Network Security Team Lead
| Verified Pay check_circle | Provided by the employer$125.00 to $150.00 per hour |
|---|---|
| Hours | Full-time, Part-time |
| Location | Dallas, TX Dallas, Texas open_in_new |
About this job
Job Description
On-site in Dallas, TX
Our client seeks a Network Security Team Lead to design the Palo Alto Panorama management hierarchy for an estate of approximately 350 firewalls, then lead and participate in the migration waves. You will architect device groups, template stacks, access domains, and logging, size and specify the Panorama deployment, and establish onboarding sequences with validation and rollback. You will run the wave calendar, hold seven engineers to the runbook, act as the escalation point during change windows, and work as part of a two-person pair on the floor. You will own policy migration and rulebase cleanup, plan and execute a parallel-run period, and deliver a clean cutover and documentation for handoff.
We can facilitate w2 and corp-to-corp consultants. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $125.00 to $150.00/hr. w2
JN -092026-108520
Responsibilities:- Design the Panorama management hierarchy end to end, including device groups, templates and template stacks, shared versus local policy, pre-rule and post-rule model, administrative roles and access domains, and log collector and log forwarding architecture.
- Size and specify the Panorama deployment, including an HA pair and an appropriate license tier.
- Measure the estate and produce the fleet inventory, configuration archetype map, dependency register, and measured log-rate baseline to size log collectors.
- Define the per-device onboarding sequence with pre-checks, validation steps, and rollback for each change window.
- Lead the wave phase, run the wave calendar, enforce the onboarding runbook, and serve as escalation during late change windows.
- Work as part of a two-person pair during change windows in addition to leading the team.
- Own policy migration and rulebase cleanup, including shadowed, unused, and overly permissive rules.
- Design and manage the parallel-run period and execute a clean monitoring cutover from the incumbent platform.
- Handover to the client with complete runbooks.
- Direct design of a Panorama hierarchy at 250+ devices in production, with clear rationale for device group and template stack structure. Hard requirement.
- Proven leadership of a network security engineering team through delivery at comparable scale and pace, including wave calendar management, runbook adherence, and escalation ownership. Hard requirement.
- Recent hands-on device work suitable for working change windows as part of a two-person pair.
- Deep PAN-OS expertise across policy structure, NAT, security profiles, App-ID and User-ID, GlobalProtect, HA, and mixed-version fleet considerations.
- Experience taking over a firewall estate from a third-party managed provider or a comparable migration where another party held administrative control.
- Ability to produce build-ready design documents and defend them in client architecture reviews.
- PCNSE or equivalent demonstrable depth.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:
· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact fraud@eliassen.com.