Senior Network Security Engineer — Firewall Team (South FL, US)

About Us

For more than four decades, Compuquip Cybersecurity has designed, implemented, and operated security programs for organizations that cannot afford to get it wrong. Our teams deliver 24x7 detection and response, managed firewall and network security, vulnerability management, and offensive security services across cloud, network, and endpoint environments.

We are evolving how those services are delivered. Rather than having analysts triage every alert and engineers hand-write every change, we are building AI systems that handle reasoning work at scale so our people can focus on judgment, escalation, and customer outcomes. This work runs against live customer environments with real service commitments attached.

 

About The Role

This role would join our Firewall Team as a senior technical resource, embedded on-site with an enterprise customer and backed by the wider Compuquip engineering organization. 

The work is more than firewall administration. You will design and modernize network security architectures, lead migrations and platform transitions, and troubleshoot problems that cross firewalls, routing, VPN, segmentation, and cloud boundaries. 

We are looking for a senior engineer with a deep networking foundation who will take ownership and operate autonomously.

 

What You Will Work On

Firewall architecture and policy.
Design, implement, and optimize Palo Alto Networks environments across an enterprise environment. Including Panorama, security policies and profiles, threat prevention, application control, NAT, zoning, and high-availability configurations 

End-to-end troubleshooting.
Complex issues spanning firewalls, routing, switching, VPN, NAT, and segmentation. Traffic flow analysis, firewall logs, PCAPs, and telemetry, worked to root cause rather than to a workaround that holds until next quarter.

VPN and connectivity architecture.
Site-to-site and remote-access designs, IPsec/IKE and GRE, and the dependencies that make them fragile in real customer networks.

Lifecycle and migration work.
Upgrades, platform transitions, multi-vendor migrations, and architecture modernization, including the implementation planning, change planning, and peer validation.

Architectural guidance.
Reviewing what exists, identifying where security, reliability, performance, or operability is being quietly compromised, and recommending the fix rather than absorbing the symptom.

Engineering standards.
Documentation, runbooks, and design patterns that make the next engineer's work easier, plus mentorship and technical guidance for less experienced engineers on the team.


What You Will Bring

Network Security Engineering:

  • 8+ years in network security engineering, network engineering, or a related infrastructure security discipline, with significant hands-on time on enterprise firewall platforms.

  • Strong hands-on experience with Palo Alto Networks, and ideally Check Point or Fortinet alongside it.

  • Palo Alto Next-Generation Firewall Engineer certification preferred

  • Comfort designing and supporting high-availability firewall architectures, centralized logging and management, and multi-site policy at scale.

Enterprise networking

  • Real depth in routing and switching, IP addressing and subnetting, VLANs, segmentation, NAT, VPN technologies, and network security architecture.

  • Working knowledge of IPsec/IKE, GRE, BGP, OSPF, ACLs, and security zoning

  • The ability to follow a flow across multiple layers of the network and security stack and find the actual cause.

How you work

  • You operate independently. You take a complex problem from investigation to resolution without being managed through it.

  • You communicate clearly with engineers and non-engineers alike as well as directly with the customer

  • You take ownership of outcomes rather than tasks, and you make the case for your technical decisions rather than just asserting them.

  • You bring a service mindset to a security-first recommendation.

  • You reside in South Florida and can work on-site at the customer environment.


Nice to Haves

  • Multi-vendor depth across Palo Alto Networks, Check Point, and Fortinet.

     

  • OT/ICS environments and industrial network security.

     

  • Managed services or multi-customer experience — knowing how to context-switch across environments without dropping standards.

     

  • Large-scale, distributed, or highly available enterprise network security architecture.

     

  • RADIUS, TACACS+, and 802.1X.

     

  • Automation, scripting, APIs, or infrastructure as code.

     

  • SIEM, centralized logging, or network security analytics platforms.

     

  • Cloud and hybrid networking.


How We Work:

Three things define how we operate:

We get it done. We plan the change, validate it, and ship it. We would rather resolve the underlying architectural problem this quarter than manage around it for another year.

We work as a team. Nothing here gets built in isolation. Our best work comes from engineers, architects, and analysts solving problems in the same room, and we expect people to ask for help early and offer it freely.

We are customer obsessed. Every design decision is measured by whether it makes a customer safer or a service better. That is the standard, and it applies to internal standards as much as anything a customer sees.


Compensation:

$150,000–$170,000 base salary, plus a 10% discretionary annual bonus, health and dental coverage. On-site in South Florida with occasional remote flexibility. We will be direct about the number early in the process.

 

Apply for this job by reaching out to ai@compuquip.com with your resume and cover letter. 

What are you looking for?