Source description
About the role
Design and deploy Cisco Secure Firewall Threat Defense (FTD) managed by Firewall Management Center (FMC), including high-availability pairs, threat policies (Snort IPS, malware defense, URL filtering), and both site-to-site and remote access VPN configurations.
Configure and manage Palo Alto Networks next-generation firewalls running PAN-OS, including security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, WildFire), App-ID, User-ID, SSL/TLS decryption, and centralized management via Panorama.
Lead firewall migration projects including legacy Cisco ASA to FTD conversions, cross-vendor migrations (Check Point, Fortinet, Juniper to Palo Alto or Cisco), and policy translation with rule optimization during cutover.
Design network segmentation architectures using firewall zones, virtual routers, VRFs, and policy-based routing to enforce least-privilege east-west and north-south traffic controls.
Deploy cloud-native firewall solutions including Palo Alto Cloud NGFW for AWS and Azure, and Cisco Secure Firewall Cloud Native for containerized and cloud workload environments.
Implement firewall high availability designs including active/standby failover, active/active clustering, and multi-context deployments for service provider and large enterprise environments.
Configure centralized logging, SIEM integration (Splunk, Microsoft Sentinel, syslog), and NetFlow/IPFIX for traffic analytics, threat correlation, and compliance reporting.
Perform firewall rule base optimization, policy cleanup, and compliance auditing to reduce attack surface and align with regulatory frameworks (PCI-DSS, HIPAA, NIST).
Integrate Cisco Secure Firewall with Cisco XDR for cross-platform threat detection, event correlation, and automated incident response across the security portfolio.
Automate firewall provisioning, configuration backup, and policy deployment using infrastructure-as-code tools (Terraform, Ansible) and vendor APIs for repeatable, auditable workflows.
Deploy Cisco Identity Services Engine (ISE) for 802.1X wired and wireless authentication, MAC Authentication Bypass (MAB), and RADIUS/TACACS+ device administration across campus, branch, and data center environments.
More at AHEAD
Related open roles
Senior Technical Consultant - Enterprise Networking, Wireless
Remote · United States
Senior Technical Consultant - Network Security Operations
Remote · United States
Identity Application Architect
Remote · United States
Manager Security
Bangalore · Hyderabad · Delhi NCR · Hybrid
Security Analyst
Remote · IN
Sr Network Engineer - Palo Alto
Bangalore · Hyderabad · Hybrid
