Ahead
Senior Technical Consultant - Network Security
United States · Senior
Sponsorship not specified$170k-$200kDetected 62 days ago
AWSGCPAzureCloud PlatformsTerraformAnsibleCybersecurityNetwork SecuritySIEMMicrosoft SentinelDetection EngineeringIncident ResponseComplianceAuditingFirewallVPNCiscoBGP/OSPFZero TrustHIPAALeadershipMentoring
About the role
- We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.
- This OTE range may vary based on the candidate's relevant experience, qualifications, and geographic location.
- Why AHEAD: Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.
Responsibilities
- Configure and manage Palo Alto Networks next-generation firewalls running PAN-OS, including security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, WildFire), App-ID, User-ID, SSL/TLS decryption, and centralized management via Panorama.
- Lead firewall migration projects including legacy Cisco ASA to FTD conversions, cross-vendor migrations (Check Point, Fortinet, Juniper to Palo Alto or Cisco), and policy translation with rule optimization during cutover.
- Design network segmentation architectures using firewall zones, virtual routers, VRFs, and policy-based routing to enforce least-privilege east-west and north-south traffic controls.
- Implement firewall high availability designs including active/standby failover, active/active clustering, and multi-context deployments for service provider and large enterprise environments.
- Perform firewall rule base optimization, policy cleanup, and compliance auditing to reduce attack surface and align with regulatory frameworks (PCI-DSS, HIPAA, NIST).
- Design and implement ISE authorization policies including Security Group Tags (SGTs) with TrustSec, downloadable ACLs (dACLs), VLAN assignment, and Adaptive Network Control (ANC) for dynamic threat response.
- Implement pxGrid integrations to share identity and session context between ISE, Cisco Secure Firewall, Splunk, and third-party security platforms for unified policy enforcement and threat intelligence.
- Design ISE distributed deployments spanning Policy Administration Nodes (PAN), Policy Service Nodes (PSN), and Monitoring and Troubleshooting Nodes (MnT) for scale, redundancy, and geographic distribution.
- Perform ISE upgrades, migrations (legacy ACS to ISE), and advanced troubleshooting using RADIUS live logs, policy trace, TCP dump, and debug utilities to resolve authentication and authorization issues.
- Implement Cisco Secure Access (SSE) including Zero Trust Network Access, Secure Web Gateway, Cloud Access Security Broker, and resource connector deployment for private application access.
Requirements
- 7+ years of network security, infrastructure security, or security engineering experience, with at least 3 years in a consulting, professional services, or client-facing delivery role.
- Demonstrated hands-on experience designing and deploying Cisco Secure Firewall (FTD/FMC) and Palo Alto Networks NGFW (PAN-OS/Panorama) in enterprise production environments.
- Production experience deploying Cisco ISE for 802.1X authentication, TACACS+ device administration, and network access policy enforcement across wired, wireless, and VPN environments.
- Production experience with at least one SASE platform (Zscaler ZIA/ZPA, Palo Alto Prisma Access, Cisco Secure Access, or Netskope) including SWG, CASB, and ZTNA configuration.
- Strong understanding of routing protocols (BGP, OSPF, EIGRP), VPN technologies (IPsec, SSL/TLS), network segmentation, and Zero Trust architecture principles.
- Experience with identity and access management platforms (Okta, Microsoft Entra ID, SAML 2.0, SCIM) and their integration with firewall, NAC, and SASE solutions.
- Experience integrating security platforms with SIEM (Splunk, Microsoft Sentinel), syslog infrastructure, and automation tools (Terraform, Ansible) for centralized visibility and repeatable deployments.
Nice to have
- CCIE Security or CCNP Security certification.
- Palo Alto PCNSE or PCNSC certification
- Zscaler ZCCA/ZCCP
- Cisco Secure Access or Netskope certifications.
- CISSP, CompTIA Security+, or equivalent industry security certification.
- Firewall migration experience including ASA to FTD conversions and cross-vendor platform migrations with rule translation and optimization.
- These tools assist our recruitment team but do not replace human judgment.
- You may opt-out of the review or analysis of your application and resume by AI tools by using the General Application.
Skills
- AHEAD builds platforms for digital business.
- Final hiring decisions are ultimately made by humans.
- Candidates will not be penalized for choosing to opt-out.
Compensation
- The compensation range indicated in this posting reflects the On-Target Earnings ("OTE") for this role, which includes a base salary and any applicable target bonus amount.
Benefits
- Medical, Dental, and Vision Insurance
- Paid parental and caregiver leave
- Plus more! See benefits https://www.aheadbenefits.com/ for additional details.
Visa & Work Authorization
- You may opt-out of the review or analysis of your application and resume by AI tools by using the General Application.
This listing is sourced directly from Ahead's careers page and normalized into a canonical job model.