Network Security Architect - Palo Alto Prisma SD-WAN (ION), AWS, PCNSA / PCNSE

Summary

The Network Security Architect will design and implement end-to-end Palo Alto Prisma SD-WAN architectures for AWS and hybrid cloud environments. The role involves creating HLD/LLD documentation, managing cloud-to-branch connectivity, and ensuring enterprise-grade security through SASE and Zero Trust principles.

Role: Network Security Architect - Palo Alto Prisma SD-WAN (ION), AWS

Remote - Canada


Required Skills

Networking & SD-WAN

* Must know Palo Alto Prisma SD-WAN (ION) - on prime and AWS Strata Cloud Manager (SCM)

* Prisma Access

* BGP

* OSPF

* Static Routing

* ECMP

* IPSec VPN

* GRE Tunnels

* SD-WAN High Availability (HA)

* MPLS

* DIA

* Broadband Connectivity

* Traffic Engineering and Application-Aware Routing


### Cloud


* AWS VPC

* Transit Gateway

* Direct Connect

* Route Tables

* Security Groups

* NACLs

* AWS Networking Design

* Hybrid Cloud Connectivity


### Security


* Palo Alto NGFW

* Zero Trust Architecture

* SASE/SSE

* Segmentation and Security Policies

* Identity and Access Management


## Roles & Responsibilities


* Design end-to-end Palo Alto Prisma SD-WAN architecture for AWS, branch locations, data centers, and cloud environments.

* Develop HLD and LLD documentation for SD-WAN deployments.

* Design AWS-hosted ION Virtual Appliance architecture including HA clusters and multi-region resiliency.

* Define routing strategies using BGP, static routes, route redistribution, and cloud connectivity models.

* Deploy and onboard Prisma SD-WAN ION Virtual Appliances in AWS.

* Integrate AWS VPCs, Transit Gateway, and Direct Connect with Prisma SD-WAN fabric.

* Configure cloud-to-branch and branch-to-cloud connectivity.

* Design secure connectivity for applications hosted in AWS.


### SD-WAN Implementation


* Configure ION devices, sites, WAN circuits, and VPN fabrics.

* Implement application-aware policies, QoS, and path selection.

* Configure WAN overlays and service links.

* Execute greenfield and brownfield migrations.

* Design active/active and active/standby ION HA clusters.

* Plan failover, redundancy, and disaster recovery scenarios.

* Validate AWS availability zone resilience and WAN failover mechanisms.


### Integrate Prisma Access and Palo Alto SD-WAN & NGFW


* Implement segmentation, secure zones, and security policies.

* Ensure compliance with enterprise security standards.

* Lead migration from traditional WAN or third-party SD-WAN solutions to Prisma SD-WAN.

* Execute cloud migration and data center exit initiatives.

* Perform pilot deployments and production cutovers.

* Diagnose routing, tunnel, and application performance issues.

* Work with Palo Alto TAC for critical incidents and platform bugs.

* Optimize application experience and network performance.

* Provide L3/L4 engineering support.

* Prepare HLD, LLD, MOP, migration runbooks, rollback plans, and SOPs.

* Participate in architecture reviews and customer workshops.

* Present technical solutions to customers and stakeholders.


## Mandatory Certifications


* Palo Alto PCNSA / PCNSE

* Palo Alto Prisma SD-WAN Certification (Preferred)



See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available