Principal Network Security Architect | Palo Alto Networks
Overview
You will own the architectural blueprint and governance for a global network security footprint spanning hybrid cloud and on-prem. As Principal Enterprise Network Security Architect, you will drive Zero Trust adoption, security automation, and AI/ML integration. You will collaborate with security, infrastructure, and IT teams to embed security into every layer. This role stands out for its automation-first approach and ultimate escalation authority during critical events.
What You'll Do8
- 1Own the architectural blueprint and governance for the global network security footprint, scaling across hybrid environments.
- 2Define and enforce enterprise-wide security policies including segmentation, access control, and traffic inspection.
- 3Drive security integration into all network design layers, collaborating with security, infrastructure, and IT teams.
- 4Identify vulnerabilities and lead complex remediations across on-prem and cloud environments.
- 5Implement Palo Alto Networks products and third-party platforms to boost network visibility and threat intelligence.
- 6Champion network security automation with scripting, CI/CD pipelines, and Terraform or Ansible.
- 7Serve as the escalation authority for critical security events and design long-term remediations.
- 8Mentor senior engineers and shape architectural standards for a security-first culture.
Requirements10
- 112+ years in enterprise networking and network security engineering with leadership in large-scale environments.
- 2Deep expertise in Zero Trust architecture and advanced network segmentation.
- 3Proven experience with hybrid-cloud infrastructures on AWS, Azure, or GCP.
- 4Advanced capability writing infrastructure-as-code with Terraform or Ansible.
- 5Strong skill in building CI/CD pipelines.
- 6Experience leveraging AI/ML tools for operational tasks and auto-healing.
- 7Understanding of AI and LLM architectures, including data flows and APIs.
- 8Expertise in firewall technologies, VPN, IDS/IPS, NAC, and micro-segmentation.
- 9Mastery of routing, switching, and TCP/IP; experience with Arista or Juniper hardware.
- 10Local to SF Bay Area.
Salary Insight
$154 - $250k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Purple Drive Technologies LLC
VerifiedNetwork Security Engineer / Firewall Architect
You own the design and implementation of network security infrastructure at Purple Drive Technologies, securing enterprise networks with Palo Alto and Cisco firewalls. You architect zero-trust access, segment networks, and harden cloud boundaries with Azure Firewall. You collaborate with DevOps and network teams to ship resilient security solutions. This role demands deep hands-on expertise, not just oversight, and you will drive firewall modernization from day one.

CCS Global Tech
VerifiedNetwork Security Administrator CCS Global Tech
Lead design and implementation of secure infrastructure to protect organizational assets. Manage identity and access controls across hybrid environments. Ensure compliance with industry standards while supporting rapid growth initiatives. Drive continuous improvement of security posture through proactive monitoring and incident response.
631 Booz Allen Hamilton_United States
VerifiedNetwork Architect Senior
Design and architect secure networks for DoD using advanced technologies. Lead development of enterprise-wide infrastructure while ensuring reliability and scalability. Optimize mission-critical systems through strategic network design and software implementation.
MetroSys
VerifiedNetwork Operations Engineer, Cisco & Palo Alto Firewalls
You will own network uptime and performance for enterprise infrastructure spanning data centers, branch sites, and cloud. Your stack centers on Cisco routing and switching, Palo Alto firewalls, VMware NSX, and SD-WAN across a regulated multi-site environment. You will join the infrastructure operations team and partner with security, cloud, and application groups. This role stands out for its depth in NSX and SD-WAN and the chance to shape network standards in a compliance-driven setting.

DatamanUSA, LLC
VerifiedNetwork Security Administrator - Palo Alto Firewalls
You will own the security posture of a Denver-based network, defending against threats across Palo Alto firewalls. You'll join a tight-knit team of engineers and report directly to the security lead. This 10-month contract offers you a chance to harden enterprise infrastructure with Cisco and Juniper gear, with a clear path to permanent hire.
Zoox
VerifiedSenior Staff Network Security Engineer Zoox
Design and maintain secure hybrid/multi-cloud network architectures (AWS/GCP) while enforcing zero-trust access controls and network segmentation across corporate data centers and edge environments. Own next-generation firewall platforms and secure remote access solutions integrating SAML and Entra ID. Drive automation using Terraform Python and CI/CD pipelines to streamline security baselines and reduce manual toil.