MUST BE ABLE TO WORK ONSITE IN HAUPPAGUE, NY ON LONG ISLAND.
Our client is at the forefront of engineering and implementing leading-edge technological solutions to fuel growth, innovation and better customer service for government clients. We have been serving a variety of public and private sector businesses and organizations in efficient, effective digital transformation from design through development to maintenance.
We need a Palo certified engineer that can work 35 hours a week on site at Suffolk for Firewall management. This is going to be 6-12 month renewable contract.
Daily Tasks
- Monitor firewall and Panorama system health (CPU, memory, sessions, interfaces)
- Review system and threat logs for anomalies and critical alerts
- Validate High Availability (HA) status and synchronization
- Ensure successful log forwarding to SIEM/logging systems
- Review and respond to service requests and incident tickets
Weekly Tasks
- Analyze traffic trends, application usage, and bandwidth consumption
- Review and tune firewall policies for optimization and security posture
- Validate content and signature updates (Threat, Apps, WildFire, URL filtering)
- Conduct rulebase hygiene (identify unused, redundant, or overly permissive rules)
- Provide weekly operational reporting
Monthly Tasks
- Perform comprehensive firewall health and performance review
- Analyze threat trends and provide actionable recommendations
- Validate licensing and subscription status
- Review SSL decryption coverage and effectiveness
- Update documentation (runbooks, diagrams, configurations)
- Deliver monthly executive report and recommendations
As-Needed Tasks
- Implement firewall policy changes and configuration updates
- Support incident response and troubleshooting activities
- Perform packet capture and deep traffic analysis
- Participate in change management processes (CAB approvals)
- Assist with audit requests and compliance validation
- Provide recommendations for architecture improvements
11.2 Required Technical Experience
The assigned engineer must demonstrate the following minimum experience and qualifications:
Core Requirements
- Minimum 5+ years of hands-on experience with Palo Alto Networks NGFW
- Strong experience with Panorama centralized management
- Deep knowledge of:
- App-ID, User-ID, and Content-ID
- Security policies and NAT configurations
- Zone-based firewall architecture
Security & Threat Expertise
- Experience analyzing:
- Threat logs (malware, exploits, C2 traffic)
- WildFire analysis and verdicts
- DNS Security and URL filtering events
- Understanding of:
- Network security principles
- Threat detection and response workflows
Networking & Troubleshooting
- Strong understanding of:
- TCP/IP, routing, switching, and VLANs
- VPN technologies (IPSec and GlobalProtect)
- Experience with:
- Packet capture tools
- CLI-based troubleshooting
- Session-level traffic analysis
Operational & Process Experience
- Experience working within:
- Change management processes (CAB)
- Incident management workflows
- ITSM/ticketing systems
- Ability to:
- Document configurations and procedures
- Produce operational and executive-level reports
Certifications (Preferred)
- Palo Alto Networks Certified Network Security Engineer (PCNSE) – Preferred
- Other relevant certifications (e.g., Security+, CISSP) – Beneficial
11.3 Soft Skills & Professional Requirements
- Strong communication skills (technical and non-technical)
- Ability to work independently and within a team environment
- Strong analytical and problem-solving skills
- Ability to prioritize tasks in a dynamic operational environment
- Professional demeanor suitable for public sector engagement