What are the responsibilities and job description for the Firewall Audit SME position at Global Solutions Group?
Engagement Type
- Internal firewall audit supporting a county Internal Audit team
- Not a penetration test and not a purely tool-driven compliance review
- Deep, process-heavy audit in an environment with limited pre-documented controls
Required Technical Skills
- Hands-on experience auditing internal firewalls (not just perimeter/external)
- Strong practical knowledge of firewall rule sets, including:
- Ports, services, zones, directions, and rule logic
- Administrative access controls and least-privilege enforcement
- Ability to manually analyze large firewall configuration exports and log data (millions of records if needed)
- Experience validating controls when automated tools (e.g., Tenable/CIS scans) are incomplete, misconfigured, or unavailable
- Comfort extracting evidence directly from firewall platforms (e.g., Palo Alto) and explaining findings at a granular level
Audit & Process Expectations
- Experience with internal audit environments where:
- Controls are not fully documented up front
- The auditor helps identify, validate, and document controls during the engagement
- Ability to assess and document:
- Secure configuration baselines
- Change management workflows (tickets, approvals, testing, deployment)
- Patch and firmware management accountability
- Compensating controls and risk acceptance
- Capable of producing detailed workpapers with clear attributes, observations, and conclusions (not just checklist results)
Soft Skills / Fit
- Comfortable working collaboratively with Internal Audit teams
- Able to explain technical findings clearly to non-engineers
- Flexible, non-rigid audit mindset (not limited to this is / isn t an audit step framing)