Palo Alto Firewall Engineer - Lead Solution Advisor
Deloitte’s Cyber Risk Services helps our clients to be secure, vigilant and resilient in the face of an ever increasing array of cyber threats and vulnerabilities. Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions, using proven methodologies and tools in a consistent manner. Our services help organizations to address in a timely manner, pervasive issues such as identity theft, data security breaches, data leakage, cyber security, and system outages across organizations of various sizes and industries, with the goal of enabling ongoing, secure, and reliable operations across the enterprise.
Deloitte’s Cyber Risk Services have been recognized as a leader by a number of independent analyst firms. Kennedy Consulting Research & Advisory, a leading analyst firm, recently named Deloitte a global leader in cyber security consulting. Source: Kennedy Consulting Research & Advisory; Cyber Security Consulting 2013; Kennedy Consulting Research & Advisory estimates © 2013 Kennedy Information, LLC. Reproduced under license.
The Team
Vigilant Cyber Threat Management, provides on-site Consulting and Managed services that help IT security teams better defend and enable today’s dynamic business by refining and extending the security information and event management infrastructure. Vigilant Cyber Threat Management empowers customers to more efficiently respond to shifting threats, achieve regulatory compliance, and prioritize protection of services that drive revenue and competitive advantage, and measure progress of the overall IT risk management program.
Work you’ll do
- Implement Palo Alto Firewalls according to the best practices
- Operational tasks such as Level 2 & 3 on-call technical support for the Palo Alto Firewall Engineering; including assisting client with issues and escalation
- Provide technical support during implementations and troubleshoot issues
- Configuring VLANs/routing/NATing with the Palo Alto Firewalls as per the design
- Provide VPN management and administration. Configuring Site to Site VPNs, Zoning Failover, defining and managing the Firewall policies
- Responsible for designing and deploying various network security & High Availability features in Palo Alto Firewalls
- Understanding migration of Cisco ASA configuration to Palo Alto
- Administer the process and review, approve and execute policy change requests
- Plan and conduct software & firmware upgrades as needed
- Design and provide guidance on areas around network security and secure enterprise network architecture, providing solution inputs and help identifying the security controls for enterprise networks
Qualifications
Required:
- Candidate should have 5-7 years’ experience with Palo Alto Firewall implementation and troubleshooting expertise
- Experience with Panorama Firewall Administration, Rule Analysis, Rule Modification
- Expertise in packet analysis and network traffic flow identification
- Fast troubleshooting and problem-solving skills on Palo Alto
- Ability to analyze network packet traces (PCAP)
- Knowledge on implementing, administering and maintaining IPSec Site-to-Site VPNs. Implementation of the VPN includes: Internet Key Exchange Policy using DES and SHA for encryption and authentication, access-lists to define VPN traffic
- Understanding and implementation of network traffic analysis, remote access methods and systems, stateful inspection firewalls, encryption, authentication and authorization technology
- Hands-on technical experience working with VPN technologies (IPSEC, SSL VPN, WebVPN, AnyConnect, DMVPN, etc.). Experience in implementing Split tunneling on VPN’s
- Experience in Palo Alto/Cisco ASA Firewalls on Stateful inspection, and Global rule base, address spoofing
- Proficient understanding of IT infrastructure and security
- Proficient understanding of relevant security technologies, such as malware management, network forensics, flow analysis, IDS/IPS, etc
- Experience developing reports for software and version compliance
- Ability to suggest/recommend remediation to stakeholders, including executives, risk and security team members
- Ability to provide documentation and analytical skills; documenting processes, policies and standards
- Effective written and communication skills
- Basic understanding of Industry standards in operations such as ITIL processes (e.g. Change Management, Configuration Management, Problem Management, Incident Management), SixSigma standards etc.
Preferred:
- Firewall certifications such as Palo Alto Networks Accredited Configuration Engineer (ACE),Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional (CCNP)
- Should have played a lead role in client engagements