Sr Network Firewall Engineer

PanAgora Asset ManagementBoston, MA
1d

About The Position

Founded in 1989, PanAgora (Greek for across marketplace) Asset Management is a premier provider of investment solutions spanning most major asset classes and risk ranges. We seek to provide investment solutions using sophisticated quantitative techniques that incorporate fundamental insights and vast amounts of market information. While PanAgora’s investment strategies are highly systematic in nature, the processes deployed within these strategies are built and overseen by talented professionals with significant and diverse investment experience. Innovative research plays a central role in our investment philosophy and process, and is an essential component of our firm’s ability to deliver attractive investment solutions. Investment teams are organized into an Equity Strategies group and a Multi Asset Strategies group. Most investment team members are engaged in original research using fundamental intuition, market intelligence, modern finance and scientific methods. We are committed to providing clients with reliable investment processes, consistent performance, transparency, and access to our investment resources. Our client base is comprised of institutional investors across the globe, including public & private retirement funds, sovereign wealth funds, endowments & foundations, and sub-advisory mandates. We are seeking a Senior Network/Firewall Engineer to manage our network infrastructure and security architecture across hybrid on-premises and Azure environments. This role focuses on day-to-day Palo Alto firewall operations, leading our VPN-to-SASE migration, and designing network architectures that optimize traffic flows and support our quantitative investment operations. You will work closely with the Platform Services team to ensure our network delivers optimal uptime, performance, and security while meeting the demands of a regulated asset management firm. The ideal candidate is a focused network and firewall engineer who excels at core networking disciplines while understanding how network design impacts the broader infrastructure. They should demonstrate deep expertise in firewall management, cloud networking, and security architecture while being a strong collaborator who can work effectively with infrastructure and operations teams. This role requires someone who can balance strategic initiatives like VPN-to-SASE migration with day-to-day operational excellence, and who brings both technical precision and effective communication skills to support a sophisticated quantitative investment firm. This job description is not intended to be an exhaustive list of all duties, responsibilities and qualifications of the job. The employer has the right to revise this job description at any time. You will be evaluated in part based on your performance of the responsibilities and/or tasks listed in this job description. You may be required perform other duties that are not included on this job description. The job description is not a contract for employment, and either you or the employer may terminate employment at any time, for any reason. PanAgora is an equal opportunity employer and provides equal employment opportunities to job applicants and employees without regard to race, religion, sex, marital status, color, national origin, age, physical or mental disability, veteran status, pregnancy, ancestry or sexual orientation. PanAgora is committed to maintaining an environment that is free from discrimination as well as adhering to applicable federal and state laws. Our culture thrives on collaboration and creativity. We believe encouraging diversity of thought generates new perspectives that contribute to the overall investment debate, allows for focused collaboration, and ultimately leads to investment innovation. We nurture and promote our culture with a focus on the following principles: Our Core Values Team - At PanAgora, we maintain that a team approach to investing fosters collaboration and compounds the value of insights contributed by any single team member. Research - We believe a holistic approach to research that emphasizes the identification of market inefficiencies, often overlooked by traditional academic research, contributes to the development of more robust idea generation. PanAgora’s strategies combine the firm’s fundamental investment philosophy and original research with an advanced quantitative framework. Service - We seek to provide flexible investment solutions tailored to the evolving needs of our clients. We pair an array of investment offerings with a high degree of transparency in an effort to ensure that our clients understand the drivers of past performance and have proper expectations for the future. We focus on providing unfettered access to experienced client services and investment professionals, and pride ourselves on providing accurate and timely communication with our clients.

Requirements

  • BS in Computer Science or related field; 7+ years enterprise network engineering experience
  • Strong Palo Alto firewall experience including daily operations and policy management
  • Proven ability designing network architectures for hybrid datacenter and cloud environments
  • Hands-on experience with Azure networking (NSGs, ExpressRoute, VNets, Private Link)
  • Knowledge of SD-WAN, SASE solutions, and experience with VPN migrations
  • Understanding of network protocols (BGP, OSPF, VLAN) and routing architectures
  • Experience with certificate management and PKI infrastructure
  • Scripting skills in Python or PowerShell for network automation
  • Strong troubleshooting abilities and systematic problem-solving approach
  • Experience in regulated environments (financial services, healthcare, or similar)
  • Excellent communication skills and ability to collaborate with infrastructure teams

Nice To Haves

  • PCNSE, CCNP Security, or Azure Network Engineer certification
  • Experience with Infrastructure as Code tools (Terraform, Ansible)
  • Knowledge of DNS automation for Kubernetes environments
  • Understanding of virtualization networking concepts
  • Familiarity with low-latency network requirements for financial applications

Responsibilities

  • Manage Palo Alto firewall infrastructure including daily rule changes, policy optimization, and threat prevention
  • Lead migration from traditional VPN to SASE architecture for remote users
  • Design network architectures optimizing north-south and east-west traffic flows across on-premises and Azure environments
  • Implement Azure networking including NSGs, ExpressRoute, Private Link, and VNets
  • Manage enterprise TLS/SSL certificate lifecycle to support Zero Trust Network Access initiatives
  • Design network segmentation strategies supporting business operations and compliance requirements
  • Implement SD-WAN/SASE for remote locations while maintaining traditional routing between owned sites
  • Manage DNS infrastructure and develop automation for upcoming Kubernetes deployment
  • Collaborate with infrastructure team on network optimization for virtualized workloads and storage systems
  • Monitor network performance, execute maintenance windows, and participate in on-call rotation
  • Develop network automation using Python or PowerShell and maintain comprehensive documentation
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service