MUST KNOW
- SASE engineer who can understand complex networks and cloud services (this should cover mostly anything below)
- Involved with multiple Platforms such as (Netskope, Zscaler, Palo Alto, Fortinet). Any other is nice to have.
- SD-WAN fabrics overlay design, application-aware routing, QoS and traffic shaping, path selection policy, and SASE service insertion at the branch edge.
- Zero Trust Principle, least-privilege application segmentation, device posture assessment, and continuous verification
- Lead migration from legacy networks to cloud-delivered SASE Services.
- Good documentation skills, network diagrams, policy standards, and as-built records that other engineers can implement and audit against
- Evaluate SASE and SSE vendors and features against requirements; provide technical recommendations to architecture review and procurement.
- Cloud services such as AWS, Azure, Google Cloud Platform, nice to have (or mandatory)
- Network routing protocols and VLANS.
- Identity integration for SAML/OIDC, SSO, SCIM, Entra ID or Okta, MDM/UEM, and EDR posture signals.
- Troubleshoot complex networks.
- Secure Web Gateway experience
- Experience with ITAR a plus. Individual needs to be a US Cit holder
- Understanding of SSL/TLS, including certificate distribution, PKI integration, bypass and exemption management, and pinned application handling.
DAY-TO-DAY
- Serve as tier-3 escalation for SASE, SD-WAN, and remote access incidents; lead root cause analysis and drive corrective actions to closure.
- Troubleshoot complex application, latency, and access failures across the full path endpoint, agent, tunnel, cloud PoP, policy engine, and destination using packet capture, digital experience monitoring, and log analytics.
- Build monitoring, alerting, and dashboards for platform health, tunnel state, policy hit rates, capacity, and user experience; establish and report against SLOs.
- Manage policy lifecycle and change control: peer review, testing, staged deployment, documentation, and periodic rule and exception cleanup.
- Participate in an on-call rotation for critical network and security infrastructure.
ADDITIONALLY
- Partner with Security Operations, Identity, Endpoint, Cloud, and Application teams to align network policy with security requirements and application needs.
- Support audit and compliance activities by evidencing control implementation and maintaining accurate configuration and policy documentation.
- Mentor mid-level and junior engineers; build runbooks and lead knowledge transfer so operational load does not concentrate on individuals.
- Communicate technical trade-offs and risk clearly to both engineering peers and non-technical stakeholders.
NICE TO HAVE
- Python or any automation skills.
- Cloud skills from multiple vendors
- Networking skills; CCNA/CCNP are welcome.