Join Deloitte on the Cyber Enterprise Security team in Milwaukee, Wisconsin for an onsite role that centers on modernizing network security through cloud-delivered zero trust architectures and Palo Alto Networks solutions across both on prem and cloud environments. This senior consultant position emphasizes strategy, growth, and transformation, offering a competitive compensation range of USD 105,400 to 207,800 per year and the chance to work with cloud platforms such as AWS, Azure, and Google Cloud Platform.
As part of Deloitte's Enterprise Security practice, you will help clients secure their digital transformations while collaborating across security architecture, secure development, and end-to-end cyber cloud capabilities. The role provides a pathway to leadership through hands-on engineering, design, and advisory work, with an onsite focus and opportunities to impact security programs at scale.
Benefits and opportunities
- Competitive compensation: USD 105,400 – 207,800 per year
- Onsite in Milwaukee, WI with a focus on real-world impact and collaboration
- Work with cloud-delivered security and zero trust architectures across on-premises and cloud environments
- Exposure to major cloud providers including AWS, Azure, and GCP
- Travel flexibility up to 50% to serve diverse clients and industries
- Sponsorship potential for immigration may be available
- Collaborative culture within a team focused on security architecture, secure development and deployment, and cyber cloud capabilities
Responsibilities
- Design, deploy, and operate Palo Alto Networks Next-Generation Firewalls across on-site and cloud environments (AWS, Azure, GCP)
- Implement and optimize Prisma Access offerings, including GlobalProtect, Prisma Agent, and Prisma Browser, for secure internet and remote access
- Administer Panorama and Strata Cloud Manager to enable centralized policy governance, configuration, visibility, and consistency
- Configure and tune security controls such as Threat Prevention, IPS/IDS, Anti-Spyware, Antivirus, WildFire, DNS Security, and SSL/TLS decryption policies
- Develop client-focused designs and recommendations, integrating Palo Alto platforms with SIEM/SOAR and identity providers, and support automation via Terraform, Ansible, or Python
Requirements
- BA/BS in a technical field or equivalent work experience
- PCNSE certification
- 5+ years of progressively responsible network security engineering experience with demonstrated Palo Alto expertise
- 5+ years designing, deploying, and managing Palo Alto NGFWs in both on-prem and cloud environments (AWS, Azure, and/or GCP)
- 3+ years designing, deploying, and managing Prisma Access (GlobalProtect, Prisma Agent, Prisma Browser)
- 3+ years managing Panorama and Strata Cloud Manager
- 3+ years configuring Threat Prevention features (IPS/IDS, Anti-Spyware, Antivirus, WildFire, DNS Security)
- 3+ years implementing and troubleshooting SSL/TLS Decryption policies (forward proxy and inbound inspection, certificate management, decryption exclusions)
- 3+ years defining and managing security policies, including rule optimization and lifecycle reviews
- 3+ years working with one or more cloud providers (AWS, GCP, Azure) and their native security toolsets, including VM-Series deployments
- Ability to travel up to 50% on average
- Limited immigration sponsorship may be available
Technology stack
- Palo Alto Networks NGFW, Prisma Access, GlobalProtect, Prisma Agent, Prisma Browser
- Panorama, Strata Cloud Manager, Threat Prevention, IPS, IDS
- SSL/TLS decryption, DNS Security
- Automation and IaC: Terraform, Ansible, Python
- Cloud platforms: AWS, Azure, GCP; VM-Series in cloud-native architectures
- SOAR/SIEM integrations: Splunk, Microsoft Sentinel, Palo Alto XSOAR
- Identity and access: Okta, Azure AD, Ping Identity, Palo Alto Cloud Identity Engine (CIE)
- Security tooling: Zscaler, Netskope, SAML/SCIM
The team
The Enterprise Security offering at Deloitte embeds security across digital transformation programs, securing technical backbones while enabling secure innovation. The team covers security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and security for emerging technologies and connected products.