Palo Alto Subject Matter Expert (SME)

Crimson Phoenix

$135K — $152K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of hands-on experience with Palo Alto Networks NGFWs in large-scale settings.
  • Active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification required.
  • Must be compliant with DoD 8140.01 and DoD 8570.01-M IAT Level II (e.g., Security+ CE).
  • Ability to obtain/maintain a CSSP Infrastructure Support certification within 120 days of starting.
  • Deep knowledge of legacy Gen 2/Gen 3 hardware and practical troubleshooting skills.
  • Experience with modern PAN-OS architectures and cloud environments (AWS, Azure, GCP).
  • Expertise in using Panorama for centralized firewall policy management.

Responsibilities

  • Lead the design and implementation of secure network architectures using Palo Alto Networks products.
  • Oversee the administration and troubleshooting of Palo Alto NGFWs across hybrid environments.
  • Manage the lifecycle of Palo Alto hardware and software, including upgrades and refreshes.
  • Maintain configuration management processes and SOPs for security platforms.
  • Utilize Panorama to manage firewall configurations efficiently across diverse environments.
  • Develop and oversee security incident reporting and documentation processes.
  • Mentor junior engineers and serve as an escalation point for troubleshooting.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • 401(k) plan with company match.
  • Generous paid time off policy.
  • Company-paid life and disability insurance.
  • Tuition reimbursement for professional development.
  • Employee recognition programs and wellness benefits.
Full Job Description
Job Description

As a Palo Alto Subject Matter Expert (SME) on the Network Security Services (NSS) team, you will be the focal point for all Palo Alto-related tasks, operations, and projects. You will work with both corporate and customer leadership to research, analyze, and implement enterprise-wide network security solutions that bridge legacy and next-generation architectures. This role requires a unique blend of deep, hands-on expertise with traditional Gen 2/Gen 3 hardware platforms and modern, cloud-native solutions like Prisma Access (SASE) and Cortex XSOAR. You will provide critical technical oversight, ensuring the stability, security, and modernization of our firewall infrastructure.

Responsibilities

  • Lead the design, analysis, testing, and implementation of state-of-the-art secure network architectures centered on the Palo Alto Networks ecosystem.
  • Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto Networks Next-Generation Firewalls (NGFWs) across a hybrid enterprise environment.
  • Manage the full lifecycle of Palo Alto hardware and software, including executing complex hardware refreshes and PAN-OS upgrades, especially on legacy platforms.
  • Develop, oversee, and maintain configuration management processes and Standard Operating Procedures (SOPs) for all Palo Alto security platforms.
  • Utilize Panorama for centralized policy management, ensuring consistent and efficient configuration across a diverse fleet of physical and virtual firewalls.
  • Configure and maintain master-level security profiles, including App-ID, User-ID, Content-ID, SSL Decryption, and WildFire threat prevention.
  • Oversee the reporting, documentation, and investigation of security-related incidents, and lead the development of corrective measures.
  • Act as a liaison to contract/customer management and the government Designated Approving Authority (DAA) regarding network security status, policies, and procedures.
  • Evaluate and report on new and emerging network security technologies to enhance the capabilities, performance, and reliability of the network.
  • Provide mentorship and technical oversight to junior engineers, and act as an escalation point for complex troubleshooting efforts.


Required Skills

  • Experience: A minimum of 7+ years of hands-on experience administering, configuring, and troubleshooting Palo Alto Networks NGFWs in large-scale enterprise/global environments.
  • Certifications:
  • Must hold an active Palo Alto Networks Certified Network Security Engineer (PCNSE) certification.
  • Must be DoD 8140.01 and DoD 8570.01-M IAT Level II compliant (e.g., Security+ CE).
  • Must be able to successfully obtain/maintain a CSSP Infrastructure Support certification within 120 days of the start date.
  • Legacy Systems Management: Deep, practical knowledge of legacy Gen 2/Gen 3 hardware (e.g., PA-3000, PA-5000 series), including legacy CLI, physical hardware troubleshooting, and line-card replacements.
  • Next-Gen & Cloud Security: Direct experience deploying and managing modern PAN-OS architectures, including Prisma Access (SASE), Prisma SD-WAN, and virtual firewalls (VM-Series) in public/private cloud environments (AWS, Azure, or GCP).
  • Centralized Administration: Proven expertise utilizing Panorama for centralized policy management, template/device group inheritance, and pushing configurations across a hybrid fleet.
  • Network Foundations: Advanced understanding of core networking protocols critical to firewall routing and legacy-to-modern transitions, specifically BGP, OSPF, IPSec VPNs, and NAT.
  • Education: Bachelor's degree in a related field (e.g., IT, Cybersecurity, Computer Science). Additional years of relevant experience may be considered in lieu of a degree.


Desired Skills

  • Advanced Certifications: Active Palo Alto Networks Certified Network Security Consultant (PCNSC) or Prisma Certified SASE Professional (PCSAE).
  • Automation & Scripting: Proficiency in Python and experience automating firewall deployment, policy changes, and configuration backups using Ansible, Terraform, or Palo Alto XML/REST APIs.
  • Security Orchestration: Hands-on experience with Cortex XDR or Cortex XSOAR for automated threat response.
  • Migration Tools: Proficiency using Palo Alto Networks Expedition to migrate and consolidate legacy rules to modern App-ID-based policies.
  • Enterprise Architecture: Background in designing Zero Trust Network Access (ZTNA) architectures across complex, segment-isolated enterprise environments.
  • Broader Experience: Experience with other security platforms and technologies such as F5 (APM, AFM), Juniper SRX, and Cisco FTD/ASA.


Additional Details

Compensation & Benefits: This position has an anticipated salary range of $135,000-$152,000 per year. Actual compensation will be determined based on factors including experience, qualifications, skills, education, certifications, and business needs. Crimson Phoenix offers a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) with company match, generous paid time off, company-paid life and disability insurance, tuition reimbursement, professional development opportunities, employee recognition programs, and additional wellness and work-life benefits.

U.S. citizenship and the ability to obtain or maintain a security clearance may be required for certain positions.

Similar Jobs

More Jobs at Crimson Phoenix

More Information Technology Jobs

Find similar Palo Alto Subject Matter Expert (SME) jobs: