← Back to all jobs

Principal Technical Consultant - Network Security

Ahead · United States · Posted 2026-08-17

Apply on the company site →

Job description

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation. At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD. We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived. We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD. We are seeking a Principal Technical Consultant to serve as the senior technical leader for network security engagements across four core pillars: next-generation firewall design and deployment (Palo Alto Networks, Cisco Secure Firewall, Fortinet), Cisco ISE-based network access control and identity services, load balancing and application delivery (F5 BIG-IP, including web application firewall and global server load balancing), and SASE and Zero Trust architectures (Zscaler, Palo Alto Prisma Access). Principal Technical Consultants design, deploy, and troubleshoot highly complex environments spanning multiple networking and security domains. They lead large, multi-technology projects, guide cross-functional delivery teams, and act as trusted advisors to client technical staff and executive leadership. This role owns end-to-end delivery from discovery and architecture through implementation, testing, cutover, and knowledge transfer, while also mentoring engineers across the organization, supporting sales campaigns as a subject matter expert, and building the reusable assets and industry content that advance the practice. Key Responsibilities - Firewall: Design and deploy Palo Alto Networks next-generation firewalls running PAN-OS, including App-ID, User-ID, and Content-ID enforcement, security profiles (Antivirus, Anti-Spyware, Vulnerability Protection, WildFire), SSL/TLS decryption, and centralized management through Panorama or Strata Cloud Manager. Design and deploy Fortinet FortiGate firewalls running FortiOS, including security profiles and inspection modes, virtual domains (VDOMs), centralized policy management through FortiManager, and logging and reporting through FortiAnalyzer. Design and deploy Cisco Secure Firewall Threat Defense (FTD) managed by on-premises Firewall Management Center or cloud-delivered Firewall Management Center through Cisco Security Cloud Control, including Snort 3 intrusion policies, malware defense, URL filtering, and high-availability pairs. Lead firewall migration programs including legacy Cisco ASA to FTD conversions and cross-vendor migrations to Palo Alto, Fortinet, or Cisco platforms, owning policy translation, rule base optimization, phased cutover, and rollback planning. Design network segmentation architectures using firewall zones, virtual routers, VDOMs, VRFs, and policy-based routing to enforce least-privilege north-south and east-west traffic controls. Implement firewall high availability designs including active/standby failover, active/active clustering, multi-context and multi-VDOM deployments, and state synchronization for large enterprise and service provider environments. Deploy cloud-native and virtual firewall solutions including Palo Alto Cloud NGFW for AWS and Azure, FortiGate virtual appliances across AWS, Azure, and GCP, and Cisco Secure Firewall Threat Defense Virtual for hybrid and cloud workload environments. Design and deploy site-to-site IPsec VPN and remote access VPN architectures using GlobalProtect, FortiClient, and Cisco Secure Client, including route-based and policy-based tunnel selection and redundant termination. Configure centralized logging, SIEM integration (Splunk, Microsoft Sentinel, syslog), and NetFlow/IPFIX export for traffic analytics, threat correlation, and compliance reporting. Perform firewall rule base optimization, policy cleanup, and compliance auditing to reduce attack surface and align with regulatory frameworks including PCI-DSS, HIPAA, and NIST 800-53. Automate firewall provisioning, configuration backup, and policy deployment using infrastructure-as-code tooling (Terraform, Ansible) and vendor APIs including the PAN-OS REST and XML APIs, the FortiOS REST API, and the Firewall Management Center REST API. Key Responsibilities - Network Access Control: Deploy Cisco Identity Services Engine (ISE) for 802.1X wired and wireless authentication, MAC Authentication Bypass (MAB), and RADIUS and TACACS+ device administration across campus, branch, and data center environments. Design and implement ISE authorization policies including Security Group Tags (SGTs) with TrustSec, downloadable ACLs (dACLs), dynamic VLAN assignment, and Adaptive Network Control for automated threat response. Configure ISE profiling services, posture assessment, and compliance enforcement to establish endpoint visibility and confirm that devices meet organizational security baselines before access is granted. Integrate ISE with Cisco network infrastructure (Catalyst switches, wireless LAN controllers, Secure Firewall) and third-party network access devices for consistent policy enforcement across heterogeneous environments. Deploy ISE guest portals, BYOD onboarding workflows, and certificate-based authentication (EAP-TLS) integrated with internal or external certificate authorities for secure device enrollment. Implement pxGrid integrations to share identity and session context between ISE, Cisco Secure Firewall, SIEM platforms, and third-party security tooling for unified policy enforcement. Design ISE distributed deployments spanning Policy Administration Nodes,