Network Security Engineer Master
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Network Security, Network Engineer
United States
Suitability/Public Trust
Fully remote
Information Technology
OverviewGovCIO is seeking a highly experienced Master Network & Security Engineer to lead the design, operation, troubleshooting, and continuous improvement of enterprise network-security infrastructure. This role is responsible for Palo Alto Networks next-generation firewalls, Panorama, High Availability, Cisco switching, network segmentation, Cortex XSIAM, and Strata Logging Service.
The Senior Engineer will serve as a technical escalation point for complex network and security incidents, lead architecture and implementation initiatives, establish standards, and partner with SOC, infrastructure, cloud, application, and leadership teams to reduce risk and maintain highly available services.
This position is located within the United States and is fully remote.
ResponsibilitiesLead the design, deployment, administration, and lifecycle management of Palo Alto Networks NGFW environments running PAN-OS.
Own centralized firewall management through Palo Alto Panorama, including device groups, templates, template stacks, policy inheritance, upgrades, configuration backups, log monitoring, and firewall onboarding.
Design and govern security policies using zero-trust, least-privilege, application-aware, and risk-based principles.
Configure and troubleshoot security zones, NAT, virtual routers, static and dynamic routing, IPsec VPN, Global Protect, decryption, URL Filtering, Threat Prevention, Wild Fire, DNS Security, and App-.
Lead enterprise network-segmentation and microsegmentation initiatives using security zones, VLANs, subinterfaces, virtual routers, routing controls, and application-based security policies.
Develop secure controls for traffic between users, servers, applications, management networks, guest networks, IoT/OT devices, data-center workloads, and cloud resources.
Architect, configure, test, and troubleshoot Palo Alto High Availability deployments, including Active/Passive and Active/Active designs as required.
Resolve complex HA failures involving HA1 control links, HA2 session/state synchronization, HA3 packet forwarding, peer communications, configuration synchronization, monitoring failures, split-brain prevention, and failover recovery.
Plan and execute HA failover testing, PAN-OS upgrades, disaster-recovery exercises, and maintenance procedures while minimizing service impact.
Troubleshoot HA infrastructure dependencies, including cables, transceivers, switch ports, port channels, VLANs, routing, MTU, latency, packet loss, and redundant-path failures.
Lead the configuration, support, and troubleshooting of Cisco Catalyst and Nexus switching environments.
Design and support VLANs, trunking, STP/RSTP/MST, Ether Channel/port channels, HSRP/VRRP, Layer 2/Layer 3 switching, ACLs, QoS, switch security, routing, and access-control technologies.
Diagnoses complex connectivity and performance issues through firewall logs, session inspection, packet captures, CLI diagnostics, switch counters, flow data, and network-monitoring platforms.
Analyze TCP/IP behavior, including handshake failures, SYN/SYN-ACK/ACK flow, retransmissions, resets, timeouts, asymmetric routing, MTU/MSS issues, fragmentation, latency, packet loss, and NAT translation problems.
Verify packet flow across firewall policy, App-, routing, NAT, decryption, threat prevention, VPN, switching, and server/application layers.
Monitor firewall management-plane and dataplane health, including CPU, memory, session capacity, packet buffers, throughput, logging, and interface performance.
Integrate Palo Alto NGFWs and Panorama with Strata Logging Service and Cortex XSIAM.
Ensure reliable firewall log forwarding, cloud logging, log ingestion, data normalization, event…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).