Overview
Serve as the principal technical advisor and hands-on deployment specialist for enterprise Next-Generation Firewall environments. Help customers maximize the value, adoption, and security posture of their NGFW infrastructure across Internet Edge, Data Center, and Branch/Campus networks.
What you'll do
- Conduct periodic service reviews covering deployed models, OS versions, licensing, and HA states; map organizational use cases and define enablement, migration, and optimization phases.
- Evaluate security postures against least-privilege principles, review deployment architectures for scalability, and use Strata Incident Framework to proactively mitigate operational risks.
- Execute customized enablement plans and targeted technical workshops for customer network, security, and operations teams.
- Assist customers with Panorama and Strata Cloud Manager, and advise on HA design, logging architecture, and PAN-OS upgrade planning.
- Train customers on technical engagement best practices, diagnostic collection, and use of the CLI and APIs for operational efficiency.
- Assist customers in transitioning from legacy port/protocol rules to granular App-ID, User-ID, and Content-ID zone-based security policies.
- Implement and fine-tune Advanced Threat Prevention, Anti-Spyware profiles with DNS sinkholing, Advanced WildFire, Advanced URL Filtering, and Advanced DNS Security.
- Guide customers on Zero Trust Micro segmentation for East-West traffic, VSYS multi-tenant scoping, and ZTP workflow optimization for branch environments with local DHCP/DNS proxy setups.
- Deploy and advise on high-complexity SSL/TLS Decryption, including SSL Forward Proxy, SSL Inbound Inspection, and SSH Proxy; evaluate PQC readiness and advise on certificate distribution strategies within existing PKI architectures.
- Deploy, configure, and tune Enterprise DLP profiles for sensitive data in transit, including PII and PCI, across different environments.
- Manage Shadow IT and secure cloud applications using SaaS Security Inline, SaaS Security API, and SSPM with the App-ID Cloud Engine.
- Deploy ML-based device discovery and microsegmentation for unmanaged IoT/OT devices.
- Establish visibility, risk scoring, and security policy tuning for corporate generative AI applications.
- Guide hardware refreshes, legacy port-to-App-ID policy transitions, and Panorama-to-SCM platform migrations.
- Deploy, optimize, and maintain GlobalProtect VPN and Site-to-Site IPsec/SSL tunnels.
- Configure and troubleshoot BGP, OSPF, static routing, and HA failovers.
What you'll need
- 5+ years of experience in network security engineering, security architecture, or deployment-focused customer success roles within enterprise environments.
- A minimum of 2–3 years of direct, hands-on experience deploying and troubleshooting live production environments for enterprise firewall customers.
- Deep technical mastery of NGFW architectures, various form factors, and PAN-OS features and functionalities, including deep understanding of Panorama and Strata Cloud Manager.
- Extensive hands-on experience with IPsec VPNs, QoS traffic prioritization, BGP/OSPF, ZTP workflows, and PKI certificate validation.
- Experience configuring SAML/RADIUS/LDAP integrations and endpoint compliance with GlobalProtect/HIP.
- Familiarity with deploying and configuring CASB, Enterprise DLP engines, and IoT Security platforms.
- Exceptional ability to translate complex technical and architectural blueprints into digestible training sessions, workshops, or strategic roadmaps.
- Proven capability to establish strong technical credibility and build relationships across diverse customer personas.
Nice to have
- Prior work experience within a top-tier Technical Assistance Center environment is strongly preferred.
- Experience in security operations or firewall operations will be beneficial.
- Certifications such as PCNSE or equivalent expert-level network security credentials.
- Prior experience working with AI-driven security dashboards, AIOps, or automated configuration baseline evaluation suites.
Details
- Location: Bangalore, India, at Bagmane Tech Park.
- Most teams work from the office full time, with flexibility when needed.
- Immigration sponsorship is not available for this role.
Read the full description and apply on the company’s own careers page.