Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and Transformation
Job Description
Deloitte is seeking a seasoned security engineer in New York who brings hands-on experience with Palo Alto Networks technologies to design, deploy, and optimize next-generation firewalls across both on-site and cloud environments. The role focuses on enabling zero-trust secure transformation by integrating NGFWs, Prisma Access, Panorama, and Strata into diverse infrastructures and workflows. This position sits at the intersection of security engineering and client advisory, delivering practical, scalable solutions for complex enterprise ecosystems.
Responsibilities
- Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls across on-premises and cloud platforms including AWS, Azure, and GCP
- Implement and optimize Prisma Access features such as GlobalProtect, Prisma Agent, and Prisma Browser to support secure internet and remote access use cases
- Administer Panorama and Strata Cloud Manager to provide centralized policy control, consistent configuration, and enhanced visibility
- Configure and fine-tune security capabilities such as Threat Prevention, IPS/IDS, Anti-Spyware, Antivirus, WildFire, DNS Security, and SSL/TLS decryption policies
- Develop client-ready solution designs, integrating Palo Alto components with SIEM/SOAR platforms and identity providers, with automation support via Terraform, Ansible, or Python
Required Qualifications
- BA/BS in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience
- PCNSE certification
- 5+ years of progressively responsible network security engineering experience with deep Palo Alto expertise and leadership
- 5+ years designing, deploying, and managing NGFWs in both on-premises and cloud environments (AWS, Azure, and/or GCP)
- 3+ years of hands-on experience with Prisma Access, including configuration of GlobalProtect, Prisma Agent, and Prisma Browser
- 3+ years of experience administering Panorama and Strata Cloud Manager
- 3+ years configuring and tuning Threat Prevention features (IPS/IDS, Anti-Spyware, Antivirus, WildFire, DNS Security)
- 3+ years implementing and troubleshooting SSL/TLS Decryption policies (forward proxy and inbound inspection, certificate management, decryption exclusions)
- 3+ years defining and managing security policies, including rule base optimization and policy lifecycle reviews
- 3+ years working with one or more major cloud providers and deploying VM-Series firewalls within cloud-native architectures
- Ability to travel up to 50% on average
- Limited immigration sponsorship may be available
Preferred Qualifications
- Advanced cybersecurity certifications such as CISSP, CCIE Security, CCNP Security, or GIAC equivalents
- Experience with automation tools (Terraform, Ansible, Python) for provisioning and policy management
- Experience integrating Palo Alto Firewalls and Prisma with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, XSOAR) via log streaming, APIs, or syslog
- Experience designing and presenting Palo Alto network solution architectures tailored to client requirements
- Proven experience in large, complex enterprise environments with strict security, compliance, and availability needs
- Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM in Palo Alto Cloud Identity Engine
- Ability to conduct SASE vendor competitive analyses and advise on solution selections based on use cases
- Experience performing Zero Trust Architecture assessments and roadmaps aligned with NIST SP 800-207 or CISA frameworks
- Prior consulting or Big 4 experience delivering enterprise network security or SASE transformation engagements
The Team
Our Enterprise Security offering embeds security across digital transformation, securing a client’s technical backbone while enabling secure progress. The group covers security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.
Technologies
- Palo Alto Networks NGFW and related platforms
- GlobalProtect, Prisma Access, Prisma Agent, Prisma Browser
- Panorama, Strata Cloud Manager
- Threat Prevention, IPS/IDS, Anti-Spyware, Antivirus, WildFire, DNS Security
- SSL/TLS decryption policies, forward proxy, and inbound inspection
- Terraform, Ansible, Python
- SIEM/SOAR, AWS, Azure, GCP
- VM-Series, Zscaler, Palo Alto Cloud Identity Engine
- Okta, Azure AD, Ping Identity, SAML/SCIM
- Splunk, Microsoft Sentinel, Palo Alto XSOAR