CT

Security Network Architect/Engineer

Cticonsulting
Posted 4 hours ago
Probably WorldwideRemoteEngineering & Development
Is this job info correct?

Job Description

This is a remote position.

About This Opportunity

CTI Staffing is partnering with a growing organization to find a Network Security Consultant to support a global network infrastructure spanning offices across the US, EU, and Asia. This is a fully remote engagement.

This team owns the firewall architecture, secure connectivity, and cloud network design for a distributed enterprise footprint. You'll be the technical authority for how Palo Alto Networks security infrastructure and Azure networking work together across every site.

What You'll Do

  • Design, deploy, and maintain Palo Alto Networks NGFW infrastructure across on-premises and Azure environments
  • Architect and manage site-to-site VPN and dynamic routing (BGP/OSPF) between regional offices, data centers, and Azure VNets
  • Configure and support GlobalProtect for secure remote-user access, including route redistribution into BGP/OSPF
  • Design and manage Azure networking components: VNets, VNet peering, ExpressRoute, VPN Gateway, Route Tables, and NSGs
  • Build and maintain multi-region connectivity architecture linking offices across three continents with consistent security policy
  • Manage centralized policy and logging via Panorama across all sites
  • Own BGP routing design and troubleshooting between Palo Alto virtual routers and Azure/ExpressRoute circuits
  • Support network segmentation and Zero Trust security zone design across cloud and branch environments


Requirements

What You Bring

Must-Have:

  • 5+ years of hands-on experience with Palo Alto Networks firewalls (PAN-OS), including Panorama management
  • Strong working knowledge of GlobalProtect architecture (portal/gateway design, IP pools, split tunneling, redistribution)
  • Solid understanding of BGP (route redistribution, filtering, multi-homed peering); OSPF a plus
  • Demonstrated experience with Microsoft Azure networking: VNets, ExpressRoute, VPN Gateway, NSGs, Route Tables
  • Experience designing and supporting multi-region WAN/VPN architectures across multiple continents
  • Working knowledge of IPSec VPN design, GRE tunnels, and hub-and-spoke topologies
  • Experience supporting distributed teams across US, EU, and Asia time zones
  • Strong troubleshooting skills using CLI (PAN-OS), packet captures, and routing table analysis

Nice-to-Have:

  • PCNSE certification
  • Microsoft Certified: Azure Network Engineer Associate
  • CCNP / JNCIP or equivalent routing/switching certification
  • Familiarity with SD-WAN concepts and technologies
  • Juniper experience

Technical Environment:

  • Palo Alto Networks NGFW (physical and VM-Series), Panorama, GlobalProtect
  • Microsoft Azure networking (VNets, ExpressRoute, VPN Gateway, Azure Firewall)
  • BGP, OSPF, IPSec VPN, GRE tunnels

What Success Looks Like:

  • Multi-region connectivity architecture is stable, documented, and consistently enforced
  • BGP peering between Palo Alto and Azure/ExpressRoute is clean with no unresolved routing issues
  • Security policy and logging via Panorama is consistent across every site


Similar jobs