About The Problem Core Skills Proof Approach Experience Certifications Training Beyond Security Contact
NGFW Operations & Training Specialist

Most breaches don't start
with a zero-day.
They start with a
misconfigured firewall.

Not deployment. Not migration.
Operations. Management. ROI.

Elvis KUPARA — I specialise in the day-to-day operations and management of Palo Alto Networks NGFWs — ensuring every licensed security capability is activated, configured, and delivering measurable protection. I also train your team to own that outcome themselves.

EK
Elvis Kupara
PCNSP · NGFW Ops & Management · Zimbabwe
7+
Yrs Ops Experience
4
Continents
15K+
Users Secured
35+
Firewalls Managed
PCNSPCCNANSE3MCSE/MCTPCSPI (2026)
AI-Generated Podcast
Hear Elvis's Story
An AI-generated podcast on career, philosophy & NGFW security

01 The Conviction

A Career Built Around One Uncomfortable Truth

NGFW Operations & Management Not Deployment or Migration

I'm a network security engineer specialising in the day-to-day operations and management of Next-Generation Firewalls — not their design, deployment, implementation, or migration. Once the NGFW is in, that's where my work begins.

The pattern I see everywhere: organisations invest in best-in-class Palo Alto Networks NGFWs, deploy them, and then run them as expensive routers. App-ID disabled. WildFire unsubscribed. SSL/TLS inspection off. The capability is licensed. The protection is dormant. The ROI is zero.

With 7+ years inside enterprise, MSSP, and public-sector security operations, I close that gap — through configuration audits, capability activation, operational optimisation, and hands-on training that ensures the firewall keeps working long after I leave. I help teams hit the ground running with PAN firewalls and build the competency to keep them running right.

7+
Years in NGFW ops & management
4
Continents of firewall operations
15K+
Users secured in COVID crisis
35+
Firewalls managed simultaneously

An NGFW is not a router with an expensive licence. Every underutilised feature is a gap in your defences and a gap in your ROI. My job is to close both — and train your team to keep them closed.

— Elvis Kupara

02 The Core Problem

Your NGFW is probably underperforming. Here's why.

The Industry Problem

"Through 2023, 99% of firewall breaches will be caused by misconfiguration, not firewall flaws."

— Gartner Research

Most organizations invest heavily in Next-Generation Firewalls — then deploy them as glorified routers.

App-ID disabled. SSL/TLS inspection off. WildFire not subscribed. User-ID not configured. DNS Security inactive. DLP untouched.

Every unused capability is an unmitigated risk. Every unlicensed-but-subscribed feature is wasted investment. The firewall passes traffic it should be blocking — and nobody knows.

The problem isn't the technology. It's the operational gap between what the platform can do and what it's actually doing. And that gap lives in day-to-day operations.

The Two-Pronged Answer

01
Fix it operationally. Through Security Lifecycle Reviews, Best Practice Assessments, configuration audits, and hands-on remediation — surfacing misconfigurations before they become exploitable vulnerabilities, activating dormant capabilities, and aligning to Zero Trust principles.
02
Prevent recurrence through training. Remediation without capability-building is a temporary fix. The organisational competency to sustain good posture must be built into the team — training engineers and educating decision-makers who are responsible for keeping it that way.

This dual capability — operational practitioner and educator — is rare. Most consultants can fix it. Elvis fixes it and makes sure it stays fixed.

03 Core Skills

Areas of Expertise

Full-stack security capability across NGFW platforms, cloud, threat prevention, and knowledge transfer.

NGFW Platforms & Management
Full lifecycle management of Palo Alto Networks NGFWs — from rulebase engineering and policy hygiene to HA operations, Panorama centralisation, and Strata Cloud Manager orchestration.
PA-SeriesVM-SeriesPanoramaSCMAIOpsSSL/TLS Decryption
Threat Prevention & Intelligence
Activating the full threat prevention stack — App-ID, User-ID, Content-ID, WildFire, DNS Security, DLP, IDS/IPS tuning, and IoC analysis — making threats visible and stoppable.
WildFireApp-IDDNS SecurityDLPIDS/IPSAutoFocus
Cloud Security & SASE
Securing hybrid and multi-cloud environments through Prisma SASE, Cloud NGFW for AWS/GCP/Azure, ZTNA, and GlobalProtect — consistent policy enforcement wherever users and workloads live.
Prisma SASEZTNACloud NGFWGlobalProtectIPSec VPN
Monitoring & Operations
Continuous traffic monitoring, SIEM integration, log pipeline optimisation, SolarWinds and Wireshark analysis — maintaining persistent visibility across complex, distributed security estates.
SIEMSolarWindsNetFlowServiceNowITSM
Training & Knowledge Transfer
Technical and non-technical stakeholder education, NGFW operations training, Security Lifecycle Reviews, and BPAs — translating security investment into measurable posture improvements and ROI.
SLRBPAPAN-OSSecurity AwarenessROI Optimisation
Compliance, Audit & Governance
Configuration audits, capability adoption planning, risk reduction metrics and reporting — aligning firewall environments with Zero Trust principles and organisational security governance frameworks.
Zero TrustConfig AuditRisk MetricsPolicy HygieneBPA/SLR

04 The Proof

Signature Projects

Engagements where full-stack security thinking and day-to-day operational discipline delivered real, measurable outcomes.

01
City of Cape Town
GlobalProtect VPN for 15,000 Users
Managed and deployed GlobalProtect Remote Access VPN enabling 15,000 municipal employees to work securely from home — delivered within days of the COVID-19 national lockdown, ensuring uninterrupted government service delivery under crisis conditions.
15,000 users secured
02
Dimension Data
Multi-Continent Firewall Operations
Day-to-day operations and management of 35+ Palo Alto and FortiGate NGFWs across 5 cities and 4 continents via Panorama — delivering consistent policy hygiene, SSL/TLS decryption governance, and threat prevention efficacy across a geographically distributed estate.
4 continents · 35+ devices
03
Kowoyo Networks
NGFW Capability Adoption & ROI
Helped multiple organisations unlock advanced NGFW features that were licensed but dormant — activating App-ID, WildFire, DNS Security, and DLP through operational audits and BPA-led capability adoption planning to reduce risk and maximise investment value.
Measurable posture improvement
04
Multiple Clients
Security Lifecycle Reviews & BPAs
Delivered Security Lifecycle Reviews, Best Practice Assessments, and configuration audits across multiple client environments — identifying operational misconfigurations, closing posture gaps, and aligning firewall management practices with Zero Trust principles.
Zero Trust alignment

05 The Approach

How I Close the Gap

Every engagement follows the same three-act operational framework — whether a single config audit or a multi-month training programme.

Step One
01
Audit
Surface what's broken, dormant, or exposed. SLRs, BPAs, and configuration audits that reveal the operational gap between what your NGFW should be doing and what it's actually doing — before an attacker finds it first.
SLRBPAConfig AuditRisk AssessmentZero Trust Gap Analysis
Step Two
02
Optimise
Activate the full security stack. App-ID, User-ID, Content-ID, SSL/TLS decryption, WildFire, DNS Security, DLP, and AIOps — turned on, tuned, and working in concert. Policy hygiene restored. Dormant capabilities activated. ROI realised.
App-IDWildFireSSL/TLSDNS SecurityDLPAIOps
Step Three
03
Train
Make it stick. Technical teams upskilled to operational proficiency in PAN-OS. Decision-makers briefed on risk and governance. The organisational competency built to sustain good posture — so the fix doesn't need repeating.
PAN-OS TrainingOperational ProficiencyExecutive BriefingHit the Ground Running

06 The Journey

Employment History

A career defined by operational discipline — managing complex firewall estates, activating security capability, and building teams that can sustain it.

Kowoyo Networks
Founder & Principal Trainer
Harare, Zimbabwe
June 2023 – Present

Founded and operate an independent NGFW training organisation specialising in Palo Alto Networks platforms — designing curriculum that helps security teams hit the ground running with PANW firewalls and manage them to their full operational potential.

  • Delivered hands-on NGFW operations training building team competency from initial configuration through advanced threat prevention management.
  • Conducted SLRs, Firewall Policy Reviews, and BPAs identifying and closing operational configuration gaps before exploitation.
  • Advised organisations on maximising ROI through activating underutilised licensed security features.
  • Educated C-suite on device capability, risk implications, and security investment value.
PAN-OSBPASLROps TrainingROI
Dimension Data
Remote MSSP Engineer — Western Cape Security Operations
Harare, Zimbabwe (Remote)
May 2022 – June 2023

Day-to-day operations and management of 35 Azure VM-Series and PA-Series firewalls across 5 cities and 4 continents as part of the Western Cape Security Operations team.

  • Centrally managed and operated firewall security, authentication, SSL/TLS decryption, and policy compliance via Panorama.
  • Recommended and implemented IDS/IPS profiles where previously undetected threats were traversing client environments.
  • Conducted daily Security Device Health Checks, SLRs, and BPAs, surfacing operational misconfigurations proactively.
  • Founded an internal knowledge-sharing circle of 4 colleagues focused on PANW operational best practices.
PanoramaPA-SeriesVM-SeriesIDS/IPSMSSP Ops
City of Cape Town
Security Project Consultant — NGFW & IPS
Cape Town, South Africa
Nov 2018 – May 2022

Centralised security consultant responsible for the ongoing operations and management of 10 Palo Alto Networks PA-Series devices across the City's infrastructure via Panorama.

  • Managed and deployed GlobalProtect VPN enabling 15,000 municipal employees to work securely — delivered within days of the COVID-19 national lockdown.
  • Operated SIEM and centralised logging infrastructure, maintaining incident detection and audit trail coverage.
  • Managed Data Centre Internet Breakout security, HA/redundancy, VPN, and threat prevention profiles.
GlobalProtectPA-SeriesSIEMVPN OpsPublic Sector
Computacenter UK
Network Analyst
Cape Town, South Africa
June 2016 – July 2018

Network operations and monitoring for a UK-based managed services provider — incident management, firewall rule management, and performance optimisation.

  • Monitored network performance using SolarWinds, TCPDump, and Wireshark; resolved BGP and EIGRP routing issues.
  • Managed Checkpoint and Cisco ASA firewall rules and policy optimisation.
  • Implemented Cisco NetFlow to resolve over-utilised links; managed SNMP and device health reporting.
Cisco ASANetFlowBGPSolarWinds

07 Credentials

Certifications & Accreditations

A broad portfolio spanning Palo Alto Networks, Fortinet, Cisco, and Microsoft — anchored by a 2026 roadmap that culminates in the PCSPI instructor credential.

Active Certifications
PCNSP
Palo Alto Networks
Hardware Firewall Technical Readiness
Palo Alto Networks
Software Firewall Technical Readiness
Palo Alto Networks
CMNE-F
Cisco Meraki
Legacy & Foundation Credentials
PCNSA
Palo Alto Networks
PSE: Strata Professional
Palo Alto Networks
ACE
Palo Alto Networks
NSE3
Fortinet
MCSE & MCT
Microsoft
ITIL v3 Foundation
AXELOS
CCNA R&S
Cisco
Cybersecurity Operations Associate
Cisco
2026 Certification Goals
PCSPI — Certified Security Platform Instructor
⭐ Flagship Goal · Palo Alto Networks
PCNSA — Network Security Analyst
In Progress · Palo Alto Networks
CSEE — Certified Service Edge Engineer
In Progress · Palo Alto Networks
CCSP — Certified Cloud Security Professional
In Progress · Palo Alto Networks
CCSK — Cloud Security Knowledge
In Progress · CSA
Azure Security Engineer Associate
In Progress · Microsoft
AWS Security – Specialty
In Progress · Amazon

08 Training Organisation

Kowoyo Networks Logo
KOWOYO NETWORKSEnterprise NGFW Training

Training the Next Generation of NGFW Operators

Kowoyo Networks, founded in 2023, is an independent enterprise network security training organisation built around one belief: that sustainable security posture requires technically competent operators — not just better tools.

Specialising in Palo Alto Networks NGFW platforms, the curriculum spans from foundational PAN-OS awareness through to advanced policy management, full-stack security capability utilization, BPAs, SLRs, and Firewall Policy Reviews.

Delivery is dual-track: hands-on technical training for engineers building operational proficiency, and executive stakeholder education on risk implications, governance obligations, and security investment value.

Elvis is actively pursuing PCSPI (Palo Alto Networks Certified Security Platform Instructor) — PANW's own formal teaching accreditation — cementing Kowoyo Networks as a verifiably credentialled NGFW training provider.

Enquire About Training
2023
Founded
PANW
Primary Platform
2-Track
Delivery Model
Remote
& On-site
  • PAN-OS Fundamentals & Security Policy Management
  • Full-stack capability activation — App-ID, User-ID, Content-ID
  • SSL/TLS Decryption, WildFire, DNS Security, DLP
  • Security Lifecycle Reviews (SLRs) & Best Practice Assessments
  • Firewall Policy Reviews & Configuration Audits
  • Executive security governance & ROI briefings
PCSPI in progress — Palo Alto Networks Certified Security Platform Instructor. The formal PANW teaching accreditation that makes Kowoyo Networks a verifiably credentialled training provider.

09 Beyond Security

The Person Behind the Firewall

Security is the profession. Curiosity is the engine. Here's what keeps it running.

Sport
Football & Tennis
Whether on the pitch or the court, sport is where strategy meets execution under pressure — not unlike network security operations. The discipline of reading the game, anticipating moves, and responding in real time translates more directly to this work than most people expect.
FootballTennisTeam PlayStrategy
AI & Automation
Exploring Generative AI Tools
Actively exploring generative AI for content creation, automation, and workflow optimisation — with a particular interest in how AI capabilities are being integrated into security operations platforms. From AI-generated podcasts to automated analysis pipelines, the convergence of AI and security operations is where the next frontier lives.
Generative AIContent CreationWorkflow AutomationAI + SecOps
Web & Brand Strategy
AI-Powered Website Transformation
Using AI to analyse and transform poorly-designed websites into aesthetic, effective growth systems — sites that generate leads, operate 24/7, and build powerful brands. The same systems thinking that makes a firewall perform at full capability applies here: identify what's dormant, activate what's possible, and make the whole thing work as designed.
AI AnalysisWeb StrategyGrowth SystemsBrand BuildingLead Generation

10 Get In Touch

Is your firewall's full capability activated?

Let's find out — and fix what's not. Whether you need a posture audit, an SLR/BPA, hands-on NGFW training for your team, or simply a conversation about where your firewall investment is and isn't working — reach out.

Location
Goromonzi, Zimbabwe
Availability
Remote & On-site Engagements
Chat on WhatsApp