required:

* Security Clearance:
Must possess an active TS/SCI clearance and be able to successfully pass/maintain a U.S. Government Polygraph.

* A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments.

* Must hold an active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification. Must be DoD 8140.01 and DoD 8570.01-M IAT Level II compliant (e.g., Security+ CE).

* Must be able to successfully obtain/maintain a CSSP Infrastructure Support certification within 120 days of the start date.

* Deep, practical knowledge of legacy Gen 2/Gen 3 hardware (e.g., PA-3000, PA-5000 series), including legacy CLI, physical hardware troubleshooting, and line-card replacements.

* Next-Gen & Cloud Security:
Direct experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and virtual firewalls (VM-Series) in public/private cloud environments (AWS, Azure, or GCP).

* Proven expertise utilizing Panorama for centralized policy management, template/device group inheritance, and pushing configurations across a hybrid fleet.

* Network Foundations:
Advanced understanding of core networking protocols critical to firewall routing and legacy-to-modern transitions, specifically BGP, OSPF, IPSec VPNs, and NAT.

* Bachelor's degree in a related field (e.g., IT, Cybersecurity, Computer Science). Additional years of relevant experience may be considered in lieu of a degree. Desired:
* Advanced

Certifications:

Active Palo Alto Networks Certified Network Security Consultant (PCNSC) or Prisma Certified SASE Professional (PCSAE).

* Automation & Scripting:
Proficiency in Python and experience automating firewall deployment, policy changes, and configuration backups using Ansible, Terraform, or Palo Alto XML/REST APIs.

* Security Orchestration:
Hands-on experience with Cortex XDR or Cortex XSOAR for automated threat response.

* Migration Tools:
Proficiency using Palo Alto Networks Expedition to migrate and consolidate legacy rules to modern App--based policies.

* Enterprise Architecture:
Background in designing Zero Trust Network Access (ZTNA) architectures across complex, segment-isolated enterprise environments.

* Broader

Experience:

Experience with other security platforms and technologies such as F5 (APM, AFM), Juniper SRX, and Cisco FTD/ASA.

- What You Can Expect: A culture of integrity. At CACI, we place character and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary