Security Network Architect/Engineer
CticonsultingJob Description
This is a remote position.
About This Opportunity
CTI Staffing is partnering with a growing organization to find a Network Security Consultant to support a global network infrastructure spanning offices across the US, EU, and Asia. This is a fully remote engagement.
This team owns the firewall architecture, secure connectivity, and cloud network design for a distributed enterprise footprint. You'll be the technical authority for how Palo Alto Networks security infrastructure and Azure networking work together across every site.
What You'll Do
- Design, deploy, and maintain Palo Alto Networks NGFW infrastructure across on-premises and Azure environments
- Architect and manage site-to-site VPN and dynamic routing (BGP/OSPF) between regional offices, data centers, and Azure VNets
- Configure and support GlobalProtect for secure remote-user access, including route redistribution into BGP/OSPF
- Design and manage Azure networking components: VNets, VNet peering, ExpressRoute, VPN Gateway, Route Tables, and NSGs
- Build and maintain multi-region connectivity architecture linking offices across three continents with consistent security policy
- Manage centralized policy and logging via Panorama across all sites
- Own BGP routing design and troubleshooting between Palo Alto virtual routers and Azure/ExpressRoute circuits
- Support network segmentation and Zero Trust security zone design across cloud and branch environments
Requirements
What You Bring
Must-Have:
- 5+ years of hands-on experience with Palo Alto Networks firewalls (PAN-OS), including Panorama management
- Strong working knowledge of GlobalProtect architecture (portal/gateway design, IP pools, split tunneling, redistribution)
- Solid understanding of BGP (route redistribution, filtering, multi-homed peering); OSPF a plus
- Demonstrated experience with Microsoft Azure networking: VNets, ExpressRoute, VPN Gateway, NSGs, Route Tables
- Experience designing and supporting multi-region WAN/VPN architectures across multiple continents
- Working knowledge of IPSec VPN design, GRE tunnels, and hub-and-spoke topologies
- Experience supporting distributed teams across US, EU, and Asia time zones
- Strong troubleshooting skills using CLI (PAN-OS), packet captures, and routing table analysis
Nice-to-Have:
- PCNSE certification
- Microsoft Certified: Azure Network Engineer Associate
- CCNP / JNCIP or equivalent routing/switching certification
- Familiarity with SD-WAN concepts and technologies
- Juniper experience
Technical Environment:
- Palo Alto Networks NGFW (physical and VM-Series), Panorama, GlobalProtect
- Microsoft Azure networking (VNets, ExpressRoute, VPN Gateway, Azure Firewall)
- BGP, OSPF, IPSec VPN, GRE tunnels
What Success Looks Like:
- Multi-region connectivity architecture is stable, documented, and consistently enforced
- BGP peering between Palo Alto and Azure/ExpressRoute is clean with no unresolved routing issues
- Security policy and logging via Panorama is consistent across every site