Location: Tysons Corner, VA
Salary: Depends on Experience
Description: Lead Enterprise SASE Security Engineer (Netskope Focus)Type: 6+ Month ContractLocation: Tysons Corner, VA - 5 days a week Position SummaryWe are seeking a Lead Enterprise SASE Security Engineer to serve as the technical owner for the deployment, optimization, and operationalization of our global Secure Access Service Edge (SASE) architecture. This role will lead the organization's transition from traditional network security models to a Zero Trust, cloud-delivered security framework, with Netskope serving as the core Security Service Edge (SSE) platform.
The ideal candidate is a hands-on security engineering expert with deep experience in SASE/SSE technologies, Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and enterprise-scale security transformations.
Key Responsibilities Zero Trust Architecture and ZTNA Leadership
- Design, implement, and manage Zero Trust Network Access (ZTNA) policies using identity-centric security principles.
- Define and enforce ZTNA access policies for specific user groups using technologies such as Netskope Private Access to ensure least-privilege access.
- Lead the migration from legacy perimeter-based security controls to cloud-native Zero Trust architectures.
- Develop and implement a tag-oriented unified SASE security policy strategy using user identity, device posture, application context, and other cloud-native attributes.
- Eliminate reliance on traditional one-to-one firewall rule migrations by consolidating and modernizing policy frameworks.
- Review and optimize SSL/TLS inspection and decryption policies to minimize security blind spots while maintaining application functionality.
- Assess legacy SSL exclusion policies and validate business requirements for all exceptions.
- Lead firewall and web filtering policy cleanup initiatives, removing redundant, outdated, or overly permissive rules.
- Create and maintain architecture documentation, implementation standards, operational procedures, and technical design documents.
Netskope Deployment and Operations
- Lead the end-to-end deployment and ongoing operation of the Netskope Security Cloud platform across a global enterprise environment.
- Implement and support key Netskope capabilities, including:
- Secure Web Gateway (SWG)
- Cloud Access Security Broker (CASB)
- Data Loss Prevention (DLP)
- Zero Trust Network Access (ZTNA)
- Remote Browser Isolation (RBI)
- Integrate Netskope with Identity Providers (IdPs), including Microsoft Entra ID (Azure AD) and Ping Identity.
- Integrate Endpoint Detection and Response (EDR) solutions to enable adaptive, contextual access controls based on device health and risk posture.
- Provide Tier 3 technical support and serve as the highest escalation point for complex issues involving Netskope clients, traffic steering, policy enforcement, and endpoint connectivity.
- Troubleshoot and optimize security controls across Windows and macOS environments.
Automation and Continuous Improvement
- Develop automation solutions to improve security operations, deployment efficiency, policy management, and reporting.
- Utilize Python or other scripting languages to automate administrative and operational processes.
- Integrate with security APIs for configuration management, reporting, monitoring, and remediation workflows.
- Identify opportunities to streamline processes and improve overall security effectiveness.
Required Qualifications- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline, or equivalent professional experience.
- 5+ years of hands-on experience in cybersecurity or security engineering roles.
- 3+ years of experience designing, deploying, and supporting enterprise SASE or SSE solutions.
- Deep hands-on experience with Netskope Security Cloud, including SWG, CASB, ZTNA, and DLP capabilities, or extensive experience with comparable platforms such as:
- Zscaler (ZIA, ZPA)
- Palo Alto Prisma Access
- Strong expertise in Zero Trust security architectures and identity-based access controls.
- Experience deploying and managing Secure Web Gateway, CASB, DLP, and ZTNA technologies in large enterprise environments.
- Strong knowledge of networking fundamentals, including TCP/IP, routing, switching, DNS, SSL/TLS, and OSI Layers 1-7.
- Experience with SD-WAN technologies and traditional network security architectures.
- Advanced knowledge of next-generation firewall (NGFW) policy design, optimization, and migration.
- Experience transitioning organizations from IP-based security policies to application- and identity-based access controls.
- Strong scripting and automation experience using Python or similar languages.
- Ability to troubleshoot complex network and security issues across cloud, endpoint, and enterprise environments.
Preferred Qualifications- Netskope certifications such as NCCA or NCCSE.
- Zscaler certifications such as Zscaler Certified Cloud Administrator (ZCCA) or Zscaler Certified Cloud Professional (ZCCP).
- Experience leading enterprise-scale migrations from traditional firewall platforms, including Check Point, Cisco, Palo Alto Networks, or Fortinet, to SASE/SSE solutions.
- Experience integrating SASE platforms with SD-WAN technologies, including:
- Cisco Viptela
- Aruba Silver Peak
- Fortinet SD-WAN
- Experience designing and optimizing SSL/TLS inspection and decryption strategies for high-volume cloud environments.
- Experience leveraging security APIs for automated reporting, configuration management, and incident remediation.
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact: This job and many more are available through The Judge Group. Please apply with us today!