Firewall Engineer III

RISA

$117K — $128K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active TS/SCI clearance required with U.S. citizenship
  • Ability to obtain and maintain a U.S. Government polygraph
  • Bachelor's degree plus 6 years relevant experience (equivalents accepted)
  • 7+ years experience configuring and troubleshooting Palo Alto NGFWs
  • Active PCNSE certification essential
  • DoD 8140.01 and 8570.01-M IAT Level II required within 120 days of start
  • In-depth knowledge of legacy PA-3000 and PA-5000 hardware and CLI

Responsibilities

  • Lead administration, configuration, and troubleshooting of Palo Alto NGFWs
  • Design, analyze, test, and implement secure network architectures
  • Manage hardware and software lifecycle, including upgrades and refreshes
  • Run Panorama for centralized policy management of firewalls
  • Configure advanced security profiles for Palo Alto devices
  • Own configuration management and SOPs for all platforms
  • Mentor junior engineers and manage complex troubleshooting efforts

Benefits

  • Medical, dental, and vision insurance
  • 401(k) and Roth retirement options
  • Paid Time Off (PTO)
  • 11 paid Federal Holidays
Full Job Description
Palo Alto Firewall Engineer / SME (PCNSE)

Location: Springfield, VA - on site

Time Type: Full time, Exempt

Clearance Required to Start: Active TS/SCI (U.S. citizenship required)

Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph

Travel: Up to 15%, local and CONUS

Salary Range: $117,000 - $128,000

Own the Palo Alto estate - legacy iron through Prisma and Panorama.

RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue.

What You Will Do
  • Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise.
  • Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack.
  • Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms.
  • Run Panorama for centralized policy management across a fleet of physical and virtual firewalls.
  • Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire.
  • Own configuration management processes and SOPs for all Palo Alto platforms.
  • Mentor junior engineers and act as the escalation point for complex troubleshooting.
  • Liaise with contract, customer, and government DAA on network security status, policies, and procedures.

What You'll Bring
  • U.S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a U.S. Government polygraph.
  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
  • 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments.
  • Active PCNSE certification.
  • DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start.
  • Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement.
  • Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP.
  • Panorama template and device-group inheritance across a hybrid fleet.
  • Advanced BGP, OSPF, IPSec VPN, and NAT.

Nice to Have
  • PCNSC or Prisma Certified SASE Professional (PCSAE).
  • Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs.
  • Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy.
  • Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA.

Benefits

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.

Similar Jobs

More Jobs at RISA

More Information Technology Jobs

Find similar Firewall Engineer III jobs: