More jobs:
Palo Alto Network Engineer Security Clearance
Job in
Springfield, Fairfax County, Virginia, 22150, USA
Listed on 2026-09-02
Listing for:
System One Holdings, LLC
Full Time
position Listed on 2026-09-02
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security
Job Description & How to Apply Below
Job Title:
Palo Alto Firewall Engineer
Location:
Springfield, VA
Type:
Contract To Hire
Compensation: $80/hr w2 Benefits available Conversion Salary: $150,000 annually plus benefits
Work Model:
Onsite Security Clearance:
Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph Responsibilities
• Lead the design, requirements analysis, testing, integration, and implementation of secure network architectures centered on the Palo Alto Networks ecosystem.
• Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment.
• Engineer and implement solutions for customer Change Requests (CRQs); assess impacts on enterprise transport and security activities and provide technically sound recommendations.
• Serve as the technical representative for assigned projects and coordinate issues with the appropriate owners, organizations, contract leadership, and customer leadership.
• Manage the full lifecycle of Palo Alto hardware and software, including complex hardware refreshes, PAN-OS upgrades, legacy-platform sustainment, physical troubleshooting, and line-card replacements.
• Develop, oversee, and maintain configuration-management processes, network architecture diagrams, technical documentation, integration and test plans, and Standard Operating Procedures (SOPs) for Palo Alto security platforms.
• Use Panorama for centralized policy management, including templates, device groups, inheritance, and consistent configuration across a diverse fleet of physical and virtual firewalls.
• Configure and maintain advanced security capabilities and profiles, including App-, User-, Content-, SSL Decryption, Wild Fire, NAT, IPSec VPNs, and threat prevention.
• Oversee security-incident reporting, documentation, investigation, and corrective-action development.
• Act as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network-security status, policies, procedures, and risks.
• Evaluate and report on new and emerging network-security and communications technologies to improve network capacity, performance, reliability, standardization, and security.
• Provide mentorship and technical oversight to junior engineers and serve as an escalation point for complex troubleshooting.
• Follow all customer network-security processes and procedures, maintain compliance with Government and QA standards, and ensure service-performance indicators are met or exceeded. Requirements
• Security Clearance:
Active TS/SCI clearance and the ability to successfully pass and maintain a U.S. Government polygraph.
• A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments.
• Active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification.
• DoD 8140.01 and DoD 8570.01-M IAT Level II compliance (for example, Security+ CE).
• Ability to obtain and maintain a CSSP Infrastructure Support certification within 120 days of the start date.
• Deep practical knowledge of legacy Gen 2/Gen 3 Palo Alto hardware, including PA-3000 and PA-5000 series platforms, legacy CLI, hardware troubleshooting, and line-card replacements.
• Experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and VM-Series virtual firewalls in cloud environments such as AWS, Azure, GCP, or private-cloud.
• Proven expertise with Panorama for centralized policy management, template/device-group inheritance, and configuration deployment across a hybrid firewall fleet.
• Advanced understanding of BGP, OSPF, IPSec VPNs, NAT, TLS/SSL, mutual TLS (mTLS), HTTP, SAML, OAuth, OCSP revocation, DoD PKI, Kerberos, LDAP, and Active Directory.
• Experience with F5 technologies, including APM, AFM, and SSL Orchestrator (SSLO), and troubleshooting TLS/SSL handshake/connection issues.
• Strong network design, engineering, implementation, and troubleshooting skills, including ROM equipment lists and cost estimates.
• Knowledge of…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×