Staff Network Engineer
Leads enterprise Zero Trust and secure-access networking, owning Zscaler architecture and operations while supporting Palo Alto, wireless, LAN/WAN, and multi-cloud infrastructure. The role requires 10+ years of network experience, deep ZIA/ZPA expertise, automation skills, and major-incident leadership.
About the job
Responsibilities
- Own and operate the Zscaler platform, including ZIA, ZPA, ZDX, and ZCC.
- Design policy frameworks, application segmentation, PAC and traffic-forwarding standards, App Connector topology, and NSS/log-streaming architecture.
- Troubleshoot secure-access incidents involving tunnel flapping, broker and connector health, SSL inspection, DNS/DTLS failures, and systemic connectivity issues.
- Manage Palo Alto firewalls, Panorama, and GlobalProtect VPN while planning migration toward Zscaler solutions.
- Support Aruba Central wireless, Ekahau, and Cisco Catalyst switches globally.
- Design, install, and configure network devices and ISP circuits for new offices.
- Build automation, dashboards, alerting, and proactive network monitoring using log analytics and Snowflake telemetry.
- Troubleshoot secure networking constructs across AWS, Azure, and Google Cloud, including NVAs, NSGs, VPCs, UDRs, Direct Connect, and ExpressRoute.
- Author technical runbooks, escalation procedures, and knowledge-base content.
- Participate in on-call rotations, implement changes, and lead responses to major network incidents.
- Travel internationally for short periods for site builds.
Requirements
- 10+ years of enterprise network infrastructure experience.
- 3+ years of hands-on Zscaler ZIA/ZPA design and deployment at scale.
- Expertise in Zero Trust and SASE architecture, including ZTNA, proxy/SWG, SSL inspection, and cloud security.
- Hands-on experience with Palo Alto PAN-OS, GlobalProtect, Panorama, and enterprise VPNs.
- Aruba wireless and Cisco LAN/WAN routing, switching, and 802.1X fundamentals.
- Strong troubleshooting skills across TCP/IP, DNS, DHCP, TLS/DTLS, BGP, and QoS.
- Multi-cloud networking and site-to-cloud connectivity experience across AWS, Azure, and Google Cloud.
- Python scripting, API configuration, and log observability experience.
- Strong ITSM, documentation, and communication skills.
Nice to Have
- Zscaler ZCCA-IA/PA or ZDTA certification.
- Palo Alto PCNSE certification.
- Aruba ACMA/ACMP certification.
- Cisco CCNA/CCNP certification.
- Experience migrating legacy GlobalProtect VPNs to ZPA.
- Familiarity with SASE, Terraform, and network-as-code/IaC.
- Experience in high-growth SaaS or cloud-native environments.
Skills
Zscaler, Zia, Zpa, Zdx, Zcc, Zero Trust, Sase, Palo Alto Pan-Os, Globalprotect, Panorama, Aruba Wireless, Cisco Catalyst, AWS, Azure, GCP
Similar jobs
Security Engineering jobsOwn the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.
Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.