Palo Alto Firewall SME (Project-Based | Azure Gov Environment)
Location: Remote (U.S.-Based Only)
Citizenship Requirement: U.S. Citizen (must currently reside in the United States)
Duration: Project-Based (Estimated 60–80 hours; potential for expansion based on assessment findings)
Schedule: Flexible; 2nd Shift Availability Preferred
Clearance: Not required to start; ability to support secure environments preferred
Position Overview
We are seeking a highly experienced Palo Alto Firewall Subject Matter Expert (SME) to support a short-term, project-based engagement focused on transitioning to the next-generation Palo Alto firewall platform within a production Azure Government environment.
This engagement will begin with a comprehensive assessment of the current network and security infrastructure, followed by the design and implementation of an optimized solution. The scope of work may range from incremental upgrades/patching of existing systems to a full-scale replacement and modernization effort, depending on assessment findings.
This role requires a senior-level engineer with deep Palo Alto expertise, strong networking fundamentals, and hands-on experience operating in secure cloud environments.
Key Responsibilities
Assessment & Discovery
- Conduct a detailed assessment of the current firewall and network environment
- Identify gaps, risks, and modernization opportunities
- Evaluate whether existing infrastructure can be upgraded or requires replacement
- Provide clear recommendations and implementation roadmap
Solution Design
- Architect a scalable and secure next-generation Palo Alto firewall solution
- Design for Azure Government cloud integration and compliance requirements
- Define network segmentation, security policies, and access controls
- Align design with best practices for performance, security, and maintainability
Implementation & Migration
- Execute firewall upgrades, reconfigurations, or full replacement as required
- Configure and deploy Palo Alto firewalls (physical and/or virtual)
- Implement security policies, NAT rules, VPNs, and routing configurations
- Ensure minimal disruption to production systems during transition
Validation & Optimization
- Perform testing and validation of the implemented solution
- Optimize performance, security posture, and reliability
- Provide documentation and knowledge transfer to internal stakeholders
Required Qualifications
- 10+ years of hands-on experience with Palo Alto Networks firewalls (SME-level expertise)
- Strong background in network engineering (routing, switching, security architecture)
- Proven experience designing and implementing firewall solutions in production environments
- Hands-on experience working in Microsoft Azure (Azure Government preferred)
- Ability to independently assess, design, and implement solutions with minimal oversight
- U.S. Citizenship and current residence in the United States
Preferred Qualifications
- CompTIA Security+ certification (or equivalent security certification)
- Azure certifications (e.g., AZ-104, AZ-500)
- Experience with cloud network security and hybrid environments
- Prior experience supporting federal or DoD environments
Additional Details
- This is a short-duration, high-impact engagement estimated at 60–80 hours, though scope may expand based on initial assessment findings
- Ideal for a senior consultant or independent SME capable of quickly evaluating and executing complex network/security transformations
- Flexible scheduling available, with preference for candidates open to 2nd shift work
Summary
This role is ideal for a senior Palo Alto expert who can step in, quickly assess an environment, and determine the most effective path forward—whether that's targeted upgrades or a full infrastructure overhaul—and execute with precision in a secure Azure Government environment.
Marathon TS is committed to the development of a creative, diverse and inclusive work environment. In order to provide equal employment and advancement opportunities to all individuals, employment decisions at Marathon TS will be based on merit, qualifications, and abilities. Marathon TS does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age or any other characteristic protected by law (referred to as "protected status").