Senior Palo Alto Engineer
London, England, United Kingdom Full-time Posted 3 days ago
Opticore IT are currently searching for a SeniorPalo Alto Engineer to deliver perimeter security infrastructure and firewall policy separation across new PoP locations and existing infrastructure as part of a corporate divestiture programme, ensuring a clean perimeter security posture for both retained and divested entities ahead of Day 1. This opportunity will be joining a Broadcast Media client based in the London area with 2 days a week on site.
Opticore IT is a specialist Network Engineer and Project Management consultancy offering a wide variety of opportunities to work within fast-paced, challenging environments across our client base spanning multiple sectors including Finance, Broadcast Media, Telecommunications and more.
What you'll be doing:
At Opticore IT we embrace diversity and are committed to equal opportunities. We actively recruit for an inclusive and diverse workforce and as such, want to ensure we do everything we can to support your application.
We want you to feel empowered to let us know if you require any adjustments to be made with your application or interview process so please speak to our recruitment team.
Opticore IT is a specialist Network Engineer and Project Management consultancy offering a wide variety of opportunities to work within fast-paced, challenging environments across our client base spanning multiple sectors including Finance, Broadcast Media, Telecommunications and more.
What you'll be doing:
- Design and deploy Palo Alto firewalls at new PoP locations, configuring security zones, interfaces, and routing integration with internet edge and core routing
- Analyse existing firewall rulebase to identify rules belonging to each entity.
- Build security policy rulebase covering internet egress/ingress, inter-zone, and partner connectivity, plus NAT policies for internet-facing services
- Implement URL filtering, threat prevention, anti-spyware, file blocking, WildFire integration, and SSL decryption policies
- Configure Panorama device groups, template stacks, and RBAC to enforce entity administrative separation, and manage shared and device-group-specific policy rules
- Analyse existing firewall rulebase, migrate retained-entity policies to new Panorama device groups, and remove retained-entity rules, address objects, and service objects from divested-entity firewalls
- Deploy firewalls in active/passive or active/active HA pairs at PoP locations and validate failover behaviour under test conditions
- Configure third-party, partner, and inter-PoP firewall policy including DMZ and partner zones for controlled external access
- Reconfigure Panorama RBAC to restrict divested admin access to divested device groups only and validate divested-entity perimeter is clean for Day 1
- Coordinate with the core routing team on internet edge and PoP integration, the Zscaler engineer on GRE tunnel termination, and the automation team on firewall-as-code approaches
- Produce low-level designs, technical working papers, and decision records, and participate in design assurance reviews
- Deep hands-on experience with PA-3200/5200/400 or VM-Series and Panorama (device groups, templates, template stacks). Application-based policy, User-ID, Content-ID. NAT (source, destination, bi-directional). Log forwarding to SIEM.
- Zone-based firewall architecture and micro-segmentation principles. Active/passive and active/active HA including session synchronisation and failover thresholds.
- Analysing and rationalising complex legacy rulebases. Migration/cutover plans with rollback. Rule auditing, cleanup, and optimisation. GlobalProtect VPN configuration where required.
- Full threat prevention suite (antivirus, anti-spyware, vulnerability protection, URL filtering, WildFire). SSL/TLS decryption (forward proxy, inbound inspection) and certificate management.
- Strong TCP/IP, stateful inspection, and packet flow through firewalls. IPSec/IKEv2/GRE for site-to-site VPN. Routing integration with firewalls (BGP, OSPF, static, PBF).
At Opticore IT we embrace diversity and are committed to equal opportunities. We actively recruit for an inclusive and diverse workforce and as such, want to ensure we do everything we can to support your application.
We want you to feel empowered to let us know if you require any adjustments to be made with your application or interview process so please speak to our recruitment team.