Sr Palo Alto Integration Engineer
- Koniag Government Services
- Washington, United States
- $120,000 – $150,000
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Palo Alto Integration Engineer (Senior) to support enterprise network security operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
This role serves as a critical senior technical function responsible for the architecture, engineering, implementation, administration, and continuous improvement of enterprise Palo Alto Networks security platform capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, and hybrid network environments.
The ideal candidate is a highly experienced and technically authoritative network security engineer with deep, hands-on expertise across the full Palo Alto Networks portfolio—including Next-Generation Firewalls (NGFW), Panorama, Prisma Access, Prisma Cloud, Cortex XDR, and related platforms—combined with a comprehensive understanding of enterprise network security architecture, Zero Trust principles, and Federal cybersecurity compliance requirements. This individual must possess the technical depth, architectural vision, and operational discipline required to lead the design, implementation, and sustained operation of enterprise-grade Palo Alto Networks security capabilities that protect Government networks, systems, and data in a highly regulated federal IT environment.
The Palo Alto Integration Engineer (Senior) will serve as the program's primary subject matter expert and technical authority for all Palo Alto Networks platform capabilities, leading the architecture, engineering, implementation, administration, and continuous improvement of enterprise Palo Alto Networks security infrastructure. This individual works closely with network engineers, security engineers, cloud operations teams, DevSecOps engineers, cybersecurity leadership, and Government stakeholders to ensure Palo Alto Networks platforms are architected, deployed, and operated in a manner that delivers maximum security value, operational resilience, and compliance with Federal cybersecurity frameworks and Zero Trust Architecture objectives across the full enterprise environment.
Principal responsibilities will include but are not limited to:
Architecture & Engineering Leadership
• Serve as the program's technical authority and subject matter expert for all Palo Alto Networks platform capabilities, providing authoritative architectural guidance, engineering leadership, and expert technical recommendations to program leadership, functional teams, and Government stakeholders.
• Lead the design and architecture of enterprise Palo Alto Networks security solutions, including NGFW deployments, Panorama management infrastructure, Prisma Access SASE implementations, Prisma Cloud security posture management, and Cortex XDR endpoint and network detection capabilities.
• Develop and maintain enterprise Palo Alto Networks architecture documentation, including network security architecture diagrams, data flow diagrams, firewall zone models, security policy frameworks, and platform configuration baselines, ensuring documentation is current, accurate, and aligned with operational reality.
• Lead security architecture reviews for new systems, applications, infrastructure changes, and cloud migrations, assessing Palo Alto Networks platform impact, identifying security risks, and recommending policy and configuration changes to maintain security posture.
• Design and implement Zero Trust network security architectures leveraging Palo Alto Networks capabilities, including App-ID based application control, User-ID based identity-aware policy enforcement, micro-segmentation, encrypted traffic inspection, and continuous threat prevention.
• Evaluate emerging Palo Alto Networks technologies, platform capabilities, and industry security trends, providing well-researched recommendations to program leadership and Government stakeholders on opportunities to enhance security posture and operational efficiency.
• Provide senior technical leadership and mentorship to junior and mid-level network security engineers, sharing expertise, guiding technical development, and ensuring consistent application of security engineering best practices across the team.
Next-Generation Firewall Engineering & Administration
• Lead the engineering, implementation, and administration of enterprise Palo Alto Networks Next-Generation Firewall (NGFW) infrastructure across all deployment contexts, including perimeter, internal segmentation, data center, and cloud-attached firewall deployments.
• Design, implement, and maintain comprehensive NGFW security policy frameworks, including application-based policies using App-ID, user-based policies using User-ID, content inspection policies using Content-ID, and threat prevention policies, ensuring policies are well-structured, consistently applied, and aligned with least-privilege access control principles.
• Implement and maintain advanced NGFW security profiles, including antivirus, anti-spyware, vulnerability protection, URL filtering, file blocking, WildFire malware analysis, and DNS security profiles, ensuring profiles are tuned to maximize threat prevention effectiveness while minimizing operational disruption.
• Design and implement SSL/TLS decryption policies, ensuring encrypted traffic is inspected in accordance with security requirements while managing certificate trust, performance impact, and privacy considerations.
• Manage NGFW security policy lifecycle, including policy review and optimization cycles, rule base cleanup, shadow rule identification, and policy documentation maintenance, ensuring the rule base remains clean, efficient, and security-effective over time.
• Conduct regular NGFW security policy audits and optimization reviews, identifying overly permissive rules, unused policies, and policy gaps, and implementing improvements to strengthen network segmentation and least-privilege access enforcement.
• Develop and maintain NGFW operational runbooks, troubleshooting guides, and standard operating procedures, ensuring the team has the documentation needed to operate and maintain NGFW infrastructure reliably and consistently.
Panorama Management Platform Engineering
• Lead the engineering, implementation, and administration of the Panorama centralized management platform, ensuring Panorama is properly configured, maintained, and leveraged to provide consistent, scalable, and auditable management of all deployed NGFW and related platform instances.
• Design and maintain Panorama device group and template hierarchies, ensuring management configurations are logically organized, consistently applied, and aligned with enterprise security policy requirements and operational management needs.
• Develop and maintain Panorama-based policy management frameworks, including shared policy structures, pre-rules, post-rules, and device group-specific policy configurations, ensuring policy management is efficient, consistent, and auditable.
• Implement and maintain Panorama role-based administration controls, ensuring administrative access privileges are properly configured and aligned with least-privilege principles and applicable Federal security requirements.
• Support Panorama platform upgrades, patches, and configuration changes, coordinating with the change management process and ensuring all changes are properly tested, documented, and approved prior to production implementation.
• Leverage Panorama logging and reporting capabilities to develop operational dashboards, security reports, and compliance evidence artifacts that support program leadership and Government stakeholder visibility requirements.
Prisma Access & SASE Engineering
• Lead the engineering, implementation, and administration of Palo Alto Networks Prisma Access Secure Access Service Edge (SASE) capabilities, ensuring secure, reliable, and high-performance remote access and cloud-delivered security services for distributed users and locations.
• Design and implement Prisma Access GlobalProtect configurations, including gateway deployments, agent configurations, split tunneling policies, and authentication integrations, ensuring remote users receive consistent security policy enforcement regardless of location.
• Configure and maintain Prisma Access security policy, threat prevention, URL filtering, and data loss prevention capabilities, ensuring cloud-delivered security services provide comprehensive protection aligned with enterprise security requirements.
• Support the integration of Prisma Access with enterprise identity platforms, including Microsoft Entra ID and Okta, ensuring identity-aware security policy enforcement and multi-factor authentication are consistently applied for all remote access scenarios.
• Monitor Prisma Access service health, performance, and security effectiveness, proactively identifying and resolving connectivity issues, performance degradation, and security policy gaps that may impact remote user experience or security posture.
Prisma Cloud Security Engineering
• Lead the engineering, implementation, and administration of Palo Alto Networks Prisma Cloud cloud security posture management (CSPM) and cloud workload protection (CWPP) capabilities across enterprise cloud environments, including AWS and Microsoft Azure Government.
• Configure and maintain Prisma Cloud compliance frameworks, security policies, and alert configurations, ensuring continuous visibility into cloud security posture, configuration compliance, and threat activity across all monitored cloud accounts and workloads.
• Develop and maintain Prisma Cloud custom compliance policies and security alerts aligned with applicable Federal security frameworks, including NIST SP 800-53, FedRAMP, CIS Benchmarks, and client-specific cloud security requirements.
• Integrate Prisma Cloud findings with the enterprise SIEM platform and vulnerability management program, ensuring cloud security posture data is incorporated into the program's broader security monitoring and remediation workflows.
• Support cloud security posture remediation activities, working with cloud operations teams to prioritize and remediate Prisma Cloud findings in accordance with defined risk-based remediation timelines.
Cortex XDR Engineering & Administration
• Lead the engineering, implementation, and administration of Palo Alto Networks Cortex XDR extended detection and response capabilities, ensuring the platform provides comprehensive endpoint, network, and cloud telemetry integration and high-fidelity threat detection across the enterprise environment.
• Configure and maintain Cortex XDR prevention policies, behavioral threat protection rules, and detection analytics, ensuring endpoint protection and detection capabilities are optimized for the enterprise environment.
• Develop and maintain Cortex XDR detection rules, behavioral analytics configurations, and BIOC (Behavioral Indicators of Compromise) content, aligned with the MITRE ATT&CK framework to ensure comprehensive coverage of relevant adversary TTPs.
• Integrate Cortex XDR with the enterprise SIEM platform, threat intelligence feeds, and SOAR capabilities, ensuring XDR telemetry and alerts are effectively incorporated into the program's broader security monitoring, detection, and response workflows.
• Conduct Cortex XDR alert triage, investigation support, and threat hunting activities, leveraging XDR telemetry to support incident response efforts and proactively identify undetected threats within the enterprise environment.
• Monitor Cortex XDR platform health, agent coverage, and detection output quality, proactively identifying and resolving platform issues, coverage gaps, and detection fidelity problems.
Threat Prevention & Security Effectiveness
• Lead the continuous improvement of threat prevention effectiveness across all Palo Alto Networks platforms, including regular review and optimization of threat prevention profiles, WildFire submission policies, DNS security configurations, and URL filtering policies.
• Develop and maintain WildFire integration configurations, ensuring unknown files and URLs are automatically submitted for analysis and that WildFire verdicts are effectively operationalized within NGFW and Cortex XDR security policies.
• Monitor and analyze threat prevention logs, WildFire analysis results, and threat intelligence feeds to identify emerging threat patterns, new attack techniques, and opportunities to improve prevention effectiveness.
• Support purple team and detection validation activities, coordinating with threat emulation efforts to validate Palo Alto Networks prevention and detection effectiveness and identify gaps requiring configuration improvements or policy updates.
• Develop and maintain threat prevention effectiveness metrics and reporting, providing program leadership and Government stakeholders with accurate visibility into prevention coverage, blocked threats, and security effectiveness trends.
Change Management & Operations
• Lead the preparation and submission of Palo Alto Networks change requests for Change Advisory Board (CAB) review, developing comprehensive implementation plans, technical impact assessments, rollback procedures, and test plans for all significant platform changes.
• Coordinate with the change management process to ensure all Palo Alto Networks platform changes are properly reviewed, approved, scheduled, and implemented without degradation to security posture or service availability.
• Conduct post-implementation reviews for significant Palo Alto Networks platform changes, documenting outcomes, unexpected impacts, and lessons learned to continuously improve the change execution process.
• Develop and maintain Palo Alto Networks operational runbooks, standard operating procedures, and knowledge base articles, ensuring the team has comprehensive, current documentation to support reliable and consistent platform operations.
• Support incident response activities involving Palo Alto Networks platforms, providing expert platform knowledge and configuration capabilities to containment, eradication, and recovery efforts.
Compliance, ATO & Continuous Monitoring
• Ensure all Palo Alto Networks platforms are configured and maintained in compliance with applicable Federal cybersecurity frameworks and requirements, including NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, applicable DISA STIGs, and client-specific cybersecurity policies.
• Support ATO activities for Palo Alto Networks platforms, including security control implementation documentation, system security plan (SSP) contribution, continuous monitoring reporting, and audit evidence collection.
• Conduct regular Palo Alto Networks platform configuration compliance assessments, identifying and remediating configuration deviations from applicable security baselines and DISA STIGs.
• Support vulnerability management activities for Palo Alto Networks platforms, including tracking, prioritizing, and remediating platform vulnerabilities identified through vendor advisories, vulnerability scanning, and continuous monitoring activities.
• Develop and maintain Palo Alto Networks compliance documentation, including configuration baseline specifications, security control implementation evidence, and audit artifacts supporting the program's ATO and continuous monitoring obligations.
Education and Experience:
Required:
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered.
• Minimum of 7 years of hands-on experience in network security engineering, firewall administration, or a closely related discipline, with at least 5 years of demonstrated hands-on experience engineering and administering Palo Alto Networks platforms in an enterprise environment.
• Demonstrated hands-on experience designing, implementing, and administering Palo Alto Networks NGFW infrastructure, including security policy development, threat prevention profile configuration, SSL decryption, and Panorama management.
• Experience with Palo Alto Networks Prisma Access SASE platform engineering and administration.
• Experience supporting network security operations in a federal government IT contracting environment, including familiarity with applicable Federal cybersecurity compliance frameworks.
• Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of offer.
Preferred:
• Prior experience serving as a senior Palo Alto Networks engineer or architect on a federal IT program of comparable scale and complexity.
• Hands-on experience with Palo Alto Networks Prisma Cloud and Cortex XDR platform engineering and administration.
• Experience supporting FedRAMP authorization activities and implementing cloud security controls leveraging Palo Alto Networks platforms within AWS GovCloud and/or Microsoft Azure Government environments.
Required Skills and Competencies:
• Deep technical expertise across the Palo Alto Networks platform portfolio, with demonstrated hands-on proficiency in NGFW policy engineering, Panorama administration, Prisma Access SASE configuration, and advanced threat prevention capabilities.
• Strong network security architecture skills with demonstrated ability to design, implement, and maintain enterprise-grade network security architectures incorporating Zero Trust principles, micro-segmentation, identity-aware policy enforcement, and encrypted traffic inspection.
• Advanced proficiency with Palo Alto Networks NGFW security policy development, including App-ID application control, User-ID identity-aware policies, Content-ID threat prevention, and SSL/TLS decryption policy design and implementation.
• Demonstrated experience with Panorama centralized management platform engineering, including device group and template hierarchy design, shared policy management, and role-based administration configuration.
• Strong knowledge of enterprise networking concepts, including routing protocols (BGP, OSPF, EIGRP), switching, VLANs, SD-WAN, VPN technologies (IPsec, SSL), and network segmentation architectures as they relate to Palo Alto Networks security platform integration.
• Experience with Palo Alto Networks Prisma Access SASE platform engineering, including GlobalProtect configuration, cloud-delivered security policy, and identity platform integration.
• Knowledge of Federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, applicable DISA STIGs, and CIS Benchmarks.
• Strong understanding of Zero Trust Architecture principles and demonstrated experience implementing Zero Trust network security controls leveraging Palo Alto Networks platform capabilities.
• Experience supporting ATO activities, including NIST SP 800-53 security control documentation, system security plan contribution, POA&M management, and continuous monitoring program support.
• Proficiency with network traffic analysis and troubleshooting tools, including Wireshark, packet capture analysis, and Palo Alto Networks native diagnostic and logging capabilities.
• Excellent written and verbal communication skills with demonstrated ability to develop comprehensive security architecture documentation, operational runbooks, and change management artifacts, and to present complex technical security information clearly to both technical and non-technical audiences.
• Strong leadership and mentorship skills with demonstrated ability to provide technical guidance, share expertise, and develop the capabilities of junior and mid-level team members.
Desired Skills and Competencies:
• Palo Alto Networks Certified Network Security Engineer (PCNSE) certification — strongly preferred.
• Palo Alto Networks Certified Security Automation Engineer (PCSAE) or Palo Alto Networks Certified Detection and Remediation Analyst (PCDRA) certification.
• Palo Alto Networks Certified Cloud Security Engineer (PCCSE) or equivalent Prisma Cloud certification.
• Certified Information Systems Security Professional (CISSP), GIAC Certified Enterprise Defender (GCED), or equivalent senior cybersecurity certification.
• Cisco Certified Network Professional Security (CCNP Security) or equivalent enterprise network security certification demonstrating broad network security knowledge complementary to Palo Alto Networks expertise.
• Experience with Palo Alto Networks Cortex XSOAR security orchestration and automation platform engineering and playbook development.
• Experience with Palo Alto Networks Cortex XDR extended detection and response platform engineering
Our Equal Employment Opportunity Policy:
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Skills
- Palo Alto Networks Firewalls
- Network Security
- Prisma Access
- Prisma Cloud
- Panorama
- Cloud Security
- Network Architecture



