Unknown Company

Network Security Engineer

denver, co • Posted Yesterday
Remote Full Time IT & Technology

Network Security Engineer — Juniper to Palo Alto Migration

Enterprise Engineering (EE) — Customer Migration Engagement

Location: Denver, CO (hybrid — 3 days onsite / 2 days remote)

Role Description (Job Summary)

We are seeking an experienced Network Security Engineer to support a customer team migrating from Juniper SRX to Palo Alto Networks Next-Generation Firewalls (NGFW). This is a hybrid engagement based in the Denver area, requiring three days per week onsite at the customer location and two days remote.

The ideal candidate has hands-on experience performing Juniper-to-Palo Alto migrations and can translate legacy Juniper configurations into Palo Alto best practices, while operating confidently in large-scale, service provider-grade environments.

Your Impact (Responsibilities)

  • Lead and support the migration of firewall infrastructure from Juniper SRX to Palo Alto NGFW
  • Translate existing Juniper configurations into Palo Alto best-practice architectures
  • Redesign legacy port/protocol-based security policies into application-aware security policies
  • Configure and operate Security Policies, NAT Policies, Application-ID, User-ID, Content-ID, and Zone-Based Security
  • Integrate Palo Alto firewalls into complex service provider routing environments, including MPLS, EVPN/VXLAN, and large-scale IP transit architectures
  • Deploy Palo Alto NGFWs in active/passive and active/active high availability architectures
  • Implement advanced threat prevention capabilities, including IPS, Anti-Malware, URL Filtering, DNS Security, and WildFire
  • Perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
  • Use Strata Cloud Manager (SCM) for centralized management, templates, device groups, policy management, and operational workflows
  • Lead cutovers during maintenance windows, minimizing customer impact and ensuring rapid rollback capability if required
  • Follow strong change management processes appropriate to large enterprise or service provider environments
  • Mentor customer engineers on Palo Alto operational best practices following migration
  • Communicate complex technical concepts clearly to both engineering and leadership audiences

Your Experience (Qualifications)

  • Experience performing a Juniper SRX to Palo Alto NGFW migration is strongly preferred
  • Expertise with Palo Alto Networks NGFW architecture, deployment, and operations in large-scale environments (service provider experience is a plus)
  • Knowledge of Juniper architecture and the ability to translate Juniper configurations into Palo Alto best practices
  • Advanced understanding of Security Policies, NAT Policies, Application-ID, User-ID, Content-ID, and Zone-Based Security
  • Strong knowledge of dynamic routing protocols including BGP, OSPF, IS-IS, static routing, route redistribution, and ECMP
  • Experience integrating Palo Alto firewalls into complex service provider routing environments with MPLS, EVPN/VXLAN, and large-scale IP transit architectures
  • Experience deploying Palo Alto NGFWs in active/passive and active/active high availability architectures
  • Experience implementing advanced threat prevention capabilities including IPS, Anti-Malware, URL Filtering, DNS Security, and WildFire
  • Ability to perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
  • Experience with SCM (Strata Cloud Manager) for centralized management, templates, device groups, policy management, and operational workflows

Key Competencies (Preferred / Other Qualifications)

  • Ability to lead cutovers during maintenance windows while minimizing customer impact and ensuring rapid rollback if required
  • Strong understanding of change management processes within large enterprise or service provider environments
  • Ability to mentor customer engineers on Palo Alto operational best practices following migration
  • Excellent communication skills, with the ability to translate complex technical concepts for both engineering and leadership audiences
  • Familiarity with cloud integrations (AWS, Azure, GCP) and hybrid network security architectures is a plus
  • Comfortable working in a hybrid onsite/remote schedule with a customer-embedded team

Education

No specific degree requirement is mandated. Relevant industry certifications (e.g., Palo Alto Networks PCNSE, JNCIA/JNCIS, or equivalent NGFW/routing certifications) are a plus and may be considered alongside equivalent hands-on professional experience.

#J-18808-Ljbffr

Network Security Engineer in denver at Unknown Company

This position is listed as full time and able to be worked remotely.

Back to Job Search