Network Security Engineer IV

1 Month ago • 10-16 Years • Cyber Security

Job Summary

Job Description

We are seeking a highly skilled L4 Network Security Engineer/ Lead Engineer to lead migration planning and execution for the End Of Life (EOL) replacement of legacy Cisco ASA firewalls with Cisco Firepower and Palo Alto Networks Next-Generation Firewalls (NGFWs). This role requires deep hands-on expertise, the ability to mentor junior engineers, drive automation efforts, and design scalable, secure migration workflows. Key responsibilities include end-to-end planning and execution of ASA to Firepower and Palo Alto migrations, designing migration workflows, HA topology, and optimizing policy conversion strategy. Perform or oversee configuration conversion from ASA to Palo Alto and Cisco Firepower. Design, test, and validate VPNs (IPSec/SSL), NAT policies, dynamic routing, and IPS/IDS profiles. Collaborate with enterprise architects, operations, and product teams for successful delivery, guiding L3 teams, reviewing configurations, and troubleshooting complex post-migration issues.
Must have:
  • Deep hands-on knowledge in Cisco ASA, Cisco Firepower/FTD
  • Palo Alto NGFW (VSYS, Panorama, Expedition, Migration Manager)
  • Strong command of Cisco ASA ACL, VPN, AnyConnect, HA, NAT, Policy Management
  • Strong command of Palo Alto VPN, Global Protect, HA, NAT, Security Policy
  • Routing protocols (Static, OSPF, BGP) and switching fundamentals
  • Policy migration planning, zero-touch deployment
  • Config conversion tools and scripting (Python preferred)
  • Multi-vendor firewall strategy and enterprise segmentation
  • Strong understanding of HA, software upgrade, rollback
  • Sound knowledge of L3 routing and switching concepts
Good to have:
  • Cisco certifications: CCIE Security/ CCNP Security/ CCNP R&S
  • Palo Alto certifications: PCNSA/PCNSE

Job Details

Job Title – Network Security Engineer-IV
 
Location: Remote
Experience: 10–16 years
Project: Cisco ASA to Palo Alto / Firepower EOL Migration
Job Type: Full-time


Role Overview:
  • We are seeking a highly skilled L4 Network Security Engineer/ Lead Engineer to lead migration planning and execution for the EOL replacement of legacy Cisco ASA firewalls (5508,5525,5545,5555 etc.) with Cisco Firepower and Palo Alto Networks NGFWs. This role requires deep hands-on expertise as well as the ability to mentor junior engineers, drive automation efforts, and design scalable, secure migration workflows.


Key Responsibilities:
  • Lead end-to-end planning and execution of ASA to Firepower and Palo Alto migrations.
  • Design migration workflows, HA topology, and optimize policy conversion strategy.
  • Perform or oversee conversion of configurations:
  • ASA → Palo Alto (1410 VSYS, 1410 Single Tenant & VM-Series)
  • ASA → Cisco Firepower with ASA Code or FTD
  • Design, test, and validate:
  • VPNs (IPSec/SSL), NAT policies,dynamic routing, IPS/IDS profiles
  • Collaborate with enterprise architects, operations, and product teams for successful delivery.
  • Strong knowledge of change/Incident management process.
  • Guide L3 teams in execution, review configurations and scripts.
  • Troubleshoot complex post-migration issues.
  • Track project milestones and ensure documentation compliance.


Must-Have Skills:
  • Deep hands-on knowledge in:
  • Cisco ASA, Cisco Firepower/FTD
  • Palo Alto NGFW (VSYS, Panorama,Expedition, Migration Manager)
  • Strong command of:
  • Cisco ASA- ACL, VPN setup (IPSec/SSL), AnyConnect, HA Setup, NAT, Policy Management, OS Upgrade.
  • Palo Alto- VPN setup (IPSec/SSL),Global protect, HA Setup, NAT, Security Policy Management, PANOS Upgrade.
  • Routing protocols (Static, OSPF,BGP) and switching fundamentals
  • Policy migration planning,zero-touch deployment models
  • Config conversion tools and scripting (Expedition, Python preferred)
  • Experience in multi-vendor firewall strategy and enterprise segmentation
  • Strong understanding of HA configurations, software upgrade planning, and rollback scenarios
  • Sound knowledge of L3 routing (Static, OSPF, BGP) and switching concepts.


Soft Skills & Professional Attributes:
  • Excellent interpersonal and communication skills – able to clearly articulate ideas, processes, and technical concepts to both technical and non-technical audiences.
  • Strong documentation abilities – capable of creating and maintaining clear, concise technical documentation and procedures.
  • Flexible, proactive, and self-driven – demonstrates initiative, reliability, and adaptability in dynamic environments.


Preferred Certifications:
  • Cisco Certifications: CCIE Security/ CCNP Security/ CCNP R&S
  • Palo Alto Certifications: PCNSA/PCNSE 


Similar Jobs

Marsh McLennan - Technical Specialist – Claims & Administration

Marsh McLennan

Adelaide, South Australia, Australia (Hybrid)
3 Months ago
Square - Manager, Environmental Health and Safety

Square

Stamford, Connecticut, United States (On-Site)
2 Weeks ago
Match Group - Research

Match Group

Seoul, South Korea (Hybrid)
1 Month ago
Fox Factory - Customer Service Representative

Fox Factory

Burnaby, British Columbia, Canada (On-Site)
2 Weeks ago
Flow - Enterprise Account Manager

Flow

Miami, Florida, United States (On-Site)
1 Month ago
Unisys - Cybersecurity Consultant

Unisys

Bogotá, Bogota, Colombia (On-Site)
1 Week ago
PwC - Security Compliance Analyst - US Client

PwC

Buenos Aires, Buenos Aires, Argentina (On-Site)
1 Week ago
Black Bery - QNX Cybersecurity Manager

Black Bery

Ottawa, Ontario, Canada (On-Site)
1 Year ago
SpecterOps - Defensive Security Analyst

SpecterOps

France (Remote)
2 Weeks ago
Valeo - IT Infrastructure Engineer - Cloud Cybersecurity

Valeo

Créteil, Île-de-France, France (Hybrid)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

upwork - Enterprise Account Manager

upwork

(Remote)
2 Months ago
TVH - Client Experience Manager

TVH

Olathe, Kansas, United States (On-Site)
3 Weeks ago
Canva - Senior Frontend Software Engineer

Canva

Auckland, Auckland, New Zealand (Remote)
2 Months ago
Everi - Solutions Architect II

Everi

Las Vegas, Nevada, United States (Hybrid)
4 Weeks ago
Nexon - Senior Gameplay Engineer

Nexon

El Segundo, California, United States (Hybrid)
3 Months ago
USE Insider - Senior Software Engineer (Golang)

USE Insider

Istanbul, İstanbul, Türkiye (Remote)
9 Months ago
Tencent - HR Intern

Tencent

Tokyo, Japan (On-Site)
1 Week ago
CAE - C-130 L-382 Instructor Flight Engineer

CAE

Tampa, Florida, United States (On-Site)
2 Months ago
GameDuell - Senior Product Manager - Games

GameDuell

Berlin, Berlin, Germany (Hybrid)
2 Months ago
Workato - Senior Frontend Engineer (Angular)

Workato

Sofia, Sofia City Province, Bulgaria (On-Site)
4 Weeks ago

Get notifed when new similar jobs are uploaded

Jobs in Gurugram, Haryana, India

Ion - Credit Analyst

Ion

Mumbai, Maharashtra, India (On-Site)
9 Months ago
Sumo logic - Senior Product Manager II - Integrations

Sumo logic

Bengaluru, Karnataka, India (On-Site)
3 Weeks ago
beghou consulting - Associate Consultant Data Warehousing (MDM)

beghou consulting

Pune, Maharashtra, India (Hybrid)
3 Weeks ago
Virtusa - Cypress QA

Virtusa

Andhra Pradesh, India (Hybrid)
8 Months ago
Nagarro - Principal Engineer, PHP Drupal

Nagarro

India (Remote)
9 Months ago
Morning Star - Project Manager

Morning Star

Mumbai, Maharashtra, India (Hybrid)
3 Weeks ago
Marvell - Senior Principal Engineer, RTL Design (DDR4/5, LPDDR, HBM)

Marvell

Bengaluru, Karnataka, India (On-Site)
1 Year ago
Bito - Inside Sales Executive

Bito

Pune, Maharashtra, India (Hybrid)
5 Months ago
Nagarro - Principal Engineer, Data Science

Nagarro

India (Remote)
9 Months ago
entrata - Utility Auditor

entrata

Pune, Maharashtra, India (Hybrid)
3 Weeks ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Imanage - Security Compliance Analyst

Imanage

Bengaluru, Karnataka, India (Hybrid)
2 Weeks ago
Yodlee - Information Security Analyst/ Analyst – Identity Governance and Compliance

Yodlee

Thiruvananthapuram, Kerala, India (On-Site)
2 Weeks ago
Adobe - Senior Cyber Defense Analyst

Adobe

Sydney, New South Wales, Australia (On-Site)
3 Months ago
PhonePe - Information Security Engineer

PhonePe

Bengaluru, Karnataka, India (On-Site)
4 Weeks ago
Egnyte - Senior Cloud Security Engineer

Egnyte

Poznań, Greater Poland Voivodeship, Poland (Remote)
2 Months ago
fortis games - Senior Application Security Engineer

fortis games

Canada (Remote)
2 Months ago
Devoteam - Cybersecurity Consultant

Devoteam

Cité Mahrajène, Tunis, Tunisia (On-Site)
9 Months ago
binance - DevSecOps Engineer, Infrastructure Security

binance

Taipei City, Taiwan (Remote)
11 Months ago
PwC - ETIC, Cybersecurity Cloud Security - Manager

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
10 Months ago
Devoteam - IT Project Manager with Cybersecurity Background and Good English Level

Devoteam

Barcelona, Catalonia, Spain (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded