Job Description
Own the design, administration, and lifecycle management of the organization's network perimeter and cloud edge security estate — spanning Palo Alto VM-Series, FortiGate HA Cluster (on-premises and multi-cloud NGFW/NVA) and Cloudflare (CDN, DDoS, edge WAF, DNS). Accountable for policy governance, high-availability resilience, VPN connectivity, edge traffic protection, and vulnerability remediation across the full perimeter-to-edge security stack.
Responsibilities
- Design and administer zone-based security architecture, inter-zone policies, and DMZ segmentation on Palo Alto and FortiGate platforms.
- Configure and maintain App-ID, User-ID, Content-ID, SSL/TLS decryption, NAT (DNAT/SNAT/U-turn), and UTM (IPS, AV, Web Filtering, App Control) policies.
- Build and operate Site-to-Site IPSec VPN (IKEv2) with BGP dynamic routing, route-based/policy-based VPNs, and SD-WAN traffic steering where applicable.
- Manage centralized policy platforms — Panorama / Strata Cloud Manager (Palo Alto) and FortiManager / FortiAnalyzer (Fortinet) — for policy push, log aggregation, and reporting.
- Design, deploy, and validate High Availability clusters (Active-Passive / Active-Active); execute and document quarterly failover testing and RCA.
- Lead NVA deployment, migration (e.g., Azure → OCI), firmware/patch lifecycle, hotfixes, and HA-aware patching with rollback planning.
- Integrate firewall/NVA inspection paths with Load Balancer tiers for L4/L7 traffic inspection.
- Administer Cloudflare CDN (cache rules, Workers/Pages), network- and application-layer DDoS protection, and edge WAF (managed rulesets, custom rules, rate limiting, bot management).
- Manage Cloudflare Load Balancing, Public DNS, and URL management; perform ongoing traffic analysis and optimization at the edge.
- Own vulnerability remediation, patching cadence, and upgrade planning for all firewall/NVA and edge security assets.
- Monitor NGFW/UTM threat logs and Cloudflare traffic/attack analytics; manage signature updates and lead incident response and triage for perimeter and edge security events.
Qualifications
Required Qualifications & Experience
- Bachelor's degree in Computer Science, Information Security, or related field.
- 5+ years experience administering enterprise NGFW platforms (Palo Alto and/or Fortinet) in production environments.
- Hands-on experience with multi-cloud NVA deployments (Azure, GCP, OCI) and cloud edge/CDN security platforms (Cloudflare or equivalent).
- Certifications preferred: PCNSE (Palo Alto), NSE 4/NSE 7 (Fortinet), Cloudflare Certified Administrator.
- Strong understanding of routing (BGP), VPN technologies, DNS, DDoS mitigation, and network segmentation.
- Excellent incident response, documentation, and cross-team coordination skills.