Shell
Website:
shell.com
Job details:
What’s the role?
The Palo Alto Firewall Operations Engineer is responsible for operating, securing, and optimizing enterprise firewall infrastructure across on-prem and cloud environments. This role requires strong expertise in network security, firewall policy management, troubleshooting, automation, and ITSM operations, ensuring high availability and compliance with enterprise security standards.
What you’ll be doing?
Palo Alto Firewall Operations
- Administer, maintain, and optimize Palo Alto Networks Next-Generation Firewalls (PA-Series, VM-Series) and Panorama management platform.
- Monitor firewall health, traffic logs, threat logs, and system performance to ensure operational stability and security.
- Configure, implement, update, and maintain firewall security policies and rules.
- Troubleshoot firewall, connectivity, GlobalProtect, security policy, and configuration-related issues.
- Manage Panorama templates, device groups, and configuration deployments across firewall environments.
- Ensure high availability (HA) configurations and failover readiness.
- Drive continuous improvements to reduce Mean Time to Resolution (MTTR) for firewall-related incidents.
- Maintain an optimized policy framework by identifying and removing redundant, obsolete, or unused rules.
- Enhance operational efficiency through automation of firewall management processes.
Network Security Management
- Implement and enforce security controls based on least-privilege access principles and application-aware security policies.
- Analyze network traffic patterns and application usage using App-ID, User-ID, and firewall logs.
- Manage security policies, URL filtering, threat prevention profiles, and GlobalProtect portals and gateways.
- Support SSL/TLS decryption, certificate lifecycle management, and secure communications.
- Collaborate with network, identity and access management (IAM), cloud, and security teams to ensure seamless connectivity and security.
- Monitor, investigate, and respond to security alerts, vulnerabilities, and incidents.
- Ensure firewall security services, including Threat Prevention, Antivirus, Anti-Spyware, and WildFire, remain current and effective.
- Support audit, compliance, and risk management requirements through reporting and security reviews.
- Assist with incident investigations and forensic analysis leveraging firewall logs and security telemetry.
Automation & Integration
- Utilize Palo Alto APIs and Panorama automation capabilities to streamline administrative processes.
- Manage firewall infrastructure using Infrastructure as Code (IaC) tools such as Terraform and GitHub.
- Develop automation solutions for rule lifecycle management, policy reviews, reporting, and operational workflows.
- Create and maintain scripts using Python and PowerShell to improve efficiency and consistency.
- Integrate firewall event and log data with SIEM platforms such as Microsoft Sentinel.
- Support automation of certificate renewals and SSL/TLS lifecycle management.
IT Service Management (ITSM)
- Manage incidents, service requests, and change activities in accordance with ITIL best practices.
- Perform incident triage, prioritization, troubleshooting, and Root Cause Analysis (RCA).
- Participate in change management reviews and risk assessments for firewall-related changes.
- Maintain accurate technical documentation, standard operating procedures (SOPs), and knowledge articles.
- Ensure compliance with service level agreements (SLAs), audit requirements, and operational standards.
Monitoring, Reporting & Continuous Improvement
- Monitor firewall performance, throughput, session utilization, and capacity metrics.
- Analyze policy usage, rule effectiveness, and rule hit counts to identify optimization opportunities.
- Generate and present reports on security posture, threat trends, compliance status, and policy optimization.
- Recommend and implement improvements to strengthen security, scalability, operational efficiency, and reliability.
What we need from you?
Technical Skills & Experience
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related field.
- 3-5 years proven hands-on experience supporting Palo Alto Networks Next-Generation Firewalls (PA-Series and VM-Series).
- Experience administering and managing Palo Alto Panorama in enterprise environments.
- Strong understanding of TCP/IP networking, routing, NAT, VPN technologies (IPSec and SSL VPN), and network security concepts.
- Deep knowledge of Palo Alto security technologies, including App-ID, User-ID, URL Filtering, Threat Prevention, and GlobalProtect.
- Experience managing SSL/TLS certificates, decryption policies, and certificate lifecycle processes.
- Strong understanding of firewall policy lifecycle management, governance, and compliance controls.
- Experience with automation, scripting, APIs, and Infrastructure as Code (IaC) methodologies.
- Familiarity with ITSM platforms and processes, including ServiceNow and ITIL frameworks.
- Strong analytical, troubleshooting, and problem-solving skills.
Preferred Qualifications
- Experience with SIEM platforms such as Microsoft Sentinel or Splunk.
- Experience working in large-scale enterprise firewall environments.
- Exposure to cloud platforms, including Microsoft Azure and AWS.
- Familiarity with automation tools, workflow orchestration, and API integrations.
- Knowledge of security operations, incident response, and forensic analysis practices.
Preferred Certifications:
- Palo Alto Networks Certified Network Security Administrator (PCNSA)
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- ITIL Foundation or Intermediate Certification
- Microsoft Azure Fundamentals / Associate Certification
- AWS Cloud Practitioner or Associate-level Certification
Disclaimer: This position is advertised as a Network & Security Engineer role. However, upon hire, your official job title will be Systems Engineer.
Click on Apply to know more.