Infrastructure Security Engineer-L2 (Palo Alto & NGFW)
Back to Jobs
GruveGet Smart Job AI Coach in the appFree on iOS and Android

Infrastructure Security Engineer-L2 (Palo Alto & NGFW)
Location
Mumbai, Maharashtra, India
Experience
Senior
Posted
Jul 7, 2026
Apply by
August 6, 2026
Applicants
0
Early applicantFull-timeWork from Office
Job Description
**About Gruve**
Gruve is an innovative software services startup dedicated to transforming enterprises to AI powerhouses. We specialize in cybersecurity, customer experience, cloud infrastructure, and advanced technologies such as Large Language Models (LLMs). Our mission is to assist our customers in their business strategies utilizing their data to make more intelligent decisions. As a well-funded early-stage startup, Gruve offers a dynamic environment with strong customer and partner networks.
**Location - Navi Mumbai, India**
**Position Summary**
We are seeking a highly skilled **Infrastructure Security Engineer-L2** (Palo Alto & NGFW) responsible for implementation, administration, and support of **Palo Alto Next-Generation Firewalls (NGFW)** across enterprise and cloud environments. The role involves handling **day-to-day operations, incident management, troubleshooting, and TAC coordination**, along with contributing to firewall migrations and security enhancements. The engineer will play a key role in maintaining secure and stable network infrastructure for critical business operations.
**Key Responsibilities**
- Provide **L2 support** for Palo Alto NGFW environments, including incident handling, troubleshooting, and resolution.
- Manage **day-to-day firewall operations**, including policy changes, NAT configurations, and VPN management.
- Perform **advanced troubleshooting** for network and security issues across on-prem and cloud environments (AWS, Azure, GCP, OCI).
- Handle **TAC coordination** with vendors for critical and complex issues.
- Configure and manage:
- **IPSec VPNs, Remote Access VPNs, and Clientless VPNs**
- **Security policies, NAT rules, and ACLs**
- Work on **Palo Alto Panorama** for centralized management, including templates, log collectors, and policy deployment.
- Implement and support **Next-Generation Firewall features** such as:
- Threat Prevention
- URL Filtering
- Content Filtering
- Data Loss Prevention (DLP)
- User-ID
- Participate in and execute **firewall migration projects** (e.g., Cisco ASA to Palo Alto).
- Support **IDS/IPS administration and monitoring**, including performance tuning and alert handling.
- Perform **change management activities** in line with ITIL processes.
- Prepare and maintain **technical documentation** including HLD, LLD, SOPs, and knowledge base articles.
- Conduct **security assessments, gap analysis**, and recommend improvements in security architecture.
- Collaborate with L3 teams and stakeholders for **design improvements and complex issue resolution**.
- Provide inputs for **network security strategy, transformation projects, and infrastructure planning**.
**Technical Skills**
- Strong hands-on experience with **Palo Alto NGFW (PAN-OS)** and its advanced features.
- Working knowledge of **Palo Alto Panorama** (templates, device groups, log collectors).
- Experience with **Cisco ASA firewalls** and firewall migration projects.
- Strong understanding of:
- **Network Security concepts**
- **OSI Model & TCP/IP protocols**
- **Routing & Switching fundamentals**
- Expertise in:
- **IPSec VPN configuration & troubleshooting**
- **NAT, ACLs, and security policy management**
- Exposure to **cloud security networking** in:
- AWS
- Azure
- GCP
- OCI
- Knowledge of **IDS/IPS systems** and threat prevention mechanisms.
**Basic Qualifications**
- Bachelor’s degree in Engineering (**B.E./B.Tech – CSE, IT, ECE**) or **MCA / M.Sc (Computer Science)**.
- Minimum **5+ years of experience** in network security and firewall management.
- Hands-on experience in **Palo Alto firewall administration and troubleshooting**.
- Strong analytical, problem-solving, and communication skills.
**Preferred Qualifications**
- **PCNSE (Palo Alto Networks Certified Network Security Engineer)** certification.
- **CCNP Security or equivalent certification**.
- Experience in **enterprise datacentre and cloud security deployments**.
**Why Gruve**
At Gruve, we foster a culture of innovation, collaboration, and continuous learning. We are committed to building a diverse and inclusive workplace where everyone can thrive and contribute their best work. If you’re passionate about technology and eager to make an impact, we’d love to hear from you.
Gruve is an equal opportunity employer. We welcome applicants from all backgrounds and thank all who apply; however, only those selected for an interview will be contacted.
Key Responsibilities
- Provide L2 support for Palo Alto NGFW environments including incident handling and troubleshooting.
- Manage day-to-day firewall operations such as policy changes, NAT configurations, and VPN management.
- Perform advanced troubleshooting for network and security issues across on-prem and cloud environments.
- Handle TAC coordination with vendors for critical and complex issues.
- Configure and manage IPSec VPNs, Remote Access VPNs, and Clientless VPNs.
- Configure security policies, NAT rules, and ACLs.
- Work with Palo Alto Panorama for centralized management including templates and log collectors.
- Implement and support Next-Generation Firewall features like Threat Prevention, URL Filtering, and DLP.
- Participate in and execute firewall migration projects such as Cisco ASA to Palo Alto.
- Support IDS/IPS administration and monitoring including performance tuning and alert handling.
- Perform change management activities in line with ITIL processes.
- Prepare and maintain technical documentation including HLD, LLD, SOPs, and knowledge base articles.
- Conduct security assessments, gap analysis, and recommend improvements in security architecture.
- Collaborate with L3 teams and stakeholders for design improvements and complex issue resolution.
- Provide inputs for network security strategy, transformation projects, and infrastructure planning.
Requirements
- Bachelor’s degree in Engineering (B.E./B.Tech – CSE
- IT
- ECE) or MCA / M.Sc (Computer Science)
Skills Required
Palo Alto NGFW (PAN-OS)Palo Alto PanoramaCisco ASA firewallsNetwork Security conceptsOSI ModelTCP/IP protocolsRouting & Switching fundamentalsIPSec VPN configurationNATACLsSecurity policy managementAWSAzureGCPOCIIDS/IPS systemsThreat PreventionURL FilteringContent FilteringData Loss Prevention (DLP)User-IDITIL processesHLDLLDSOPsKnowledge base articlesAnalytical skillsProblem-solvingCommunication skillsEnterprise datacentre security deploymentsCloud security deployments
App exclusive · Free
Smart Job AI Coach
Your personal interview coach on every job — readiness tips, profile improvements, and role-specific prep. Available only in the Pulse Job app.
Interview readiness
See how prepared you are and what to improve for each role.
Personalized tips
Actionable suggestions based on your profile and the job.
After you apply
Keep coaching momentum from job detail through application success.
Similar roles for you
Matched using this role's title and skills. Open the job search anytime to see every listing.
Full Stack Java Developer
Up2date Technologies LLC
$70–$90 / Hour
ContractEasy applyHybrid
Atlanta
DevOps Engineer
App Deft
₹45,000–₹75,000 / Month
Full-timeEasy applyWork from Office
Mohali
Backend Node.js Developer
IITIL
₹60,000–₹1,00,000 / Month
Full-timeEasy applyWork from Home
Remote
MERN Stack Developer
Techchefz Digital
₹75,000–₹95,000 / Month
Full-timeEasy applyWork from Office
Bangalore
Senior MERN Stack Developer
Metadesign Solutions
₹1,00,000–₹1,30,000 / Month
Full-timeEasy applyWork from Office
Gurugram
Software Developer
Mystartupwave Private Limited
₹40,000–₹1,20,000 / Month
Full-timeEasy applyWork from Home
Remote