Point your AI agent at freehire and let it find you a job.

Get the CLI →

Digital Global Connectors

NewBe an early applicant

Palo Alto Integration Engineer, Senior

Posted
Discussion

Palo Alto Integration Engineer, Senior


Location: Washington, DC – On-Site
Work Schedule: Full-Time, On-Site – Daily Commute Required
Employment Type: Full-Time
Clearance: Active security clearance or ability to obtain and maintain required Government background investigation and IT access
Salary Range: $135,000 – $160,000 annually


Position Summary

Digital Global Connectors (DGC) is seeking a Palo Alto Integration Engineer, Senior to serve as a senior technical authority responsible for the architecture, engineering, implementation, administration, and continuous improvement of enterprise Palo Alto Networks security infrastructure supporting a Federal Government IT environment.


This is a local, on-site position requiring a daily commute to the customer site in the Washington, DC area. Only candidates who currently reside within a reasonable daily commuting distance of the worksite will be considered. This position is not remote or hybrid, and candidates planning to relocate to the area at a later date will not be considered for this opening.


The Senior Palo Alto Integration Engineer will provide technical leadership across Palo Alto Networks Next-Generation Firewalls (NGFW), Panorama, Prisma Access, GlobalProtect, Prisma Cloud, Cortex XDR, and associated security technologies. The engineer will work closely with network engineering, cybersecurity, cloud operations, DevSecOps, program leadership, and Government stakeholders to deliver secure, resilient, and compliant enterprise network security capabilities.


The ideal candidate is an accomplished network security engineer with deep hands-on Palo Alto Networks expertise, strong enterprise security architecture experience, and demonstrated experience supporting complex Federal IT environments.


Key Responsibilities


Palo Alto Architecture & Technical Leadership

  • Serve as a senior technical authority and subject matter expert for Palo Alto Networks security technologies.
  • Lead the architecture, engineering, implementation, and optimization of enterprise Palo Alto Networks security solutions.
  • Develop network security architectures, firewall zone models, security policy frameworks, data-flow diagrams, and platform configuration baselines.
  • Lead security architecture reviews for new systems, applications, infrastructure changes, and cloud migrations.
  • Design and implement Zero Trust network security architectures using Palo Alto Networks capabilities.
  • Evaluate emerging Palo Alto Networks technologies and recommend improvements to security posture and operational effectiveness.
  • Provide technical guidance and mentorship to junior and mid-level network security engineers.

Next-Generation Firewall Engineering

  • Lead engineering and administration of Palo Alto Networks NGFW infrastructure across perimeter, internal segmentation, data center, and cloud environments.
  • Design, implement, and maintain NGFW security policies using App-ID, User-ID, and Content-ID.
  • Design and maintain advanced threat-prevention profiles, including antivirus, anti-spyware, vulnerability protection, URL filtering, file blocking, WildFire, and DNS Security.
  • Design and implement SSL/TLS decryption policies.
  • Lead firewall security-policy lifecycle management, optimization, rule-base cleanup, and policy audits.
  • Identify overly permissive rules, unused policies, shadow rules, and policy gaps and implement appropriate remediation.
  • Develop and maintain firewall engineering standards, operational runbooks, and troubleshooting procedures.

Panorama Engineering & Administration

  • Lead engineering, implementation, and administration of Palo Alto Networks Panorama.
  • Design and maintain Panorama device-group and template hierarchies.
  • Develop scalable shared-policy, pre-rule, post-rule, and device-specific policy structures.
  • Configure and maintain role-based administrative access.
  • Lead Panorama upgrades, patches, configuration changes, and platform maintenance.
  • Develop operational dashboards, security reports, and compliance reporting capabilities.

Prisma Access & SASE

  • Lead engineering and administration of Palo Alto Networks Prisma Access.
  • Design and implement GlobalProtect configurations, gateways, agent configurations, split-tunneling policies, and authentication integrations.
  • Configure and maintain Prisma Access security policies, threat prevention, URL filtering, and other cloud-delivered security controls.
  • Integrate Prisma Access with enterprise identity platforms such as Microsoft Entra ID and Okta.
  • Troubleshoot complex remote-access, performance, connectivity, and security-policy issues.
  • Optimize Prisma Access services to support secure and reliable access for distributed users.

Prisma Cloud

  • Engineer and administer Palo Alto Networks Prisma Cloud capabilities across enterprise cloud environments.
  • Support Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP) capabilities.
  • Configure compliance frameworks, policies, alerts, and reporting.
  • Develop cloud security policies aligned with Federal security requirements.
  • Integrate Prisma Cloud findings with SIEM and vulnerability-management processes.
  • Work with cloud operations teams to prioritize and remediate identified security issues.
  • Support AWS GovCloud and/or Microsoft Azure Government environments.

Cortex XDR & Threat Detection

  • Lead engineering and administration of Palo Alto Networks Cortex XDR.
  • Configure prevention policies, behavioral threat protection, and detection analytics.
  • Develop and tune detection rules and Behavioral Indicators of Compromise (BIOC).
  • Align detection capabilities with the MITRE ATT&CK framework.
  • Integrate Cortex XDR with SIEM, threat-intelligence, and SOAR capabilities.
  • Support alert investigation, incident response, and threat-hunting activities.
  • Monitor platform health, endpoint coverage, and detection effectiveness.

Threat Prevention & Security Operations

  • Lead continuous improvement of threat-prevention capabilities across Palo Alto Networks technologies.
  • Optimize WildFire, DNS Security, URL filtering, vulnerability protection, and other prevention capabilities.
  • Analyze security events, threat intelligence, and platform telemetry to identify emerging threats and security gaps.
  • Support incident-response containment, eradication, and recovery activities.
  • Participate in purple-team and detection-validation activities.
  • Develop security-effectiveness metrics and reports for program and Government leadership.

Change Management & Documentation

  • Lead development of Palo Alto Networks change requests for Change Advisory Board (CAB) review.
  • Develop technical impact assessments, implementation procedures, testing plans, and rollback procedures.
  • Coordinate significant platform changes and maintenance activities.
  • Conduct post-implementation reviews.
  • Develop and maintain architecture documentation, SOPs, runbooks, troubleshooting guides, and knowledge-base materials.
  • Ensure technical documentation accurately reflects current production configurations.

Federal Cybersecurity Compliance & ATO

  • Ensure Palo Alto Networks technologies are configured and maintained in accordance with applicable Federal cybersecurity requirements.
  • Support compliance with NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, applicable OMB requirements, DISA STIGs, and customer-specific cybersecurity requirements.
  • Support ATO activities, including security-control documentation, SSP contributions, continuous-monitoring evidence, and audit artifacts.
  • Conduct configuration-compliance assessments and support remediation of security-baseline and STIG findings.
  • Support vulnerability identification, prioritization, tracking, and remediation.
  • Develop and maintain platform security baselines and compliance documentation.


Required Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related field. An equivalent combination of education and directly relevant professional experience may be considered.
  • Minimum of 7 years of hands-on experience in network security engineering, firewall engineering, or a closely related discipline.
  • At least 5 years of demonstrated hands-on experience engineering and administering Palo Alto Networks platforms in an enterprise environment.
  • Advanced experience designing, implementing, and administering Palo Alto Networks NGFW infrastructure.
  • Advanced experience with Palo Alto Networks Panorama.
  • Hands-on experience engineering and administering Palo Alto Networks Prisma Access.
  • Experience developing App-ID, User-ID, Content-ID, threat-prevention, and SSL/TLS decryption policies.
  • Strong enterprise networking expertise, including:
    • BGP, OSPF, and other routing technologies
    • Switching and VLANs
    • SD-WAN
    • IPsec and SSL VPNs
    • Network segmentation
    • Firewall zone architecture
  • Demonstrated experience implementing Zero Trust network-security principles.
  • Experience supporting network security operations within a Federal Government IT contracting environment.
  • Knowledge of NIST SP 800-53, FISMA, FedRAMP, DISA STIGs, and Federal Zero Trust requirements.
  • Experience supporting ATO and continuous-monitoring activities.
  • Experience with network traffic analysis and troubleshooting tools.
  • Strong technical leadership and mentoring skills.
  • Excellent written and verbal communication skills.
  • Ability to communicate complex security architecture and engineering concepts to technical and non-technical stakeholders.
  • Active security clearance or ability to obtain and maintain the Government background investigation, clearance, and IT access required for the position.
  • Must currently reside within reasonable daily commuting distance of the Washington, DC/Northern Virginia customer worksite and be available to report on-site each workday.
  • Candidates requiring relocation, remote work, or a hybrid work arrangement will not be considered for this position.

Preferred Qualifications

  • Previous experience serving as a senior Palo Alto Networks engineer, architect, or technical lead on a Federal IT program.
  • Advanced experience with Prisma Cloud.
  • Advanced experience with Cortex XDR.
  • Experience with Cortex XSOAR.
  • Experience supporting AWS GovCloud and/or Microsoft Azure Government.
  • Experience integrating Palo Alto Networks technologies with SIEM, SOAR, identity-management, and threat-intelligence platforms.
  • Experience supporting FedRAMP authorization activities.
  • Advanced experience implementing Zero Trust Architecture.
  • Experience with threat hunting and incident response.
  • Experience with purple-team or detection-validation activities.
  • Experience with security automation and Palo Alto Networks APIs.


Preferred Certifications

One or more of the following certifications is strongly preferred:

  • Palo Alto Networks Certified Network Security Engineer (PCNSE) or current equivalent
  • Palo Alto Networks advanced security automation, detection/response, or cloud security certification
  • Certified Information Systems Security Professional (CISSP)
  • Cisco Certified Network Professional Security (CCNP Security)
  • GIAC Certified Enterprise Defender (GCED)
  • Other relevant advanced Palo Alto Networks, cybersecurity, cloud security, or network security certifications


Core Competencies

Successful candidates will demonstrate:

  • Deep Palo Alto Networks technical expertise
  • Enterprise network-security architecture expertise
  • Strong technical leadership and mentorship
  • Advanced troubleshooting and root-cause analysis
  • Zero Trust architecture knowledge
  • Federal cybersecurity compliance knowledge
  • Sound security engineering judgment
  • Strong documentation and change-management discipline
  • Ability to lead complex technical initiatives
  • Effective communication with Government and program stakeholders
  • Ability to operate independently as a senior technical authority


Compensation

DGC anticipates a base salary range of $135,000–$160,000 annually for this position. Actual compensation will be determined based on Palo Alto Networks expertise, years and depth of relevant experience, Federal contracting experience, certifications, clearance status, cloud and Zero Trust experience, education, and other job-related qualifications.


Equal Employment Opportunity

Digital Global Connectors, LLC is an Equal Opportunity Employer. DGC provides equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable Federal, state, or local law.


Skills

See also

Software Engineering jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available