
Cybersecurity Firewall Analyst II
Eliassen Group
Job description
Description
Hybrid 3 days on-site in Charlotte, NC
Our client seeks a Cybersecurity Firewall Analyst II to engineer, support, and optimize Palo Alto SASE and related inspection zone technologies in a large enterprise. The role will implement and maintain Prisma Access, GlobalProtect, and Strata Cloud Manager while integrating with on-prem platforms such as F5 BIG-IP and secure web gateway solutions. The analyst will collaborate with Security Operations, Network Engineering, and Incident Response to enforce policy, enhance telemetry and monitoring, and strengthen threat detection. The position will drive high availability, hardening, and resilience, produce actionable metrics, and align SASE strategy with modernization initiatives and security architecture in a 24x7 CSOC environment.
Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $45.00 to $50.00/hr. w2
JN -092026-108449
Responsibilities
-
Participate in implementation, support, and lifecycle management of Palo Alto SASE solutions (Prisma Access, GlobalProtect, Strata Cloud Manager) integrated with Inspection Zone technologies (F5 BIG-IP, SWG/Proxy).
-
Design, deploy, and optimize cloud-delivered security controls including SWG, CASB, ZTNA, and threat prevention per Palo Alto SASE architecture.
-
Provide advanced engineering support for SASE and Inspection Zone platforms in partnership with Security Operations, Network Engineering, and Incident Response.
-
Drive monitoring, telemetry integration, and policy enforcement across SASE and on-prem environments for consistent visibility and detection.
-
Execute system hardening, high availability design, failover strategy, and service continuity planning for SASE and Inspection Zone.
-
Apply threat intelligence and best practices to proactively reduce risk.
-
Continuously improve detection and response by leveraging SASE telemetry for incident analysis and threat hunting.
-
Develop and report operational and security metrics to inform leadership and improve maturity.
-
Collaborate to align SASE strategy with enterprise security architecture and modernization initiatives, including legacy proxy replacement.
Experience Requirements
-
Hands-on engineering and lifecycle support of Palo Alto Networks solutions.
-
Strong knowledge of network protocols including BGP, IPSec, routing, and NAT with SASE connectivity design.
-
Experience with SASE platforms such as Prisma Access, GlobalProtect, and Strata Cloud Manager.
-
Integration with on-prem Inspection Zone and hybrid cloud architectures, including F5 BIG-IP and SWG/Proxy.
-
Collaboration with Security Operations, Network Engineering, and Incident Response.
-
System hardening, high availability, and performance optimization.
-
Security monitoring, telemetry integration, policy enforcement, and threat detection across SASE and on-prem environments.
-
Preferred experience with automation and infrastructure-as-code such as Python or Terraform.
-
Understanding of cybersecurity frameworks and practices such as NIST, CIS, and Zero Trust.
-
Desired certifications include SANS GIAC/GCIA/GCIH/GCFA, CISSP, CISA, CISM, or related network/system security certifications.
Education Requirements
-
High School, Associate, Bachelor, Master, Bachelor of Science, or Bachelor of Arts in Cybersecurity, Information Security, Computer Science, Management Information Systems, or related field. Equivalent experience may substitute for a degree.
-
4+ years cybersecurity or IT-related experience, including information security or system administration roles. Additional 3+ years in cybersecurity or IT functions preferred.