
Security Network Architect β Engineer
Posted 12 hours ago

Posted 12 hours ago
This is a fully remote position, open to applicants in United States.
β’ Design, implement, and maintain the infrastructure of Palo Alto Networks NGFW across both on-premises and Azure environments.
β’ Architect and oversee site-to-site VPN and dynamic routing (BGP/OSPF) connections among regional offices, data centers, and Azure VNets.
β’ Configure and facilitate GlobalProtect for secure remote user access, including route redistribution into BGP/OSPF.
β’ Design and manage Azure networking components: VNets, VNet peering, ExpressRoute, VPN Gateway, Route Tables, and NSGs.
β’ Develop and sustain a multi-region connectivity architecture that links offices across three continents while enforcing a consistent security policy.
β’ Manage centralized policy and logging through Panorama across all locations.
β’ Take ownership of BGP routing design and troubleshooting between Palo Alto virtual routers and Azure/ExpressRoute circuits.
β’ Support network segmentation and the design of Zero Trust security zones across cloud and branch environments.
β’ Ensure that the multi-region connectivity architecture is stable, well-documented, and consistently applied.
β’ Troubleshoot routing issues and maintain clean BGP peering between Palo Alto and Azure/ExpressRoute.
β’ Ensure a consistent security policy and logging via Panorama across all sites.
β’ A minimum of 5 years of hands-on experience with Palo Alto Networks firewalls (PAN-OS), including expertise in Panorama management.
β’ Strong knowledge of GlobalProtect architecture, including portal/gateway design, IP pools, split tunneling, and redistribution.
β’ Solid understanding of BGP (route redistribution, filtering, multi-homed peering); knowledge of OSPF is a plus.
β’ Proven experience with Microsoft Azure networking, specifically VNets, ExpressRoute, VPN Gateway, NSGs, and Route Tables.
β’ Experience in designing and supporting multi-region WAN/VPN architectures across various continents.
β’ Familiarity with IPSec VPN design, GRE tunnels, and hub-and-spoke topologies.
β’ Experience in supporting distributed teams across US, EU, and Asia time zones.
β’ Strong troubleshooting capabilities using CLI (PAN-OS), packet captures, and routing table analysis.
β’ PCNSE certification is a plus.
β’ Microsoft Certified: Azure Network Engineer Associate is a plus.
β’ CCNP / JNCIP or equivalent routing/switching certification is a plus.
β’ Familiarity with SD-WAN concepts and technologies is a plus.
β’ Experience with Juniper products is a plus.
β’ Fully remote engagement.
Forward Networks, Inc.
Associated Bank
Nebius Group
Red River
Get handpicked remote jobs straight to your inbox weekly.