24 Sep
|
V Group
|
Bhopal
Security Engineer - Firewall / Palo Alto (Contract)
Job Summary
We are seeking an experienced Firewall / Palo Alto Security Engineer to deliver perimeter security infrastructure and firewall policy separation as part of a large-scale corporate divestiture programme. The role is responsible for designing, building, and configuring Palo Alto firewalls at new PoP locations, migrating and separating security policies between entities, and ensuring a clean perimeter security posture ahead of Day 1.
The successful candidate will have deep hands-on experience with Palo Alto Networks firewalls and Panorama, strong security policy design skills, and the ability to deliver at pace across multiple sites. They will work closely with the core routing team (internet edge and PoP build), the Zscaler security engineer, and the automation and tooling team.
Key Responsibilities
Perimeter Security Build-Out
- Design and deploy Palo Alto firewalls at new PoP locations
- Configure security zones, interfaces, and routing integration with internet edge and core routing
- Build security policy rulebase covering internet egress, ingress, inter-zone traffic, and partner connectivity
- Configure NAT policies (source NAT, destination NAT) for internet-facing services
- Implement URL filtering, threat prevention, anti-spyware, file blocking, and WildFire integration
- Configure SSL decryption policies aligned with security requirements
- Establish GlobalProtect or equivalent remote access VPN if required (coordinating with the Zscaler workstream)
Panorama Management
- Configure Panorama device groups, template stacks,
and management hierarchy for current firewalls
- Implement RBAC on Panorama to enforce entity administrative separation
- Manage shared and device-group-specific policy rules through Panorama
- Configure log forwarding profiles, reporting, and alerting integration
Firewall Policy Separation
- Analyse existing firewall rulebase to identify rules belonging to each entity
- Migrate retained-entity security policies to new Panorama device groups
- Remove retained-entity rules, address objects, and service objects from divested-entity firewalls
- Ensure no residual cross-entity access remains in either perimeter after separation
- Document policy ownership and classification for audit trail
unh4>
Third-Party & Partner Integration
- Configure firewall rules for third-party and partner connectivity as required by the business
- Implement DMZ and partner zones for controlled external access
- Configure inter-PoP firewall policy for site-to-site traffic where required
High Availability & Resilience
- Deploy firewalls in active/passive or active/active HA pairs at PoP locations
- Configure session synchronisation, failover thresholds, and monitoring
- Validate HA failover behaviour under test conditions
Skills
- Palo Alto
- Panorama
- RBAC
- GlobalProtect
- VPN
- URL Filtering
- Threat Prevention
- WildFire
- SSL Decryption
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Security Engineer - Firewall / Palo Alto (Bhopal)
🏢 V Group
📍 Bhopal