Senior Network Security Engineer (Remote)
Summary
Hands-on technical leader designing, implementing, and operating secure network services across Kohl's data centers, cloud (GCP), retail locations, and remote access using Palo Alto Networks firewalls, GlobalProtect VPN, Prisma Access, and SASE.
About the Role
The Senior Network Engineer, Network Security is a hands-on technical leader responsible for designing, implementing, and operating secure, reliable, and scalable network services across locations, data centers, cloud environments, partner connectivity, and remote-user access.
This role requires strong network engineering fundamentals with deep experience in network security, including Cloud Networking (GCP/AWS), Palo Alto Networks firewalls, GlobalProtect VPN and Prisma Access. The engineer will lead technical delivery for firewalls, remote access, SASE, network segmentation, cloud network security, DNS security, and automation.
What You’ll Do
Design, implement, and support Google Cloud Platform or similar Cloud network-security solutions, including VPC architecture, Cloud NGFW, Palo Alto VM-Series firewalls, routing, segmentation, ingress and egress controls, NAT, and centralized logging.
Design, deploy, configure, and support next-generation firewalls across data centers, retail locations, internet edge, B2B partner connectivity, remote access, and cloud environments.
Own the firewall-policy lifecycle, including intake, design review, implementation, validation, documentation, periodic rule recertification, and decommissioning of obsolete rules.
Lead hardware refreshes, software upgrades, migrations, and platform consolidations with minimal business impact.
Troubleshoot complex firewall, connectivity, routing, NAT, application, and performance issues using logs, packet captures, traffic-flow analysis, and monitoring tools.
Design, implement, and support GlobalProtect VPN and Prisma Access services for secure remote-user connectivity.
Drive the transition toward Zero Trust access controls, SSL decryption, consistent security policy enforcement, and secure direct internet access.
Troubleshoot remote-user connectivity, application performance, authentication, voice and video quality, routing, and security-policy issues across GlobalProtect and Prisma Access.
Lead lifecycle management, upgrades, capacity planning, resiliency testing, and operational improvements for remote-access and SASE platforms.
Serve as an escalation resource for major network incidents, participate in the on-call rotation, support front-line operations teams with complex issues, lead root-cause analysis, and implement corrective actions to prevent recurrence.
What Skills You Have
Required
5+ years of network security experience in large-scale, complex enterprise, or high-traffic global environments.
Strong understanding of networking concepts and protocols (e.g., TCP/IP, BGP, EIGRP, OSPF, VLANs, DNS/DHCP)
Hands-on experience with Palo Alto Networks firewalls, Panorama, GlobalProtect VPN, and Prisma Access.
Strong understanding of remote-access VPN, SASE, Zero Trust Network Access, IPsec VPN, identity integration, and security-policy design.
Strong experience with Google Cloud Platform or similar cloud networking and security, including VPCs, firewall policies, Cloud NGFW or third-party cloud firewalls, Cloud VPN, Cloud Interconnect, Cloud Router, BGP, Cloud DNS, and load balancing.
Experience troubleshooting GlobalProtect and Prisma Access issues using firewall logs, Prisma Access logs, packet captures, routing data, and end-user experience metrics.
Experience designing secure connectivity for remote users, retail locations, cloud environments, data centers, and third-party partners.
Preferred
Palo Alto Networks certifications such as PCNSA, PCNSE, or Prisma Access certification.
Cisco certifications such as CCNA, CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, or CCIE Security.
CISSP or equivalent security certification.
Experience with Cisco routing, switching, Cisco ACI, SD-WAN, and enterprise data-center networking.
Experience with Prisma Access, SASE, ZTNA, ADEM, and identity-based access controls.
Experience with FireMon or similar firewall policy-management and compliance platforms.
Experience supporting PCI DSS or another regulated environment.