Palo Alto Firewall Engineer / SME (PCNSE)Location: Springfield, VA - on site
Time Type: Full time, Exempt
Clearance Required to Start: Active TS/SCI (U.S. citizenship required)
Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph
Travel: Up to 15%, local and CONUS
Salary Range: $117,000 - $128,000
Own the Palo Alto estate - legacy iron through Prisma and Panorama.RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue.
What You Will Do- Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise.
- Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack.
- Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms.
- Run Panorama for centralized policy management across a fleet of physical and virtual firewalls.
- Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire.
- Own configuration management processes and SOPs for all Palo Alto platforms.
- Mentor junior engineers and act as the escalation point for complex troubleshooting.
- Liaise with contract, customer, and government DAA on network security status, policies, and procedures.
What You'll Bring- U.S. citizenship and an active TS/SCI.
- Ability to successfully obtain and maintain a U.S. Government polygraph.
- Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
- 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments.
- Active PCNSE certification.
- DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start.
- Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement.
- Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP.
- Panorama template and device-group inheritance across a hybrid fleet.
- Advanced BGP, OSPF, IPSec VPN, and NAT.
Nice to Have- PCNSC or Prisma Certified SASE Professional (PCSAE).
- Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs.
- Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy.
- Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA.
BenefitsMedical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.