Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and Transformation
Job Description
This Senior Consultant role sits within Deloitte's Cyber Enterprise Security practice, focusing on modernizing network defense using Palo Alto Networks technologies across on premises and cloud environments, including NGFW, Prisma Access, and SIEM/SOAR integrations. The position is onsite in Costa Mesa, CA, with a salary range of USD 105,400 to 207,800 per year.
Responsibilities
- Design, deploy, and operate Palo Alto Networks Next-Generation Firewalls across on premises and cloud environments, including AWS, Azure, and Google Cloud Platform.
- Implement and optimize Prisma Access components such as GlobalProtect, Prisma Agent, and Prisma Browser to support secure internet access and remote work scenarios.
- Administer Panorama and Strata Cloud Manager to enable centralized policy management, device configuration, visibility, and consistency across enterprise deployments.
- Configure and tune security capabilities including Threat Prevention, IPS/IDS, Anti-Spyware, Antivirus, WildFire, DNS Security, and SSL/TLS decryption policies.
- Develop client solution designs and recommendations, integrating Palo Alto platforms with SIEM/SOAR and identity provider tools, and enabling automation through Terraform, Ansible, or Python.
Requirements
- BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology, or equivalent work experience).
- PCNSE (Palo Alto Networks Certified Network Security Engineer) certification.
- 5+ years of progressive network security engineering experience with demonstrated depth in Palo Alto Networks technologies and increasing levels of technical ownership and leadership.
- 5+ years hands-on experience designing, deploying, and managing Palo Alto Networks NGFW in on premises and cloud environments (AWS, Azure, and/or GCP).
- 3+ years designing, deploying, and managing Prisma Access, including configuration of GlobalProtect, Prisma Agent, and Prisma Browser for Internet and secure remote access use cases.
- 3+ years designing, deploying, and managing Panorama centralized management, and Strata Cloud Manager.
- 3+ years configuring and tuning Palo Alto Threat Prevention features, including IPS/IDS, Anti-Spyware, Antivirus, WildFire, and DNS Security.
- 3+ years implementing and troubleshooting SSL/TLS Decryption policies, including forward proxy and inbound inspection, certificate management, and decryption exclusion handling.
- 3+ years hands-on experience defining, managing, and reviewing security policies, including rule base optimization, policy lifecycle management, and periodic access reviews.
- 3+ years of experience with one or more major cloud service providers (AWS, GCP, Azure) and their native security toolsets, including deployment of VM-Series firewalls within cloud-native architectures.
- Ability to travel up to 50 percent on average, based on client work and industries served.
- Limited immigration sponsorship may be available.
Technologies
- Palo Alto Networks NGFW, AWS, Microsoft Azure, Google Cloud Platform (GCP)
- Prisma Access, GlobalProtect, Prisma Agent, Prisma Browser
- Panorama, Strata Cloud Manager
- Threat Prevention, IPS, IDS, Anti-Spyware, Antivirus, WildFire, DNS Security
- SSL/TLS decryption, Terraform, Ansible, Python
- VM-Series, SIEM, SOAR, Zscaler, Netskope, Okta, Azure AD, Ping Identity, Palo Alto Cloud Identity Engine (CIE), SAML, SCIM
Benefits
- Discretionary annual incentive program
The Team
Our Enterprise Security offering embeds security across digital transformation by protecting a client’s technical backbone while enabling secure innovation. The practice spans security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.