About this opportunity
Magnit Global lists this Network Security Engineer opportunity in denver, Colorado. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Network Security Engineer — Juniper to Palo Alto Migration
Enterprise Engineering (EE) — Customer Migration Engagement
Location: Denver, CO (hybrid — 3 days onsite / 2 days remote)
Role Description (Job Summary)
We are seeking an experienced Network Security Engineer to support a customer team migrating from Juniper SRX to Palo Alto Networks Next-Generation Firewalls (NGFW). This is a hybrid engagement based in the Denver area, requiring three days per week onsite at the customer location and two days remote.
The ideal candidate has hands-on experience performing Juniper-to-Palo Alto migrations and can translate legacy Juniper configurations into Palo Alto best practices, while operating confidently in large-scale, service provider-grade environments.
Your Impact (Responsibilities)
Lead and support the migration of firewall infrastructure from Juniper SRX to Palo Alto NGFW
Translate existing Juniper configurations into Palo Alto best-practice architectures
Redesign legacy port/protocol-based security policies into application-aware security policies
Configure and operate Security Policies, NAT Policies, Application-ID, User-ID, Content-ID, and Zone-Based Security
Integrate Palo Alto firewalls into complex service provider routing environments, including MPLS, EVPN/VXLAN, and large-scale IP transit architectures
Deploy Palo Alto NGFWs in active/passive and active/active high availability architectures
Implement advanced threat prevention capabilities, including IPS, Anti-Malware, URL Filtering, DNS Security, and WildFire
Perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
Use Strata Cloud Manager (SCM) for centralized management, templates, device groups, policy management, and operational workflows
Lead cutovers during maintenance windows, minimizing customer impact and ensuring rapid rollback capability if required
Follow strong change management processes appropriate to large enterprise or service provider environments
Mentor customer engineers on Palo Alto operational best practices following migration
Communicate complex technical concepts clearly to both engineering and leadership audiences
Your Experience (Qualifications)
Experience performing a Juniper SRX to Palo Alto NGFW migration is strongly preferred
Expertise with Palo Alto Networks NGFW architecture, deployment, and operations in large-scale environments (service provider experience is a plus)
Knowledge of Juniper architecture and the ability to translate Juniper configurations into Palo Alto best practices
Advanced understanding of Security Policies, NAT Policies, Application-ID, User-ID, Content-ID, and Zone-Based Security
Strong knowledge of dynamic routing protocols including BGP, OSPF, IS-IS, static routing, route redistribution, and ECMP
Experience integrating Palo Alto firewalls into complex service provider routing environments with MPLS, EVPN/VXLAN, and large-scale IP transit architectures
Experience deploying Palo Alto NGFWs in active/passive and active/active high availability architectures
Experience implementing advanced threat prevention capabilities including IPS, Anti-Malware, URL Filtering, DNS Security, and WildFire
Ability to perform firewall sizing, performance tuning, session analysis, and capacity planning for high-throughput environments
Experience with SCM (Strata Cloud Manager) for centralized management, templates, device groups, policy management, and operational workflows
Key Competencies (Preferred / Other Qualifications)
Ability to lead cutovers during maintenance windows while minimizing customer impact and ensuring rapid rollback if required
Strong understanding of change management processes within large enterprise or service provider environments
Ability to mentor customer engineers on Palo Alto operational best practices following migration
Excellent communication skills, with the ability to translate complex technical concepts for both engineering and leadership audiences
Familiarity with cloud integrations (AWS, Azure, GCP) and hybrid network security architectures is a plus
Comfortable working in a hybrid onsite/remote schedule with a customer-embedded team
Education
No specific degree requirement is mandated. Relevant industry certifications (e.g., Palo Alto Networks PCNSE, JNCIA/JNCIS, or equivalent NGFW/routing certifications) are a plus and may be considered alongside equivalent hands-on professional experience.
#J-18808-Ljbffr
Worksite address
denver, CO, 80285, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.