We are seeking an expert Subject Matter Expert (SME) to serve as the ultimate technical authority within our Network Security Operations team. This is a pure security engineering, and partial leadership role cantered around four critical pillars: Palo Alto Environments, Zscaler Platform, Web Application Firewalls (WAF), and Public Cloud Security.
As an SME, you will own the entire lifecycle of these platforms leading complex project planning, architectural design, high-risk implementations, and acting as the final escalation tier for operational crises. While a foundational understanding of routing and switching is required to integrate tools, your daily focus is entirely dedicated to safeguarding our perimeter, secure cloud edge, cloud infrastructure, and application layers.
Key Responsibilities:
Architectural Planning, Design & Project Implementation
- High-Level Strategy: Plan and design security topologies across Palo Alto NGFW, Prisma Access, Zscaler (ZIA/ZPA), F5 WAF, and public clouds (AWS/Azure).
- Complex Migrations & Deployments: Lead high-risk greenfield deployments, technical migrations (e.g., legacy VPN to Zscaler/Prisma SASE), and security zone expansions.
- Engineering Documentation: Author and approve high-level designs (HLD), low-level designs (LLD), migration manifests, and fallback procedures.
Security Operations & Escalation (Tier 3+)
- SME Escalation Anchor: Act as the highest technical escalation tier for catastrophic outages, complex traffic drops, and intricate security tool failures.
- Advanced Policy Engineering: Architect and continuously audit global firewall rule bases, WAF signatures, and Zscaler security policies to eliminate false positives and security gaps.
- Threat & Vulnerability Mitigation: Investigate complex application-layer violations, advanced persistent threats, and network perimeter vulnerabilities.
Process, Workflows & Governance
- ITIL Change & Advisory: Serve as a technical validator in corporate Change Management processes, ensuring high-impact policy shifts are risk-assessed and vetted.
- Knowledge & Shift Enablement: Build comprehensive Standard Operating Procedures (SOPs) and technical knowledge bases to seamlessly delegate daily tasks to shift operations teams.
- Lifecycle Management: Monitor vendor roadmaps, product updates, hotfixes, and zero-day advisories to plan global lifecycle upgrades.
Skills
Technical Qualifications
1. Palo Alto Networks & Prisma SASE (Advanced)
- Expert management of Palo Alto Next-Generation Firewalls (NGFW) and centralized orchestration via Panorama.
- Hands-on experience designing, implementing, and troubleshooting Prisma Access for Secure Access Service Edge (SASE) and enterprise GlobalProtect VPN architectures.
- Familiarity with Prisma SD-WAN environments, dashboard monitoring, and configuring traffic steering/app-defined routing rules.
2. Zscaler Cloud Security (SME / Advanced Platform Ownership)
- Expert-level deployment, administration, and architectural knowledge of Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA).
- Deep experience configuration and maintaining Zscaler components: Cloud Connectors, App Connectors, Zscaler Client Connector (ZCC), and central admin consoles.
- Proven ability to configure advanced SSL/TLS inspection, URL filtering, sandboxing, data loss prevention (DLP), and Zero Trust network access (ZTNA) policies.
3. Web Application Firewall (F5 / Azure / AWS WAF)
- Advanced expertise configuring, deploying, and tuning F5 WAF (Advanced WAF / BIG-IP ASM) and cloud-native WAFs.
- Comprehensive understanding of OWASP Top 10 protection strategies, building custom security policies, and diagnosing intricate traffic violations.
4. Cloud Security Firewalls (Moderate)
- Solid experience deploying, configuring, and managing cloud perimeter security tools including Azure Firewall and AWS Network Firewall.
- Strong grasp of cloud-native infrastructure, hub-and-spoke security boundaries, security groups, and cloud routing mechanisms.
5. Infrastructure Foundations (Basic)
- Foundational knowledge of routing and switching (OSPF, BGP, VLANs, and Subnetting) purely to assist with security tool deployment and network integration.
6. Network Foundations:
- Foundational knowledge of routing and switching (OSPF, BGP, VLANs, and Subnetting) purely to assist with security tool deployment and network integration.
7. Process, Workflows & Governance:
- Incident Escalation: Act as the Tier 3 escalation anchor, collaborating closely with L1/L2 monitoring teams and vendor support to resolve critical outages.
- ITIL Change & Release Management: Strictly adhere to corporate Change Management processes, ensuring all firewall and WAF policy changes are thoroughly planned, validated, and documented.
- Knowledge Management: Document complex project implementations, creating Standard Operating Procedures (SOPs) and knowledge base articles to transition day-to-day tasks smoothly to shift operations.
- Platform Lifecycle Maintenance: Proactively track Palo Alto, F5, and cloud-native product updates, software release notes, and security advisories to plan necessary upgrade cycles.
Experience & Soft Skills
- Experience: 7+ years of dedicated experience in network security engineering and operations, with at least 2 years operating as a technical lead or SME.
- Shift Flexibility: Comfortable working in shift rotations or on-call schedules to ensure continuous operations.
- Problem-Solving: Strong analytical mindset to diagnose complex security infrastructure issues under pressure.
Preferred Certifications
- Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer)
- Zscaler: ZCSE (Zscaler Certified Security Engineer) or ZCCA/ZCCP credentials
- WAF: F5-CTS Advanced WAF/ASM (Exam 303)
- Cloud Security: AWS Certified Security - Specialty and/or Microsoft Azure Security Engineer Associate (AZ-500)