← Back to jobs
Dallas, TX, USA
No related jobs found
Job Description:
Requirements* · Expertise in PAN-OS Security Policies, including rule order, App-ID–based rules, pre-rules vs post-rules, and application-default services. · Experience in policy optimization, cleanup, and implementation of logging best practices (Traffic, Threat, URL, HIP logs). · Strong hands-on experience with GlobalProtect, including Portal vs Gateway, Always-On VPN, split vs full tunneling, HIP profiles, and client troubleshooting.
· Integration of GlobalProtect with SAML and MFA (Azure AD / Okta / Duo). · Solid understanding of IPsec VPN design, including IKEv1 vs IKEv2, crypto profiles, Proxy-ID vs route-based VPNs, and tunnel monitoring. · Proven skills in VPN troubleshooting and monitoring using PAN-OS logs and tools. · Experience configuring HA Active/Passive and exposure to Active/Active (advanced) deployments. · Knowledge of HA interfaces, heartbeat, session synchronization, and state handling. · Hands-on implementation of link and path monitoring, failover scenarios, and controlled HA testing.
Key
Responsibilities* · Design, implement, and manage Palo Alto security policies, ensuring correct rule order, App-ID usage, pre-rules vs post-rules, and application-default services. · Perform policy optimization, cleanup, and enforcement of logging best practices to improve security posture and operational efficiency. · Deploy, configure, and support GlobalProtect Remote Access VPN, including Portal and Gateway, always-On VPN, split/full tunnel designs, HIP profiles, and client issue resolution. · Integrate GlobalProtect authentication with SAML and MFA platforms to ensure secure user access. · Design, implement, and troubleshoot Site-to-Site IPsec VPNs, including IKEv1/IKEv2, crypto profiles, and Proxy-ID vs route-based VPNs. · Monitor and troubleshoot VPN tunnels and traffic flows using PAN-OS logs and diagnostic tools. · Configure and maintain High Availability (HA) setups, including Active/Passive and exposure to Active/Active deployments. · Implement and validate HA interfaces, heartbeat, session synchronization, and state failover behavior. · Configure link and path monitoring and execute failover testing to ensure high availability and resilience. · Provide operational support, root-cause analysis, and documentation for firewall, VPN, and HA-related incident
Role Descriptions: Design| implement| and manage Palo Alto security policies| ensuring correct rule order| App ID usage| pre rules vs post rules| and application default services. Perform policy optimization| cleanup| and enforcement of logging best practices to improve security posture and operational efficiency. Deploy| configure| and support GlobalProtect Remote Access VPN| including Portal and Gateway| always On VPN| split/full tunnel designs| HIP profiles| and client issue resolution. Integrate GlobalProtect authentication with SAML and MFA platforms to ensure secure user access. Design| implement| and troubleshoot Site to Site IPsec VPNs| including IKEv1/IKEv2| crypto profiles| and Proxy ID vs route based VPNs. Monitor and troubleshoot VPN tunnels and traffic flows using PAN OS logs and diagnostic tools. Configure and maintain High Availability (HA) setups| including Active/Passive and exposure to Active/Active deployments. Implement and validate HA interfaces| heartbeat| session synchronization| and state failover behavior. Configure link and path monitoring and execute failover testing to ensure high availability and resilience. Provide operational support| root cause analysis| and documentation for firewall| VPN| and HA related incidents.
Essential Skills: Expertise in PAN OS Security Policies| including rule order| App IDbased rules| pre rules vs post rules| and application default services. Experience in policy optimization| cleanup| and implementation of logging best practices (Traffic| Threat| URL| HIP logs). Strong hands on experience with GlobalProtect| including Portal vs Gateway| Always On VPN| split vs full tunneling| HIP profiles| and client troubleshooting. Integration of GlobalProtect with SAML and MFA (Azure AD / Okta / Duo). Solid understanding of IPsec VPN design| including IKEv1 vs IKEv2| crypto profiles| Proxy ID vs route based VPNs| and tunnel monitoring. Proven skills in VPN troubleshooting and monitoring using PAN OS logs and tools. Experience configuring HA Active/Passive and exposure to Active/Active (advanced) deployments. Knowledge of HA interfaces| heartbeat| session synchronization| and state handling. Hands on implementation of link and path monitoring| failover scenarios| and controlled HA testing.
Desirable Skills: Cloud Architect
Keyword: ~Cloud Architect~
Skills: Digital : Cloud Computing (General)
Experience Required: 10 & Above
Any Graduate
No related jobs found
← Back to jobs