Design, deploy, and maintain Palo Alto Networks security infrastructure across on-premises and Azure environments. Manage multi-region connectivity, BGP routing, and Zero Trust security policies for a distributed global enterprise.
This is a remote position.
About This Opportunity
CTI Staffing is partnering with a growing organization to find a Network Security Consultant to support a global network infrastructure spanning offices across the US, EU, and Asia. This is a fully remote engagement.
This team owns the firewall architecture, secure connectivity, and cloud network design for a distributed enterprise footprint. You'll be the technical authority for how Palo Alto Networks security infrastructure and Azure networking work together across every site.
What You'll Do
Design, deploy, and maintain Palo Alto Networks NGFW infrastructure across on-premises and Azure environments
Architect and manage site-to-site VPN and dynamic routing (BGP/OSPF) between regional offices, data centers, and Azure VNets
Configure and support GlobalProtect for secure remote-user access, including route redistribution into BGP/OSPF
Design and manage Azure networking components: VNets, VNet peering, ExpressRoute, VPN Gateway, Route Tables, and NSGs
Build and maintain multi-region connectivity architecture linking offices across three continents with consistent security policy
Manage centralized policy and logging via Panorama across all sites
Own BGP routing design and troubleshooting between Palo Alto virtual routers and Azure/ExpressRoute circuits
Support network segmentation and Zero Trust security zone design across cloud and branch environments
Requirements
What You Bring
Must-Have:
5+ years of hands-on experience with Palo Alto Networks firewalls (PAN-OS), including Panorama management
Strong working knowledge of GlobalProtect architecture (portal/gateway design, IP pools, split tunneling, redistribution)
Solid understanding of BGP (route redistribution, filtering, multi-homed peering); OSPF a plus
Demonstrated experience with Microsoft Azure networking: VNets, ExpressRoute, VPN Gateway, NSGs, Route Tables
Experience designing and supporting multi-region WAN/VPN architectures across multiple continents
Working knowledge of IPSec VPN design, GRE tunnels, and hub-and-spoke topologies
Experience supporting distributed teams across US, EU, and Asia time zones
Strong troubleshooting skills using CLI (PAN-OS), packet captures, and routing table analysis
Nice-to-Have:
PCNSE certification
Microsoft Certified: Azure Network Engineer Associate
CCNP / JNCIP or equivalent routing/switching certification
Familiarity with SD-WAN concepts and technologies
Juniper experience
Technical Environment:
Palo Alto Networks NGFW (physical and VM-Series), Panorama, GlobalProtect
Microsoft Azure networking (VNets, ExpressRoute, VPN Gateway, Azure Firewall)
BGP, OSPF, IPSec VPN, GRE tunnels
What Success Looks Like:
Multi-region connectivity architecture is stable, documented, and consistently enforced
BGP peering between Palo Alto and Azure/ExpressRoute is clean with no unresolved routing issues
Security policy and logging via Panorama is consistent across every site
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”