Firewall Design

2 weeks ago


Sydney, New South Wales, Australia AYAN INFOTECH PTY LTD Full time $120,000 - $180,000 per year

AYAN InfoTech is looking for Firewall Design (Palo Alto) - Security Specialist/Network Technical Specialist to join an exciting project based in Sydney / Melbourne / Canberra. The role offers you the opportunity to contribute towards an extremely well structured and mature environment, working on sophisticated enhancement projects.

Role: Firewall Design (Palo Alto) - Security Specialist/Network Technical Specialist

Location: Sydney / Melbourne / Canberra

Contract Duration: 6 to 9 Months with high possible extensions

Experience: 7+ Years

Available Roles: Firewall Design (Palo Alto) - Security Specialist/Network Technical Specialist, Infrastructure and Platform Architect.

Job description: Job Title: Technical L3 SME (Network Technical consultant)

Role Overview

As a BGP Technical L3 SME, you will lead the design, implementation, and optimization of Border Gateway Protocol (BGP) configurations across enterprise and customer networks. Your expertise will ensure resilient, scalable, and secure routing architectures that support high availability and minimal service disruption.

Key Responsibilities

  • Route-Map Implementation - Design and deploy inbound and outbound BGP route-map updates to control prefix advertisement, path selection, and policy enforcement.
  • Resilient Routing Design - Apply advanced BGP routing patterns-including local preference, AS path prepending, MED tuning, and conditional advertisements-to achieve site-level redundancy and failover.
  • Change Governance - Ensure all routing changes adhere to industry best practices, internal standards, and change management protocols, minimizing risk of service impact.
  • Platform Expertise - Configure BGP on platforms such as Cisco IOS/IOS-XE, NX-OS, Juniper, and Arista
  • Support BGP in hybrid cloud, MPLS, and SD-WAN environments
  • Integrate BGP with IGPs (OSPF, EIGRP) and route redistribution policies
  • Advanced Troubleshooting - Act as the L3 escalation point for BGP-related incidents, performing diagnostics using CLI, route analytics, and packet captures.
  • Monitoring & Optimization - Use tools like BGPmon, ThousandEyes, SolarWinds, or NetBrain to monitor route stability, convergence times, and prefix health.
  • Documentation & RCA - Maintain detailed configuration records, topology diagrams, and root cause analysis reports for recurring routing anomalies.

Job Title: Technical SME - Palo Alto, Check Point & Cisco FTD Firewalls [Security Technical SME - L3]

Role Overview:

As a Technical L3 SME for Firewall Platforms, you will lead the design, implementation, and lifecycle management of firewall policies across Palo Alto Networks, Check Point, and Cisco FTD environments. You'll ensure secure, compliant, and efficient rule management aligned with customer's security standards and customer-specific requirements.

Key Responsibilities:

  • Firewall Rule Creation & Validation - Design and implement new firewall rules with pre-deployment validation to prevent duplication, policy conflicts, and ensure alignment with customer's security standards.
  • Policy Modification & Optimization - Update existing firewall policies to incorporate new source IPs, destinations, and ports, ensuring minimal disruption and consistent access control.
  • Rule Decommissioning - Identify and safely remove obsolete or unused firewall rules, maintaining a clean and efficient policy base across platforms.
  • Policy Lifecycle Management - Ensure consistent policy governance, documentation, and change control across multi-vendor environments and customer-specific deployments.
  • Platform Expertise - Palo Alto Networks: Manage security policies, App-ID, User-ID, and Panorama-based deployments
  • Check Point: Administer SmartConsole, rule base tuning, and threat prevention modules.
  • Cisco FTD: Configure policies via FMC, manage access control, NAT, and SSL inspection
  • Advanced Troubleshooting & Escalation - Serve as the L3 escalation point for firewall-related incidents, performing diagnostics using CLI, logs, and packet captures.
  • Compliance & Documentation - Maintain detailed records of rule changes, policy reviews, and audit logs to support security compliance frameworks (ISO 27001, NIST, PCI-DSS).

Job Title: SSL VPN L3 SME - Palo Alto & Cisco [Security Technical SME]

Role Overview:

As an SSL VPN L3 SME, you will lead the secure provisioning and governance of remote access infrastructure using Palo Alto GlobalProtect and Cisco AnyConnect. You'll ensure that VPN connectivity is tightly controlled, policy-driven, and aligned with enterprise security standards.

Key Responsibilities:

  • VPN Profile Provisioning - Provision and manage SSL VPN profiles for internal users and third-party vendors, ensuring secure and role-based access.
  • Access Policy Enforcement - Design and implement fine-grained routing and firewall rules to control traffic flow across VPN tunnels, enforcing least-privilege access.
  • Infrastructure Access Control - Ensure that VPN users can only access authorized infrastructure services, using endpoint posture checks, group-based policies, and certificate-based authentication.
  • Platform Expertise - Configure and maintain Palo Alto Global Protect gateways and portals
  • Administer Cisco ASA/Firepower with AnyConnect profiles and policies
  • Integrate VPN platforms with identity providers (LDAP, RADIUS, SAML, Azure AD)
  • Troubleshooting & Escalation - Act as the L3 escalation point for VPN-related incidents, performing advanced diagnostics using CLI, logs, and packet captures.
  • Compliance & Documentation - Maintain detailed documentation of VPN configurations, access policies, and change records to support audit and compliance requirements (ISO 27001, NIST, GDPR).

Required Skills & Qualifications

  • 5+ years in network security or remote access engineering
  • Hands-on experience with: Palo Alto GlobalProtect (portal/gateway configuration, HIP profiles)
  • Cisco ASA/Firepower with AnyConnect (group policies, DAP)
  • SSL/IPsec VPN protocols, split tunneling, and endpoint posture validation
  • Strong understanding of Firewall rule design, NAT policies, and routing logic
  • Authentication protocols (SAML, RADIUS, LDAP)
  • SIEM integration and log analysis

Contact: for more details.

Please note we will be able to contact only shortlisted candidates for this role. We thank you in advance for your interest.



  • Sydney, New South Wales, Australia Talent Full time $120,000 - $180,000 per year

    A leading Financial Services provider is seeking a Network Security Designer with strong firewall (Fortinet and/or Juniper SRX) and F5 load balance expertise to join their team on a permanent basis.Joining a fast-paced, collaborative team environment, this role will be responsible for the design of a range of project initiatives within their large, complex...


  • Sydney, New South Wales, Australia Bluefin Resources Pty Limited Full time $120,000 - $180,000 per year

    A major bank is seeking a Senior Network Security Engineer (Firewalls and F5) for a permanent role.This is a mix of design and implementation work across Firewalls- Fortinet, Juniper SRX and F5. Responsibilities: Key Duties: Undertake project design and architecture work, like High-level and detailed design work.Installation, configuration and upgrade...


  • Sydney, New South Wales, Australia AC3 Pty Limited Full time $120,000 - $180,000 per year

    Our client is seeking a Senior Network Engineer with strong firewall and security expertise to join their expanding and motivated team. The role will see you working extensively with Palo Alto firewalls (must-have), while also leveraging experience across Fortinet and broader networking technologies. You'll balance operational responsibilities with project...


  • Sydney, New South Wales, Australia HELYXON HEALTHCARE SOLUTIONS PRIVATE LIMITED Full time $120,000 - $180,000 per year

    Job Title: Cyber Security Program ManagerLocation: Sydney or MelbourneDuration: 9 – 12 monthsPosition Summary:We are seeking a seasoned and strategic Cyber Security Program Manager with over 15 years of experience in cybersecurity, including hands-on expertise in firewall design, configuration, and migration using technologies such as CISCO ASA/Firepower...

  • Project Manager

    1 week ago


    Sydney, New South Wales, Australia HELYXON TECHNOLOGIES PRIVATE LIMITED Full time $120,000 - $180,000 per year

    JobTitle:Cyber Security Program ManagerLocation:Sydney or MelbourneDuration: 9 – 12 monthsPosition Summary:We are seeking a seasoned and strategic Cyber Security Program Manager with over 15 years of experience in cybersecurity, including hands-on expertise in firewall design, configuration, and migration using technologies such as CISCO ASA/Firepower and...


  • Sydney, New South Wales, Australia ITbility Full time $120,000 - $200,000 per year

    Technical L3 SME for Firewall PlatformsSydney/MelbourneContract - 6 + MonthsOur client in Sydney is looking forTechnical L3 SME for Firewall Platformsconsultant this is aPermanentrole. Please email me at for more information.Job description:As aTechnical L3 SME for Firewall Platforms, you will lead the design, implementation, and lifecycle management of...


  • Sydney, New South Wales, Australia World Wide Technology Full time $120,000 - $180,000 per year

    Responsibilities:Design, configure and test enterprise network solutions with strong expertise in Cisco routing & switching (Catalyst, Nexus, ISR/ASR series) or Juniper (EX, QFX, MX series)Design and hands on configuration experience with Cisco SD-WAN (Viptela).Document low-level designs, configuration steps, and operational procedures.Design and hands on...

  • Network Engineer

    2 weeks ago


    Sydney, New South Wales, Australia CareCone Group Full time $120,000 - $180,000 per year

    Role: Network EngineerLocation: SydneyJob Description:Must require skills: Key technology – Arista LAN, Palo Alto FW, Cisco LANAdd on skills: AWS Networking, ISP Carrier Network, Enterprise and Data Center Network, Security Appliances (Load Balancers, PA Firewall etc),MPLS,Certification – CCIE/CCNA /CCNP/CCAr/Arista/F5/Palo Alto etcData Center / LAN /...


  • Sydney, New South Wales, Australia CareCone Group Full time $104,000 - $130,878 per year

    Role: Senior Network Security Engineer (Cisco/Arista)Location: SydneyJob Description:Must require skills: Key technology – Arista LAN, Palo Alto FW, Cisco LANAdd on skills: AWS Networking, ISP Carrier Network, Enterprise and Data Center Network, Security Appliances (Load Balancers, PA Firewall etc),MPLS,Certification – CCIE/CCNA...

  • Network Engineer

    2 days ago


    Sydney, New South Wales, Australia CareCone Group Full time $120,000 - $180,000 per year

    Role: Network Engineer (Arista/Palo Alto)Location: SydneyJob Description:Must require skills: Key technology – Arista LAN, Palo Alto FW, Cisco LANAdd on skills: AWS Networking, ISP Carrier Network, Enterprise and Data Center Network, Security Appliances (Load Balancers, PA Firewall etc),MPLS,Certification – CCIE/CCNA /CCNP/CCAr/Arista/F5/Palo Alto...