Senior Network Security Engineer
ON-SITE - Torrance, CaliforniaSenior Network Security Engineer3 - 6 month W2 (ONLY) contract - No C2C or 3rd partiesFree parking$65 - $75/hr. - Please let me know what you seek.Must Haves5+ years’ experience in network engineering and network securityProven hands-on experience with Palo Alto Networks firewalls (policy creation, NAT, routing, troubleshooting)Experience configuring and supporting GlobalProtect VPNExperience building site-to-site VPN tunnels with Azure and AWSWorking knowledge of 802.1X authentication (wired/wireless) and certificate-based network accessExperience with Ruckus switch configuration and routingWhat Success Looks LikeFirewall policies and routing are well-organized, documented, and optimized for security and performanceGlobalProtect VPN provides reliable, secure remote access for all authorized usersSite-to-site tunnels to Azure and AWS are stable and properly monitoredCertificate-based authentication (EZPKI/EZRadius) is integrated smoothly with minimal access disruptionsIoT devices and cameras are securely onboarded via 802.1X/TLS with minimal frictionRuckus switch routing is stable and correctly segmented across the networkSeeking a Senior Network Security Engineer to design, implement, and maintain enterprise network security infrastructure. This role focuses heavily on Palo Alto Networks firewall administration, secure remote access via GlobalProtect VPN, cloud connectivity across Azure and AWS, and network access control for wired, wireless, and IoT devices. The ideal candidate combines deep firewall/routing expertise with practical experience securing endpoints, cameras, and IoT devices through certificate-based (TLS/802.1X) authentication.Key ResponsibilitiesFirewall & Network SecurityConfigure and manage Palo Alto Networks firewall security policies, NAT rules, and threat prevention profilesDesign and implement Palo Alto Firewall routing (static, dynamic, and policy-based routing)Monitor, troubleshoot, and optimize firewall performance and rule setsVPN & Cloud ConnectivityBuild, configure, and maintain GlobalProtect VPN for secure remote accessCreate and manage site-to-site VPN tunnels between on-premises infrastructure and Azure and AWS environmentsTroubleshoot VPN connectivity, tunnel stability, and routing issues across hybrid cloud environmentsIdentity, Certificates & Access ControlIntegrate and manage EZPKI and EZRadius (Azure-based SaaS RADIUS and SaaS TLS/PKI services) for certificate-based network authenticationDeploy and support TLS-based 802.1X authentication for IP cameras and other IoT devicesConfigure 802.1X network access control policies across wired and wireless infrastructureSwitching & LAN InfrastructureConfigure and maintain routing on Ruckus switchesSupport VLAN segmentation, inter-VLAN routing, and network access policies for IoT and camera device segmentsCross-Functional / Nice-to-HaveSupport Prisma (Prisma Access / Prisma Cloud) initiatives as neededSupport Palo Alto CASB deployment and policy configuration as neededRequired Qualifications5+ years’ experience in network engineering and network securityProven hands-on experience with Palo Alto Networks firewalls (policy creation, NAT, routing, troubleshooting)Experience configuring and supporting GlobalProtect VPNExperience building site-to-site VPN tunnels with Azure and AWSWorking knowledge of 802.1X authentication (wired/wireless) and certificate-based network accessExperience with Ruckus switch configuration and routingStrong understanding of enterprise routing concepts (static routing, VLANs, inter-VLAN routing)Solid troubleshooting skills across firewall, VPN, and switching layersPerformed root-cause analysis on wireless access point failures, adjusted AP placement and power/range settings to optimize coverage, and resolved intermittent Wi-Fi connectivity issues. Skilled in wireless access point diagnostics, RF coverage tuning, and troubleshooting client connectivity and signal degradation issues.Preferred QualificationsExperience with Prisma Access and/or Prisma CloudExperience with Palo Alto CASBExperience with EZPKI / EZRadius or similar Azure-based SaaS RADIUS/PKI/TLS certificate servicesExperience deploying TLS/802.1X authentication for IoT devices and IP camerasRelevant certifications such as PCNSE (Palo Alto Certified Network Security Engineer), CCNP\CCNP Security, or similarLight automation such ansible, Terraform, SaltstackThe estimated pay range for this position is USD $65.00/hr - USD $75.00/hr. Exact compensation and offers of employment are dependent on job-related knowledge, skills, experience, licenses or certifications, and location. We also offer comprehensive benefits. The Talent Acquisition Partner can share more details about compensation or benefits for the role during the interview process***Notice to Job Seekers Regarding Impersonation and Fraudulent Job Offers***It has come to our attention that unauthorized individuals and entities are impersonating Milestone Technologies, Inc. on various job boards/portals, specifically Naukri.com and Linkedin.comPlease be advised of the following official Milestone Technologies recruitment policies:Official Communication ChannelsAll legitimate email communications from our recruitment team will originate ONLY from the domains: @milestone.tech. We do not use generic email services (e.g. @gmail.com, @yahoo.com, @outlook.com) or unofficial third party messaging apps to conduct formal business.No Recruitment FeesMilestone Technologies never requests any form of payment, "security deposit", "laptop/equipment fee", or "processing fee" at any stage of the recruitment or onboarding process. Any request for money in exchange for an interview or job offer is a scam.