Data Security Analyst
Govcio LLC United States
IT System Data Services · 1,001-5,000 employees
About the role
The Data Security Analyst will lead the design, implementation, and optimization of enterprise security controls across data centers, cloud, and remote environments. They are responsible for managing firewall policies, investigating security incidents, and collaborating with cross-functional teams to ensure robust network security posture.
What they look for
Requirements
Candidates must have over 10 years of progressive experience in cybersecurity and network security, with deep expertise in Palo Alto Networks and Cisco technologies. A bachelor's degree is required, and the ability to attain and maintain an AOUSC Public Trust clearance is mandatory.
Full description
GovCIO is seeking a highly experienced Data Security Analyst — Master to lead the design, implementation, operation, and continuous improvement of enterprise security controls that protect data, networks, applications, and cloud-connected environments. This senior individual-contributor role requires deep hands-on expertise with the Palo Alto Networks security portfolio—particularly next-generation firewalls, Panorama, Cortex, and Strata—as well as strong Cisco networking and security capabilities.
This position will be located within the United States and will be a fully remote opportunity.
Responsibilities
- Architect, deploy, administer, and optimize Palo Alto Networks next-generation firewalls across data center, campus, branch, cloud, and remote-access environments.
- Lead centralized firewall management using Palo Alto Panorama, including device groups, templates, template stacks, shared policy, role-based administration, configuration standards, software lifecycle management, and high-availability operations.
- Design and maintain security policies using least privilege, application-aware controls, user identity, URL filtering, DNS security, TLS decryption where approved, threat prevention, WildFire analysis, anti-spyware, vulnerability protection, and file-blocking capabilities.
- Lead the operational use of the Palo Alto Networks Strata portfolio to improve network security posture, policy consistency, visibility, segmentation, and operational resilience.
- Deploy and operationalize Cortex capabilities for security analytics, endpoint detection and response, extended detection and response, incident investigation, automation, orchestration, and response improvement, as applicable to the enterprise environment.
- Investigate security alerts, anomalous traffic, malware activity, policy violations, data-exfiltration indicators, and firewall-related incidents; coordinate containment, eradication, recovery, and post-incident review activities.
- Develop and tune detections, correlation logic, dashboards, investigations, and response playbooks using Cortex tooling and integrated security platforms.
- Build and maintain secure network segmentation strategies, including zone-based architecture, east-west traffic controls, microsegmentation principles, and protections for high-value data systems.
- Partner with Cisco network engineering teams to integrate secure routing, switching, VPN, wireless, identity, and network-access controls. Troubleshoot issues across Cisco and Palo Alto environments without weakening security controls.
- Support and strengthen Cisco security technologies and enterprise network services, which may include Cisco ASA/Firepower, Cisco Secure Firewall Management Center, Cisco ISE, Cisco Secure Network Analytics, VPN, routing, switching, and wireless infrastructure.
- Review, approve, implement, and document firewall and network-security change requests according to established change-management, risk-review, and emergency-change processes.
- Perform regular firewall rulebase reviews, access recertifications, risk assessments, policy cleanup, unused-rule retirement, object normalization, and security-control validation.
- Maintain accurate network security diagrams, data-flow documentation, firewall standards, operational runbooks, architecture decisions, and escalation procedures.
- Conduct vulnerability and configuration assessments; validate remediation of high-risk findings affecting firewall, network, endpoint, and data-security controls.
- Collaborate with Security Operations Center, Incident Response, Cloud Engineering, Infrastructure, Application Development, Governance/Risk/Compliance, and Audit teams on security requirements and remediation plans.
- Provide technical mentorship to analysts and engineers; establish engineering standards and lead complex troubleshooting and root-cause analysis.
- Evaluate emerging technologies, platform features, and threat trends; recommend pragmatic improvements to the enterprise security roadmap.
•
Qualifications
Bachelor's with 12+ years (or commensurate experience)
- 10+ years of progressive experience in cybersecurity, network security, security engineering, or security operations, including substantial hands-on firewall administration and incident-response experience.
- Deep expertise administering Palo Alto Networks next-generation firewalls in complex enterprise environments.
- Advanced experience with Panorama, including centralized policy administration, device-group design, templates, HA workflows, logging, upgrades, troubleshooting, and configuration governance.
- Strong practical knowledge of Palo Alto Strata security capabilities, including NGFW architecture, App-ID, User-ID, Content-ID, security profiles, decryption, segmentation, and policy optimization.
- Strong experience using Palo Alto Cortex products or related XDR/EDR/SOAR/SIEM technologies for detection, investigation, incident response, threat hunting, and automation.
- Demonstrated ability to investigate and resolve complex network-security issues using packet captures, firewall traffic logs, threat logs, system logs, routing information, and endpoint telemetry.
- Strong Cisco networking background, including TCP/IP, DNS, DHCP, NAT, routing, switching, VLANs, VRFs, BGP/OSPF fundamentals, VPNs, network segmentation, and high-availability concepts.
- Experience supporting Cisco security and network technologies, such as Cisco Secure Firewall/Firepower, ASA, ISE, Secure Network Analytics, Catalyst switching, Nexus switching, enterprise routing, and wireless platforms.
- Thorough understanding of security principles including zero trust, least privilege, defense in depth, identity-aware access, network segmentation, threat prevention, encryption, logging, and vulnerability management.
- Experience with security frameworks and control expectations such as NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 27001, PCI DSS, HIPAA, SOX, or similar requirements, as applicable.
- Strong written and verbal communication skills, with the ability to explain complex technical risks and solutions to both technical and nontechnical stakeholders.
•
Clearance Required: Must be able to attain and maintain an AOUSC Public Trust
Preferred Skills and Experience
- Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field
- Palo Alto Networks certifications such as PCNSA, PCNSE,, or equivalent advanced Palo Alto Networks credentials.
- Cisco certifications such as CCNA, CCNP Enterprise, CCNP Security, CCIE Enterprise Infrastructure, CCIE Security, or equivalent experience.
- Experience with cloud networking and security in AWS, Microsoft Azure, and/or Google Cloud Platform, including cloud firewalls, transit architectures, virtual firewalls, security groups, and centralized logging.
- Experience with infrastructure-as-code, automation, or scripting using Python, PowerShell, Ansible, Terraform, REST APIs, or Panorama APIs.
- Experience with SIEM platforms, log pipelines, threat intelligence, vulnerability-management tools, and network detection and response capabilities.
- Experience leading security projects, technical workstreams, audit remediation, control modernization, or enterprise-wide firewall migrations.
#Dice
#CHNO
#JD
Posted Salary Range
USD $125,000.00 - USD $150,000.00 /Yr.