Palo Alto Security Engineer
Posted Updated
Palo Alto Security Engineer, NGFW and SASE
Zappsec Technologies Inc.
About the role
Zappsec designs and operates network security platforms enterprise clients. This role owns the Palo Alto Networks side of that work.
You will configure Panorama, write and tune firewall policy, and migrate existing rule bases onto Palo Alto platforms in AWS and Azure. You will also build and support SASE services through Prisma Access and GlobalProtect.
This is a hands-on engineering role. You will be in the consoles and the CLI daily. You will not manage vendors or coordinate other people's work.
What you will do
Panorama configuration and platform management
Zappsec Technologies Inc.
About the role
Zappsec designs and operates network security platforms enterprise clients. This role owns the Palo Alto Networks side of that work.
You will configure Panorama, write and tune firewall policy, and migrate existing rule bases onto Palo Alto platforms in AWS and Azure. You will also build and support SASE services through Prisma Access and GlobalProtect.
This is a hands-on engineering role. You will be in the consoles and the CLI daily. You will not manage vendors or coordinate other people's work.
What you will do
Panorama configuration and platform management
- Build and maintain Panorama templates, template stacks, and device groups across client estates.
- Structure pre-rules and post-rules so inheritance behaves predictably as device groups grow.
- Run commit and push workflows, including partial commits and config audits before change windows.
- Manage log collectors, log forwarding profiles, and retention design.
- Schedule and validate dynamic content updates for applications, threats, and WildFire.
- Plan and execute PAN-OS upgrades across HA pairs, with tested rollback for every step.
- Onboard new firewalls into Panorama and bring them under central policy control.
- Write, tune, and document security policy, NAT policy, and decryption policy.
- Convert legacy port-based rules to App-ID rules using Policy Optimizer.
- Identify and remove shadowed, redundant, expired, and unused rules.
- Apply security profile groups covering antivirus, anti-spyware, vulnerability protection, URL filtering, WildFire, file blocking, and DNS Security.
- Maintain address objects, service objects, tags, dynamic address groups, and external dynamic lists against a naming standard.
- Configure User-ID and bind policy to identity groups rather than IP ranges.
- Configure SSL forward proxy and inbound inspection, including certificate handling and decryption exclusions.
- Migrate rule bases from Cisco ASA, Check Point, Fortinet, and Juniper SRX to PAN-OS.
- Use Expedition or equivalent tooling for conversion, object cleanup, and App-ID adoption.
- Rehost policy onto VM-Series and Cloud NGFW in AWS and Azure.
- Design the enforcement topology with the client architect, covering Gateway Load Balancer, transit VPC, and Azure Virtual WAN hub patterns.
- Map on-premises zones, objects, and groups to cloud constructs, resource tags, and dynamic address groups.
- Validate each migration wave against traffic logs before and after cutover.
- Write the cutover plan, the rollback plan, and the post-migration validation steps for every window.
- Configure Prisma Access mobile users, remote networks, and service connections.
- Build and support GlobalProtect portals, gateways, HIP checks, and split tunnel design.
- Write ZTNA access policy and explicit proxy configuration.
- Configure CASB and DLP controls where the engagement includes them.
- Use Autonomous DEM to diagnose user experience problems across the service path.
- Operate deployments under Strata Cloud Manager or Panorama managed Prisma Access.
- Run platform health checks and best practice reviews, then deliver written remediation guidance.
- Take escalations on complex issues using packet captures, session analysis, and global counters.
- Open and drive Palo Alto TAC cases to resolution.
- Produce high level and low level design documents, runbooks, and as-built records.
- Run knowledge transfer sessions so client teams can operate what you build.
- Five or more years configuring and operating Palo Alto NGFW in production environments.
- Direct experience administering Panorama, including templates, template stacks, and device groups.
- Proven record of firewall rule migration from another vendor platform to PAN-OS.
- Working knowledge of App-ID, User-ID, Content-ID, and security profile design.
- Experience deploying VM-Series or Cloud NGFW in at least one public cloud.
- Strong routing and switching fundamentals, including BGP, OSPF, NAT, and IPSec.
- Experience with GlobalProtect or Prisma Access in a production deployment.
- Ability to write client-facing documentation without an editor rewriting it.
- Comfort working directly with client engineers and architects during change windows.
- PCNSE certification. PCNSA or PCSFE also considered.
- Experience with Expedition for large rule base conversions.
- Consulting or managed services background across multiple client environments.
- Terraform or Ansible experience for firewall and policy automation.
- Exposure to Cortex XDR, Cortex Data Lake, or Prisma Cloud.
- Experience in regulated environments such as financial services, healthcare, or energy.
| Category | Tools |
| Management | Panorama, Strata Cloud Manager |
| Platform | PAN-OS, PA-Series, VM-Series, CN-Series, Cloud NGFW |
| SASE | Prisma Access, GlobalProtect, Explicit Proxy, Autonomous DEM |
| Migration | Expedition, Policy Optimizer, Best Practice Assessment |
| Cloud | AWS, Azure |
| Automation | Terraform, Ansible, Git, PAN-OS XML API |
| Analysis | Wireshark, packet captures, traffic and threat log analysis |
| Delivery | [Confirm ticketing and documentation stack] |