À propos de ce poste Principal Technical Consultant - Network Security chez Thinkahead
We are seeking a Principal Technical Consultant to serve as the senior technical leader for network security engagements across four core pillars: next-generation firewall design and deployment (Palo Alto Networks, Cisco Secure Firewall, Fortinet), Cisco ISE-based network access control and identity services, load balancing and application delivery (F5 BIG-IP, including web application firewall and global server load balancing), and SASE and Zero Trust architectures (Zscaler, Palo Alto Prisma Access). Principal Technical Consultants design, deploy, and troubleshoot highly complex environments spanning multiple networking and security domains. They lead large, multi-technology projects, guide cross-functional delivery teams, and act as trusted advisors to client technical staff and executive leadership. This role owns end-to-end delivery from discovery and architecture through implementation, testing, cutover, and knowledge transfer, while also mentoring engineers across the organization, supporting sales campaigns as a subject matter expert, and building the reusable assets and industry content that advance the practice.
Key Responsibilities - Firewall:
- Design and deploy Palo Alto Networks next-generation firewalls running PAN-OS, including App-ID, User-ID, and Content-ID enforcement, security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, WildFire), SSL/TLS decryption, and centralized management through Panorama or Strata Cloud Manager.
- Design and deploy Fortinet FortiGate firewalls running FortiOS, including security profiles and inspection modes, virtual domains (VDOMs), centralized policy management through FortiManager, and logging and reporting through FortiAnalyzer.
- Design and deploy Cisco Secure Firewall Threat Defense (FTD) managed by on-premises Firewall Management Center or cloud-delivered Firewall Management Center through Cisco Security Cloud Control, including Snort 3 intrusion policies, malware defense, URL filtering, and high-availability pairs.
- Lead firewall migration programs including legacy Cisco ASA to FTD conversions and cross-vendor migrations to Palo Alto, Fortinet, or Cisco platforms, owning policy translation, rule base optimization, phased cutover, and rollback planning.
- Design network segmentation architectures using firewall zones, virtual routers, VDOMs, VRFs, and policy-based routing to enforce least-privilege north-south and east-west traffic controls.
- Implement firewall high availability designs including active/standby failover, active/active clustering, multi-context and multi-VDOM deployments, and state synchronization for large enterprise and service provider environments.
- Deploy cloud-native and virtual firewall solutions including Palo Alto Cloud NGFW for AWS and Azure, FortiGate virtual appliances across AWS, Azure, and GCP, and Cisco Secure Firewall Threat Defense Virtual for hybrid and cloud workload environments.
- Design and deploy site-to-site IPsec VPN and remote access VPN architectures using GlobalProtect, FortiClient, and Cisco Secure Client, including route-based and policy-based tunnel selection and redundant termination.
- Configure centralized logging, SIEM integration (Splunk, Microsoft Sentinel, syslog), and NetFlow/IPFIX export for traffic analytics, threat correlation, and compliance reporting.
- Perform firewall rule base optimization, policy cleanup, and compliance auditing to reduce attack surface and align with regulatory frameworks including PCI-DSS, HIPAA, and NIST 800-53.
- Automate firewall provisioning, configuration backup, and policy deployment using infrastructure-as-code tooling (Terraform, Ansible) and vendor APIs including the PAN-OS REST and XML APIs, the FortiOS REST API, and the Firewall Management Center REST API.
Key Responsibilities - Network Access Control:
- Deploy Cisco Identity Services Engine (ISE) for 802.1X wired and wireless authentication, MAC Authentication Bypass (MAB), and RADIUS and TACACS+ device administration across campus, branch, and data center environments.
- Design and implement ISE authorization policies including Security Group Tags (SGTs) with TrustSec, downloadable ACLs (dACLs), dynamic VLAN assignment, and Adaptive Network Control for automated threat response.
- Configure ISE profiling services, posture assessment, and compliance enforcement to establish endpoint visibility and confirm that devices meet organizational security baselines before access is granted.
- Integrate ISE with Cisco network infrastructure (Catalyst switches, wireless LAN controllers, Secure Firewall) and third-party network access devices for consistent policy enforcement across heterogeneous environments.
- Deploy ISE guest portals, BYOD onboarding workflows, and certificate-based authentication (EAP-TLS) integrated with internal or external certificate authorities for secure device enrollment.
- Implement pxGrid integrations to share identity and session context between ISE, Cisco Secure Firewall, SIEM platforms, and third-party security tooling for unified policy enforcement.
- Design ISE distributed deployments spanning Policy Administration Nodes, Policy Service Nodes, and Monitoring and Troubleshooting Nodes to meet scale, redundancy, and geographic distribution requirements.
- Extend identity-based segmentation beyond the access layer by propagating SGTs into firewall and fabric policy through SGACLs and SXP, aligning NAC policy with the broader segmentation architecture.
- Lead ISE upgrades and migrations, including legacy ACS to ISE transitions and major version upgrades, and perform advanced troubleshooting using RADIUS live logs, policy trace, packet capture, and debug utilities.
- Deliver HPE Aruba ClearPass engagements where a client has standardized on ClearPass for network access control, including policy design, device profiling, and onboarding workflows.
Key Responsibilities - Load Balancing & Application Delivery:
- Design and deploy F5 BIG-IP Local Traffic Manager, including virtual servers, pools, health monitors, persistence profiles, SSL offload and re-encryption, local traffic policies, and iRules for advanced traffic steering and content switching.
- Implement global server load balancing with F5 BIG-IP DNS, including wide IPs, GSLB pools, topology records, static and dynamic load balancing methods, iQuery synchronization with LTM devices in each data center, and DNS TTL strategies tuned to required failover times.
- Deploy and tune F5 BIG-IP Advanced WAF, including OWASP Top 10 protection, attack signature selection and tuning, positive and negative security models, Policy Builder learning workflows, behavioral DoS, bot defense, credential stuffing protection, and DataGuard response masking.
- Implement API security controls including OpenAPI specification import and schema enforcement, JSON and XML payload validation, and discovery of undocumented endpoints surfaced through policy learning.
- Design BIG-IP high availability using Device Service Clustering, sync-failover device groups, traffic groups, and network failover for active/standby and active/active deployments across data centers and cloud regions.
- Deploy F5 BIG-IP Access Policy Manager for application access and identity federation, and F5 BIG-IP SSL Orchestrator for policy-based SSL/TLS decryption with dynamic service chaining to next-generation firewalls, intrusion prevention, DLP, and sandbox inspection services.
- Deliver NGINX Plus and NGINX App Protect deployments, including Kubernetes ingress controller integration, WAF policy delivered through APPolicy custom resource definitions, and container-native application protection for microservices architectures.
- Implement F5 Distributed Cloud services including Web Application and API Protection, bot defense, multi-cloud application connectivity, and DNS-based global load balancing delivered as a managed service.
- Architect cloud-native load balancing and application protection using AWS Application and Network Load Balancers with AWS WAF, and Azure Application Gateway and Front Door with Azure WAF, including hybrid patterns that span on-premises BIG-IP and cloud-native services.
- Automate application delivery configuration using the F5 Automation Toolchain (AS3, Declarative Onboarding, and Telemetry Streaming), iControl REST, and the F5 Terraform provider, integrating declarative application services into client CI/CD pipelines.
- Lead application delivery controller refresh, consolidation, and migration programs, including application discovery, dependency mapping, virtual server translation, and phased cutover with validated rollback.
Key Responsibilities - SASE & Zero Trust:
- Design and implement SASE and Zero Trust architectures covering remote user, branch office, cloud workload, and data center connectivity use cases under a unified security policy framework.
- Configure and deploy Zscaler Internet Access including Secure Web Gateway, SSL inspection, URL filtering, cloud firewall, sandboxing, and inline DLP, and Zscaler Private Access including ZTNA application segments, App Connectors, and browser-based access.
- Deploy Palo Alto Prisma Access including GlobalProtect remote user connectivity, explicit proxy for branch offices, and service connections to on-premises infrastructure, managed through Strata Cloud Manager or Panorama, and extend coverage to unmanaged devices with Prisma Access Browser.
- Design traffic forwarding and steering architectures including GRE tunnels, IPsec tunnels, PAC files, and client connectors, with failover behavior and bandwidth planning validated against client site topology.
- Implement identity-based access controls integrating with Okta, Microsoft Entra ID, SAML 2.0, and SCIM provisioning, combined with device posture and trust signals, to enforce conditional access consistently across every SASE platform in scope.
- Design SASE and SD-WAN convergence strategies across Fortinet Secure SD-WAN, Palo Alto Prisma SD-WAN, and Cisco Catalyst SD-WAN, maintaining policy consistency across direct internet access and backhauled traffic paths.
- Deploy Cloud Access Security Broker and Data Loss Prevention controls in both inline and API-based modes to protect sanctioned and unsanctioned application usage.
- Design east-west segmentation to complement SASE north-south controls, using firewall zones and VRFs, ISE TrustSec Security Group Tags, and data center fabric segmentation through Cisco ACI contracts or VMware NSX distributed firewall policy.
- Develop and maintain Zero Trust maturity roadmaps for clients, mapping current-state gaps to phased adoption plans across the identity, device, network, application, and data pillars.
Architecture, Delivery & Documentation:
- Lead client-facing discovery sessions, design workshops, and architecture reviews to define firewall, network access control, application delivery, and SASE strategies aligned to business objectives and compliance requirements.
- Own the creation of High-Level Design and Low-Level Design documents, network diagrams, policy matrices, implementation runbooks, and as-built documentation across all technology domains in the engagement.
- Develop migration and cutover plans with rollback procedures, change management workflows, and change advisory board review packages.
- Own delivery of large, multi-technology engagements end to end, sequencing workstreams, tracking milestones and deliverables, and escalating risk proactively to project and account leadership.
- Serve as the design authority and technical escalation point for Senior Technical Consultants, Technical Consultants, and offshore engineers, reviewing configurations and design decisions before they reach the client.
- Contribute to engagement scoping through level-of-effort estimation, scope guardrails, and documented assumptions that produce accurate and profitable statements of work.
- Conduct knowledge transfer sessions and train client operations teams on day-2 firewall management, ISE policy administration, application delivery operations, SASE platform administration, and incident response procedures.
Practice Leadership & Business Development:
- Serve as a subject matter expert on sales campaigns, partnering with account teams to shape technical solutions, validate scope, and provide continuity through the transition from sales to delivery.
- Contribute standardized statement of work language, level-of-effort models, and proposal templates that improve scoping accuracy and reduce delivery inefficiency.
- Build reusable delivery assets including customer-facing design kits, templated runbooks, knowledge base articles, and enablement material that raise repeatability across the practice.
- Drive automation and delivery efficiency through reusable code, infrastructure-as-code patterns, deployment accelerators, and AI-assisted design and testing workflows.
- Mentor Senior Technical Consultants, Technical Consultants, and offshore engineers, supporting structured skill development and certification progression across the team.
- Develop high-impact industry content including reference architectures, white papers, blog articles, and conference or internal presentations that build market presence.
- Advance the delivery maturity of assigned service offerings, closing gaps in resource capability, documentation completeness, and automation coverage.
Required Qualifications:
- 10 or more years of network security, infrastructure security, or security engineering experience, with at least 4 years in a consulting, professional services, or client-facing delivery role.
- Demonstrated hands-on experience designing and deploying next-generation firewalls in enterprise production environments on at least two of the following platforms: Palo Alto Networks (PAN-OS and Panorama), Cisco Secure Firewall (FTD and FMC), and Fortinet (FortiGate and FortiManager).
- Production experience deploying Cisco ISE for 802.1X authentication, TACACS+ device administration, and network access policy enforcement across wired, wireless, and VPN environments, including distributed node deployments.
- Production experience with F5 BIG-IP application delivery, including Local Traffic Manager and at least one of BIG-IP DNS for global server load balancing or BIG-IP Advanced WAF.
- Production experience with at least one SASE platform, Zscaler (ZIA and ZPA) or Palo Alto Prisma Access, including secure web gateway, CASB, and ZTNA policy configuration and connector or traffic forwarding design.
- Strong understanding of routing protocols (BGP, OSPF, EIGRP), VPN technologies (IPsec, SSL/TLS), network segmentation, DNS, and Zero Trust architecture principles.
- Experience with cloud platforms (AWS VPC, Azure VNet, GCP VPC) including security groups, cloud firewalls, cloud-native load balancing, and hybrid connectivity architectures.
- Experience with identity and access management platforms (Okta, Microsoft Entra ID, SAML 2.0, SCIM) and their integration with firewall, network access control, application delivery, and SASE solutions.
- Experience integrating security platforms with SIEM (Splunk, Microsoft Sentinel) and syslog infrastructure, and automating deployment with Terraform, Ansible, and vendor REST APIs.
- Demonstrated record of independently leading large, multi-technology projects and cross-practice engagements, including directing the work of other technical resources.
- Executive-level written and verbal communication skills, with the ability to produce client-ready deliverables at varying levels of technical detail.
- Ability to travel at least 25 percent.
Preferred Qualifications:
- CCIE Security, or an equivalent expert-level certification in a core focus area.
- Palo Alto PCNSE or PCNSC; Fortinet NSE 7 or NSE 8; F5 Certified Technology Specialist (LTM, DNS, or ASM) or F5 Certified Solution Expert; Zscaler ZCCA or ZCCP; CCNP Security.
- CISSP or an equivalent industry security certification.
- Firewall migration experience including ASA to FTD conversions and cross-vendor platform migrations with rule translation and optimization.
- Microsegmentation exposure through Akamai Guardicore, VMware NSX distributed firewall and vDefend, or Cisco ACI contract-based segmentation.
- Experience with additional SSE platforms including Cisco Secure Access or Netskope.
- Experience with enterprise or regulated environments (healthcare, finance, government) including compliance frameworks such as PCI-DSS, HIPAA, NIST 800-53, and SOC 2.
- Multi-cloud and hybrid architecture experience spanning AWS, Azure, and GCP with infrastructure-as-code tooling (Terraform, Ansible, CloudFormation) and CI/CD pipeline integration.
- Prior consulting, professional services, or managed services background with experience scoping engagements, writing statements of work, and managing client delivery timelines and margin.
- Demonstrated experience mentoring engineers and authoring practice enablement or public-facing technical content.
Expectations:
- Recognized as a technical authority and industry leader within the network security practice.
- Operates independently on highly complex, multi-technology problems with minimal supervision.
- Owns the overall technical outcome of assigned engagements, including quality, documentation, and client satisfaction.
- Leads cross-functional and cross-practice delivery teams, delegating workstreams to Senior Technical Consultants and Technical Consultants.
- Drives strategic technical conversations with client architects, security leadership, and executives, and connects technical decisions to business objectives.
- Contributes materially to sales campaigns as a subject matter expert and supports the transition from sales to services.
- Identifies out-of-scope client requests and escalates to the project manager or account team before delivery impact occurs.
- Carries a 60 percent target utilization, with remaining capacity directed to pre-sales support, mentorship, practice development, and thought leadership.
Soft Skills:
- Executive-level communication skills with the ability to present technical strategies and risk assessments to C-level stakeholders and security leadership.
- Ability to scope engagements, set client expectations, and manage delivery timelines and profitability in a consulting environment.
- Self-directed, detail-oriented, and comfortable operating independently on-site at client facilities or leading remote delivery engagements.
- Collaborative approach to cross-functional work with networking, identity, cloud infrastructure, compliance, and application development teams.
- Skilled at translating complex technical concepts into business outcomes and actionable recommendations for non-technical audiences.
- Genuine interest in developing other engineers, with the patience and structure to grow capability rather than absorb the work.