We are seeking a highly skilled L4 Network Security Engineer/ Lead Engineer to lead migration planning and execution for the End Of Life (EOL) replacement of legacy Cisco ASA firewalls with Cisco Firepower and Palo Alto Networks Next-Generation Firewalls (NGFWs). This role requires deep hands-on expertise, the ability to mentor junior engineers, drive automation efforts, and design scalable, secure migration workflows. Key responsibilities include end-to-end planning and execution of ASA to Firepower and Palo Alto migrations, designing migration workflows, HA topology, and optimizing policy conversion strategy. Perform or oversee configuration conversion from ASA to Palo Alto and Cisco Firepower. Design, test, and validate VPNs (IPSec/SSL), NAT policies, dynamic routing, and IPS/IDS profiles. Collaborate with enterprise architects, operations, and product teams for successful delivery, guiding L3 teams, reviewing configurations, and troubleshooting complex post-migration issues.
Good To Have:- Cisco certifications: CCIE Security/ CCNP Security/ CCNP R&S
- Palo Alto certifications: PCNSA/PCNSE
Must Have:- Deep hands-on knowledge in Cisco ASA, Cisco Firepower/FTD
- Palo Alto NGFW (VSYS, Panorama, Expedition, Migration Manager)
- Strong command of Cisco ASA ACL, VPN, AnyConnect, HA, NAT, Policy Management
- Strong command of Palo Alto VPN, Global Protect, HA, NAT, Security Policy
- Routing protocols (Static, OSPF, BGP) and switching fundamentals
- Policy migration planning, zero-touch deployment
- Config conversion tools and scripting (Python preferred)
- Multi-vendor firewall strategy and enterprise segmentation
- Strong understanding of HA, software upgrade, rollback
- Sound knowledge of L3 routing and switching concepts