Palo Alto Networks — Security Architect (Lead)
Experience: 15+ years in network/security engineering, with 5+ years hands-on Palo Alto Networks Location: Bangalore (Hybrid) / US-remote / Client-onsite as required Type: Full-time Reports to: Practice Lead / Delivery Head
Role Summary
We're looking for a Palo Alto Networks Security Architect to own the design authority for firewall and network-security engagements across our US telecom, healthcare IT, and data center clients. You'll translate client requirements into secure, scalable architectures, set the standards our engineers build to, and act as the senior technical voice in pre-sales and delivery conversations.
Key Responsibilities
-
Design end-to-end network security architectures built on Palo Alto Networks (NGFW, Panorama, Prisma Access, Prisma Cloud, Cortex) aligned to client and compliance requirements.
-
Lead migrations from legacy/other-vendor firewalls (Cisco ASA/Firepower, Check Point, Fortinet) to Palo Alto, including rule-base optimization and cutover planning.
-
Define reference designs, security policy frameworks, and hardening standards for the delivery team to execute against.
-
Own high-level and low-level design documents (HLD/LLD), architecture diagrams, and as-built documentation.
-
Support pre-sales: solutioning, effort estimation, SOW input, and client technical presentations.
-
Provide technical governance and escalation support across active engagements; mentor engineers.
-
Advise on segmentation, Zero Trust, SASE, and cloud-security posture across hybrid environments.
Required Skills
-
Deep expertise with PAN-OS: security/NAT policy, App-ID, User-ID, Content-ID, decryption, GlobalProtect.
-
Panorama for centralized management, templates, and device groups at scale.
-
Prisma Access / SASE and Prisma Cloud (CSPM) design experience.
-
Strong routing & switching fundamentals (BGP, OSPF, VLANs, VXLAN) and multi-vendor firewall exposure.
-
Firewall migration and large rule-base transformation experience.
-
Zero Trust and network segmentation design.
-
Cloud security across AWS and/or Azure.
Certifications (strongly preferred)
-
PCNSE (Palo Alto Networks Certified Network Security Engineer) — required
-
PCSAE / Prisma / Cortex certifications — a plus
-
CISSP, CCNP Security, or equivalent — a plus
Nice to Have
-
Experience delivering white-label for US system integrators.
-
Exposure to regulated environments (HIPAA/HITRUST for healthcare, data center compliance).
-
Automation/scripting for policy management (Python, Terraform, PAN-OS API).
Education
Bachelor's in Engineering / Computer Science or equivalent practical experience.