Axis Technologies is seeking an experienced Palo Alto Network Security Engineer to lead and support critical network security efforts in their transition to public cloud infrastructure. This role involves migrating Zscaler security policies to Palo Alto firewalls and implementing data-center-extension wave rules in collaboration with various teams.
Responsibilities:
- Lead efforts to migrate existing security policies from Zscaler to Palo Alto firewalls, ensuring a seamless transition before the end of the year
- Analyze current URL filtering policies and implement strategies to optimize and conserve URL category usage, specifically to remain within the 500 URL category limit per vsys
- Collaborate with network, security, and cloud teams to align policies with organizational security standards and cloud migration goals
- Develop and maintain detailed documentation of migration processes, configurations, and adjustments
- Partner with SYF PerDef to identify, develop, and implement necessary wave rules required for data center extension to the cloud
- Work closely with application teams to test and validate wave rules, ensuring minimal disruption and performance impact
- Maintain ongoing management and tuning of Palo Alto firewall policies based on application requirements and evolving threat landscape
- Manage, optimize, and troubleshoot Palo Alto firewall policies across on-premises and cloud environments
- Provide technical guidance to security and network teams regarding Palo Alto best practices, performance, and feature utilization
Requirements:
- Extensive hands-on experience (5+ years) with Palo Alto Networks firewall administration and policy management in enterprise environments
- Proven experience in migrating security policies from Zscaler to Palo Alto or similar firewall migration projects
- Strong understanding of Palo Alto URL Filtering capabilities and constraints, especially managing URL categories and vsys limits
- Experience working with data center security extension concepts including wave rules or similar traffic segmentation controls
- Solid knowledge of network security architecture, VPNs, routing, and cloud network integration, preferably with AWS or other public clouds
- Ability to collaborate effectively with application teams and other stakeholders during rule implementation and testing phases
- Excellent troubleshooting and problem-solving skills in firewall policy conflicts and rule optimization
- Strong communication skills and ability to produce clear technical documentation
- Palo Alto Networks certifications such as PCNSE (Palo Alto Networks Certified Network Security Engineer)
- Experience in financial services or similarly regulated environments
- Familiarity with Infrastructure as Code (IaC) tools for automating firewall policy deployment
- Exposure to cloud network security frameworks supporting public cloud migrations