Lead Enterprise SASE Security Engineer

THE JUDGE GROUP, INC.
Tysons, VA, United States
8 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Business Process Modeling Cloud Computing Cloud Computing Security Configuration Management Complex Networks Cyber Security Information Leak Prevention Domain Name System (DNS) OSI Models Python (Programming Language)
+16 more
Network Security Routing Ping (Networking Utility) Azure Active Directory Zero Trust Network Access Web Application Security TCP/IP Wide Area Networks Scripting Transport Layer Security Cloud Platform System Information Technology Palo Alto Networks Fortinet 3-tier Architectures Cisco

Job description

We are seeking a Lead Enterprise SASE Security Engineer to serve as the technical owner for the deployment, optimization, and operationalization of our global Secure Access Service Edge (SASE) architecture. This role will lead the organization’s transition from traditional network security models to a Zero Trust, cloud-delivered security framework, with Netskope serving as the core Security Service Edge (SSE) platform., Zero Trust Architecture and ZTNA Leadership

  • Design, implement, and manage Zero Trust Network Access (ZTNA) policies using identity-centric security principles.
  • Define and enforce ZTNA access policies for specific user groups using technologies such as Netskope Private Access to ensure least-privilege access.
  • Lead the migration from legacy perimeter-based security controls to cloud-native Zero Trust architectures.
  • Develop and implement a tag-oriented unified SASE security policy strategy using user identity, device posture, application context, and other cloud-native attributes.
  • Eliminate reliance on traditional one-to-one firewall rule migrations by consolidating and modernizing policy frameworks.
  • Review and optimize SSL/TLS inspection and decryption policies to minimize security blind spots while maintaining application functionality.
  • Assess legacy SSL exclusion policies and validate business requirements for all exceptions.
  • Lead firewall and web filtering policy cleanup initiatives, removing redundant, outdated, or overly permissive rules.
  • Create and maintain architecture documentation, implementation standards, operational procedures, and technical design documents.

Netskope Deployment and Operations

  • Lead the end-to-end deployment and ongoing operation of the Netskope Security Cloud platform across a global enterprise environment.
  • Implement and support key Netskope capabilities, including:
  • Secure Web Gateway (SWG)
  • Cloud Access Security Broker (CASB)
  • Data Loss Prevention (DLP)
  • Zero Trust Network Access (ZTNA)
  • Remote Browser Isolation (RBI)
  • Integrate Netskope with Identity Providers (IdPs), including Microsoft Entra ID (Azure AD) and Ping Identity.
  • Integrate Endpoint Detection and Response (EDR) solutions to enable adaptive, contextual access controls based on device health and risk posture.
  • Provide Tier 3 technical support and serve as the highest escalation point for complex issues involving Netskope clients, traffic steering, policy enforcement, and endpoint connectivity.
  • Troubleshoot and optimize security controls across Windows and macOS environments.

Automation and Continuous Improvement

  • Develop automation solutions to improve security operations, deployment efficiency, policy management, and reporting.
  • Utilize Python or other scripting languages to automate administrative and operational processes.
  • Integrate with security APIs for configuration management, reporting, monitoring, and remediation workflows.
  • Identify opportunities to streamline processes and improve overall security effectiveness.

Requirements

The ideal candidate is a hands-on security engineering expert with deep experience in SASE/SSE technologies, Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and enterprise-scale security transformations., * Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline, or equivalent professional experience.

  • 5+ years of hands-on experience in cybersecurity or security engineering roles.
  • 3+ years of experience designing, deploying, and supporting enterprise SASE or SSE solutions.
  • Deep hands-on experience with Netskope Security Cloud, including SWG, CASB, ZTNA, and DLP capabilities, or extensive experience with comparable platforms such as:
  • Zscaler (ZIA, ZPA)
  • Palo Alto Prisma Access
  • Strong expertise in Zero Trust security architectures and identity-based access controls.
  • Experience deploying and managing Secure Web Gateway, CASB, DLP, and ZTNA technologies in large enterprise environments.
  • Strong knowledge of networking fundamentals, including TCP/IP, routing, switching, DNS, SSL/TLS, and OSI Layers 1-7.
  • Experience with SD-WAN technologies and traditional network security architectures.
  • Advanced knowledge of next-generation firewall (NGFW) policy design, optimization, and migration.
  • Experience transitioning organizations from IP-based security policies to application- and identity-based access controls.
  • Strong scripting and automation experience using Python or similar languages.
  • Ability to troubleshoot complex network and security issues across cloud, endpoint, and enterprise environments., * Netskope certifications such as NCCA or NCCSE.
  • Zscaler certifications such as Zscaler Certified Cloud Administrator (ZCCA) or Zscaler Certified Cloud Professional (ZCCP).
  • Experience leading enterprise-scale migrations from traditional firewall platforms, including Check Point, Cisco, Palo Alto Networks, or Fortinet, to SASE/SSE solutions.
  • Experience integrating SASE platforms with SD-WAN technologies, including:
  • Cisco Viptela
  • Aruba Silver Peak
  • Fortinet SD-WAN
  • Experience designing and optimizing SSL/TLS inspection and decryption strategies for high-volume cloud environments.
  • Experience leveraging security APIs for automated reporting, configuration management, and incident remediation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner Ā· LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark Ā· LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos Ā· LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas Ā· Europe 2026 Virtual

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes Ā· WWC 2025

Videos

See all

Related articles

See all