Koniag Government Services

Sr Palo Alto Integration Engineer

Koniag Government Services$120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in network security engineering with a focus on Palo Alto Networks products.
  • Active security clearance or ability to obtain one relevant to federal work.
  • Extensive knowledge of Zero Trust security principles and Federal cybersecurity compliance.
  • Expertise in enterprise architecture and engineering of Palo Alto Networks solutions including NGFW, Prisma, and Cortex.
  • Proven ability to lead technical teams and mentor junior engineers in security best practices.
  • Fluency in designing and deploying comprehensive security policy frameworks across multi-environment setups.

Responsibilities

  • Lead the architecture and engineering of Palo Alto Networks security solutions across diverse environments.
  • Develop and maintain detailed security architecture documentation relevant to enterprise Palo Alto Networks deployments.
  • Conduct security architecture reviews, assessing impacts of changes and recommending improvements.
  • Implement Zero Trust security architectures using Palo Alto capabilities, ensuring compliance with security regulations.
  • Mentor junior engineers and provide expert guidance on security engineering best practices.
  • Manage the lifecycle and optimization of Next-Generation Firewall policies and configurations, ensuring strong security posture.

Benefits

  • Flexible work environment with options for remote and telework.
  • Professional development opportunities for career growth.
  • Supportive and collaborative team culture focusing on innovation.
  • Engagement with cutting-edge technologies in network security.
Full Job Description
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Palo Alto Integration Engineer (Senior) to support enterprise network security operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.

This role serves as a critical senior technical function responsible for the architecture, engineering, implementation, administration, and continuous improvement of enterprise Palo Alto Networks security platform capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, and hybrid network environments.

The ideal candidate is a highly experienced and technically authoritative network security engineer with deep, hands-on expertise across the full Palo Alto Networks portfolio-including Next-Generation Firewalls (NGFW), Panorama, Prisma Access, Prisma Cloud, Cortex XDR, and related platforms-combined with a comprehensive understanding of enterprise network security architecture, Zero Trust principles, and Federal cybersecurity compliance requirements. This individual must possess the technical depth, architectural vision, and operational discipline required to lead the design, implementation, and sustained operation of enterprise-grade Palo Alto Networks security capabilities that protect Government networks, systems, and data in a highly regulated federal IT environment.

The Palo Alto Integration Engineer (Senior) will serve as the program's primary subject matter expert and technical authority for all Palo Alto Networks platform capabilities, leading the architecture, engineering, implementation, administration, and continuous improvement of enterprise Palo Alto Networks security infrastructure. This individual works closely with network engineers, security engineers, cloud operations teams, DevSecOps engineers, cybersecurity leadership, and Government stakeholders to ensure Palo Alto Networks platforms are architected, deployed, and operated in a manner that delivers maximum security value, operational resilience, and compliance with Federal cybersecurity frameworks and Zero Trust Architecture objectives across the full enterprise environment.

Principal responsibilities will include but are not limited to:

Architecture & Engineering Leadership
  • Serve as the program's technical authority and subject matter expert for all Palo Alto Networks platform capabilities, providing authoritative architectural guidance, engineering leadership, and expert technical recommendations to program leadership, functional teams, and Government stakeholders.
  • Lead the design and architecture of enterprise Palo Alto Networks security solutions, including NGFW deployments, Panorama management infrastructure, Prisma Access SASE implementations, Prisma Cloud security posture management, and Cortex XDR endpoint and network detection capabilities.
  • Develop and maintain enterprise Palo Alto Networks architecture documentation, including network security architecture diagrams, data flow diagrams, firewall zone models, security policy frameworks, and platform configuration baselines, ensuring documentation is current, accurate, and aligned with operational reality.
  • Lead security architecture reviews for new systems, applications, infrastructure changes, and cloud migrations, assessing Palo Alto Networks platform impact, identifying security risks, and recommending policy and configuration changes to maintain security posture.
  • Design and implement Zero Trust network security architectures leveraging Palo Alto Networks capabilities, including App-ID based application control, User-ID based identity-aware policy enforcement, micro-segmentation, encrypted traffic inspection, and continuous threat prevention.
  • Evaluate emerging Palo Alto Networks technologies, platform capabilities, and industry security trends, providing well-researched recommendations to program leadership and Government stakeholders on opportunities to enhance security posture and operational efficiency.
  • Provide senior technical leadership and mentorship to junior and mid-level network security engineers, sharing expertise, guiding technical development, and ensuring consistent application of security engineering best practices across the team.

Next-Generation Firewall Engineering & Administration
  • Lead the engineering, implementation, and administration of enterprise Palo Alto Networks Next-Generation Firewall (NGFW) infrastructure across all deployment contexts, including perimeter, internal segmentation, data center, and cloud-attached firewall deployments.
  • Design, implement, and maintain comprehensive NGFW security policy frameworks, including application-based policies using App-ID, user-based policies using User-ID, content inspection policies using Content-ID, and threat prevention policies, ensuring policies are well-structured, consistently applied, and aligned with least-privilege access control principles.
  • Implement and maintain advanced NGFW security profiles, including antivirus, anti-spyware, vulnerability protection, URL filtering, file blocking, WildFire malware analysis, and DNS security profiles, ensuring profiles are tuned to maximize threat prevention effectiveness while minimizing operational disruption.
  • Design and implement SSL/TLS decryption policies, ensuring encrypted traffic is inspected in accordance with security requirements while managing certificate trust, performance impact, and privacy considerations.
  • Manage NGFW security policy lifecycle, including policy review and optimization cycles, rule base cleanup, shadow rule identification, and policy documentation maintenance, ensuring the rule base remains clean, efficient, and security-effective over time.
  • Conduct regular NGFW security policy audits and optimization reviews, identifying overly permissive rules, unused policies, and policy gaps, and implementing improvements to strengthen network segmentation and least-privilege access enforcement.
  • Develop and maintain NGFW operational runbooks, troubleshooting guides, and standard operating procedures, ensuring the team has the documentation needed to operate and maintain NGFW infrastructure reliably and consistently.

Panorama Management Platform Engineering
  • Lead the engineering, implementation, and administration of the Panorama centralized management platform, ensuring Panorama is properly configured, maintained, and leveraged to provide consistent, scalable, and auditable management of all deployed NGFW and related platform instances.
  • Design and maintain Panorama device group and template hierarchies, ensuring management configurations are logically organized, consistently applied, and aligned with enterprise security policy requirements and operational management needs.
  • Develop and maintain Panorama-based policy management frameworks, including shared policy structures, pre-rules, post-rules, and device group-specific policy configurations, ensuring policy management is efficient, consistent, and auditable.
  • Implement and maintain Panorama role-based administration controls, ensuring administrative access privileges are properly configured and aligned with least-privilege principles and applicable Federal security requirements.
  • Support Panorama platform upgrades, patches, and configuration changes, coordinating with the change management process and ensuring all changes are properly tested, documented, and approved prior to production implementation.
  • Leverage Panorama logging and reporting capabilities to develop operational dashboards, security reports, and compliance evidence artifacts that support program leadership and Government stakeholder visibility requirements.

Prisma Access & SASE Engineering
  • Lead the engineering, implementation, and administration of Palo Alto Networks Prisma Access Secure Access Service Edge (SASE) capabilities, ensuring secure, reliable, and high-performance remote access and cloud-delivered security services for distributed users and locations.
  • Design and implement Prisma Access GlobalProtect configurations, including gateway deployments, agent configurations, split tunneling policies, and authentication integrations, ensuring remote users receive consistent security policy enforcement regardless of location.
  • Configure and maintain Prisma Access security policy, threat prevention, URL filtering, and data loss prevention capabilities, ensuring cloud-delivered security services provide comprehensive protection aligned with enterprise security requirements.
  • Support the integration of Prisma Access with enterprise identity platforms, including Microsoft Entra ID and Okta, ensuring identity-aware security policy enforcement and multi-factor authentication are consistently applied for all remote access scenarios.
  • Monitor Prisma Access service health, performance, and security effectiveness, proactively identifying and resolving connectivity issues, performance degradation, and security policy gaps that may impact remote user experience or security posture.

Prisma Cloud Security Engineering
  • Lead the engineering, implementation, and administration of Palo Alto Networks Prisma Cloud cloud security posture management (CSPM) and cloud workload protection (CWPP) capabilities across enterprise cloud environments, including AWS and Microsoft Azure Government.
  • Configure and maintain Prisma Cloud compliance frameworks, security policies, and alert configurations, ensuring continuous visibility into cloud security posture, configuration compliance, and threat activity across all monitored cloud accounts and workloads.
  • Develop and maintain Prisma Cloud custom compliance policies and security alerts aligned with applicable Federal security frameworks, including NIST SP 800-53, FedRAMP, CIS Benchmarks, and client-specific cloud security requirements.
  • Integrate Prisma Cloud findings with the enterprise SIEM platform and vulnerability management program, ensuring cloud security posture data is incorporated into the program's broader security monitoring and remediation workflows.
  • Support cloud security posture remediation activities, working with cloud operations teams to prioritize and remediate Prisma Cloud findings in accordance with defined risk-based remediation timelines.

Cortex XDR Engineering & Administration
  • Lead the engineering, implementation, and administration of Palo Alto Networks Cortex XDR extended detection and response capabilities, ensuring the platform provides comprehensive endpoint, network, and cloud telemetry integration and high-fidelity threat detection across the enterprise environment.
  • Configure and maintain Cortex XDR prevention policies, behavioral threat protection rules, and detection analytics, ensuring endpoint protection and detection capabilities are optimized for the enterprise environment.
  • Develop and maintain Cortex XDR detection rules, behavioral analytics configurations, and BIOC (Behavioral Indicators of Compromise) content, aligned with the MITRE ATT&CK framework to ensure comprehensive coverage of relevant adversary TTPs.
  • Integrate Cortex XDR with the enterprise SIEM platform, threat intelligence feeds, and SOAR capabilities, ensuring XDR telemetry and alerts are effectively incorporated into the program's broader security monitoring, detection, and response workflows.
  • Conduct Cortex XDR alert triage, investigation support, and threat hunting activities, leveraging XDR telemetry to support incident response efforts and proactively identify undetected threats within the enterprise environment.
  • Monitor Cortex XDR platform health, agent coverage, and detection output quality, proactively identifying and resolving platform issues, coverage gaps, and detection fidelity problems.

Threat Prevention & Security Effectiveness
  • Lead the continuous improvement of threat prevention effectiveness across all Palo Alto Networks platforms, including regular review and optimization of threat prevention profiles, WildFire submission policies, DNS security configurations, and URL filtering policies.
  • Develop and maintain WildFire integration configurations, ensuring unknown files and URLs are automatically submitted for analysis and that WildFire verdicts are effectively operationalized within NGFW and Cortex XDR security policies.
  • Monitor and analyze threat prevention logs, WildFire analysis results, and threat intelligence feeds to identify emerging threat patterns, new attack techniques, and opportunities to improve prevention effectiveness.
  • Support purple team and detection validation activities, coordinating with threat emulation efforts to validate Palo Alto Networks prevention and detection effectiveness and identify gaps requiring configuration improvements or policy updates.
  • Develop and maintain threat prevention effectiveness metrics and reporting, providing program leadership and Government stakeholders with accurate visibility into prevention coverage, blocked threats, and security effectiveness trends.

Change Management & Operations
  • Lead the preparation and submission of Palo Alto Networks change requests for Change Advisory Board (CAB) review, developing comprehensive implementation plans, technical impact assessments, rollback procedures, and test plans for all significant platform changes.
  • Coordinate with the change management process to ensure all Palo Alto Networks platform changes are properly reviewed, approved, scheduled, and implemented without degradation to security posture or service availability.
  • Conduct post-implementation reviews for significant Palo Alto Networks platform changes, documenting outcomes, unexpected impacts, and lessons learned to continuously improve the change execution process.
  • Develop and maint

About Koniag Government Services

Koniag Government Services Careers

Join the dynamic team at Koniag Government Services, a leader in providing innovative solutions to government clients. This esteemed company offers a plethora of job opportunities that pave the way for professional growth and career advancement in a diverse and inclusive environment.

Explore Career Opportunities

Koniag Government Services is actively hiring and offers a range of positions that cater to various skills and experiences. Whether you're a seasoned professional or a recent graduate, Koniag Government Services provides a platform to enhance your career through meaningful work in a supportive culture.

Innovation and Leadership

At the forefront of innovation, Koniag Government Services encourages its team to lead with creativity and strategic thinking. The company is committed to leadership development and diversity training, ensuring that all team members have the opportunity to excel and contribute to industry-leading projects.

Professional Growth and Development

Koniag Government Services is dedicated to the professional development of its employees. With comprehensive benefits, competitive employment packages, and opportunities for advancement, the company supports its team in achieving their career goals. Networking within the company and industry is encouraged, fostering a community of learning and mutual growth.

Internship Programs

For those starting their career journey, Koniag Government Services offers internship programs that provide real-world experience and a pathway to full-time employment. Interns gain valuable industry knowledge and develop essential skills under the guidance of experienced mentors.

Commitment to Diversity and Inclusion

Diversity is at the core of Koniag Government Services' values. The company is committed to creating an inclusive environment where diverse voices are heard and valued. Diversity training is integral, equipping the team with the tools to thrive in a multicultural setting.

Applying for a Position

To apply for a position at Koniag Government Services, candidates should prepare a resume that highlights relevant experience and skills. The interview process is designed to assess fit both for the role and the company culture, ensuring alignment with the team’s values and objectives.

Stay Connected with Koniag Government Services Careers

Explore the various job opportunities and embark on a path of professional growth and innovation. Koniag Government Services is not just a workplace but a community where careers flourish in an environment of respect, integrity, and continuous learning.

Search Koniag Government Services Jobs

Discover the exciting career opportunities available at Koniag Government Services. Search for open positions that match your skills and interests, and join a team that values curiosity, creativity, and collaboration.

Keep Up to Date

Stay informed with the latest career tips, industry insights, and company updates directly from Koniag Government Services. Engage with content that can transform your professional journey and lead to rewarding opportunities.

Job Alert Emails

Personalize your subscription to receive job alerts and insider tips tailored to your preferences from Koniag Government Services. See what exciting and rewarding opportunities await in the field of government services.
Learn more about Koniag Government Services
Size
501 employees
Industry

Similar Jobs

More Jobs at Koniag Government Services

  • Koniag Government Services
    SIEM UEBA Engineer Mid
    $95K — $115K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person
  • Koniag Government Services
    Zero Trust Engineer
    $110K — $130K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person
  • Koniag Government Services
    Sr Palo Alto Integration Engineer
    $120K — $145K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • Koniag Government Services
    Sr Palo Alto Integration Engineer
    $120K — $145K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person
  • Koniag Government Services
    Sr Okta IAM Engineer
    $120K — $145K *
    Fort Washington, MD 20744 (Prince Georges County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Sr Palo Alto Integration Engineer jobs: