Senior Palo Alto Engineer
Deliver perimeter security infrastructure and firewall policy separation across new PoP locations and existing infrastructure as part of a corporate divestiture programme.
We usually respond within three days
Opticore IT are currently searching for a Senior Palo Alto Engineer to deliver perimeter security infrastructure and firewall policy separation across new PoP locations and existing infrastructure as part of a corporate divestiture programme, ensuring a clean perimeter security posture for both retained and divested entities ahead of Day 1. This opportunity will be joining a Broadcast Media client based in the London area with 2 days a week on site.
Opticore IT is a specialist Network Engineer and Project Management consultancy offering a wide variety of opportunities to work within fast-paced, challenging environments across our client base spanning multiple sectors including Finance, Broadcast Media, Telecommunications and more.
What you'll be doing:
Design and deploy Palo Alto firewalls at new PoP locations, configuring security zones, interfaces, and routing integration with internet edge and core routing
Analyse existing firewall rulebase to identify rules belonging to each entity.
Build security policy rulebase covering internet egress/ingress, inter-zone, and partner connectivity, plus NAT policies for internet-facing services
Implement URL filtering, threat prevention, anti-spyware, file blocking, WildFire integration, and SSL decryption policies
Configure Panorama device groups, template stacks, and RBAC to enforce entity administrative separation, and manage shared and device-group-specific policy rules
Analyse existing firewall rulebase, migrate retained-entity policies to new Panorama device groups, and remove retained-entity rules, address objects, and service objects from divested-entity firewalls
Deploy firewalls in active/passive or active/active HA pairs at PoP locations and validate failover behaviour under test conditions
Configure third-party, partner, and inter-PoP firewall policy including DMZ and partner zones for controlled external access
Reconfigure Panorama RBAC to restrict divested admin access to divested device groups only and validate divested-entity perimeter is clean for Day 1
Coordinate with the core routing team on internet edge and PoP integration, the Zscaler engineer on GRE tunnel termination, and the automation team on firewall-as-code approaches
Produce low-level designs, technical working papers, and decision records, and participate in design assurance reviews
What you'll bring:
Deep hands-on experience with PA-3200/5200/400 or VM-Series and Panorama (device groups, templates, template stacks). Application-based policy, User-ID, Content-ID. NAT (source, destination, bi-directional). Log forwarding to SIEM.
Zone-based firewall architecture and micro-segmentation principles. Active/passive and active/active HA including session synchronisation and failover thresholds.
Analysing and rationalising complex legacy rulebases. Migration/cutover plans with rollback. Rule auditing, cleanup, and optimisation. GlobalProtect VPN configuration where required.
Full threat prevention suite (antivirus, anti-spyware, vulnerability protection, URL filtering, WildFire). SSL/TLS decryption (forward proxy, inbound inspection) and certificate management.
Strong TCP/IP, stateful inspection, and packet flow through firewalls. IPSec/IKEv2/GRE for site-to-site VPN. Routing integration with firewalls (BGP, OSPF, static, PBF).
Diversity:
At Opticore IT we embrace diversity and are committed to equal opportunities. We actively recruit for an inclusive and diverse workforce and as such, want to ensure we do everything we can to support your application.
We want you to feel empowered to let us know if you require any adjustments to be made with your application or interview process so please speak to our recruitment team.
#LI-NH1
- Department
- Networks
- Role
- Senior Network Engineer
- Locations
- London
- Remote status
- Hybrid
- Employment type
- Contract
About OpticoreIT
We offer best-in-class IT network solutions to keep organisations connected to their customers and clients, keep their data secure and, keep them ahead of the curve.
We pride ourselves on our people and the practical value we add in the development and deployment of technology.