Network Security Engineer - SASE

Cargill
United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Amazon Web Services Proxy Servers Application Performance Management User Authentication Microsoft Azure Software as a Service Cloud Computing Configuration Management Complex Networks Cyber Security Computer Networks
+52 more
Information Leak Prevention Dynamic Host Configuration Protocol Software Design Documents Network Address Translation Disaster Recovery Domain Name System (DNS) Github Networking Hardware Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Intrusion Detection Systems Virtual Private Networks (VPN) Information Systems Security Architecture Professional Python (Programming Language) Network Security Network Troubleshooting Network Diagrams Routing Network Segmentation OAuth OpenID Ping (Networking Utility) Windows PowerShell Remote Access Technology Azure Active Directory Ansible Zero Trust Network Access Security Assertion Markup Language (SAML) Scaled Agile Framework Web Application Security Service Pack Security Information and Event Management TCP/IP Network Routers Computer Networking Systems Transport Layer Security Google Cloud Computer Network Operations Cloud Platform System Okta System Availability Grafana Reliability of Systems Firewalls (Computer Science) Network Support Palo Alto Networks Performance Monitor Fortinet Restful APIs Terraform Open Network Automation Platform Devsecops

Job description

The Senior Network Engineer - SASE will lead the design, deployment, automation, operation, and continuous improvement of Cargill's global Secure Access Service Edge (SASE) and Security Service Edge (SSE) capabilities. This role will help transform secure connectivity by migrating legacy web proxy and remote-access technologies to cloud-delivered security services, including Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), and threat protection. The engineer will provide technical leadership across network, security, identity, cloud, endpoint, and application teams to deliver reliable, scalable, and policy-driven access for users, sites, and applications., * NETWORK SOLUTIONS: Designs, implements and maintains network solutions to meet organizational needs, including creating network diagrams and blueprints.

  • NETWORK DEVICES CONFIGURATION: Sets up and configures various complex network devices such as routers, switches, firewalls, virtual private networks and software defined networking to maintain optimal performance and security.
  • TROUBLESHOOTING & DIAGNOSTICS: Performs complex troubleshooting and diagnostics to resolve network issues, ensuring minimal downtime and maintaining network reliability.
  • NETWORK MAINTENANCE: Leads routine maintenance and updates on network systems, including applying patches, service packs and security configurations.
  • PERFORMANCE MONITORING & OPTIMIZATION: Monitors network performance, maintains system availability and reliability, and makes necessary adjustments to optimize performance.
  • SECURITY MEASURES: Sustains network security by leading the implementation of appropriate measures such as firewalls, intrusion detection systems and encryption technologies.
  • DISASTER RECOVERY PLANNING: Develops and implements disaster recovery plans to ensure business continuity in case of network failures.
  • NETWORK AUTOMATION: Develops and implements automation and tools to streamline network operations, including configuration management, device provisioning and software updates.

Requirements

  • Minimum requirement of 4 years of relevant work experience. Typically reflects 5 years or more of relevant experience.
  • Minimum of 5 years of relevant experience in network engineering, network security, or cybersecurity engineering.
  • Hands-on experience implementing and supporting SASE or SSE solutions in an enterprise environment.
  • Experience deploying and managing SWG and ZTNA technologies.
  • Strong understanding of enterprise networking fundamentals, including TCP/IP, routing, switching, DNS, DHCP, VPNs, SSL/TLS, certificates, and network security principles.
  • Experience troubleshooting complex connectivity, authentication, and application-access issues across hybrid and cloud environments.

Preferred:

  • Experience implementing and administering one or more leading SASE/SSE platforms, such as Netskope, Palo Alto Prisma Access, Zscaler Internet Access (ZIA), or Zscaler Private Access (ZPA).
  • Experience designing, implementing, and supporting enterprise firewall platforms, such as Check Point, Palo Alto Networks, or Fortinet, including security policy management, network segmentation, NAT, VPN connectivity, and integration with SASE architectures.
  • Deep understanding of SWG capabilities, including URL filtering, SSL/TLS inspection, cloud application visibility and control, malware protection, DLP, threat prevention, and policy enforcement.
  • Experience designing ZTNA solutions for secure access to private applications and reducing reliance on traditional VPN technologies.
  • Experience with SASE traffic steering and service components, including endpoint clients, GRE/IPsec tunnels, private access connectors or publishers, dedicated egress, and high-availability designs.
  • Strong understanding of identity-driven security and integration with Microsoft Entra ID, Okta, Ping Identity, or similar identity providers using SAML, OAuth, OIDC, and SCIM.
  • Experience integrating SASE platforms with endpoint security, SIEM, XDR, and security operations workflows.
  • Knowledge of cloud networking and security architectures across AWS, Azure, and Google Cloud Platform.
  • Experience with policy lifecycle management, security posture assessments, exception governance, and change control for cloud-delivered security services.
  • Experience with automation and scripting using Python, PowerShell, REST APIs, Terraform, Ansible, GitHub, or similar tools.
  • Experience with network, security, and digital-experience observability tools used to monitor user experience, application performance, and security events.
  • Ability to develop technical architecture documentation, low-level design artifacts, implementation plans, operational runbooks, and support models for SASE deployments.
  • Experience working within Agile engineering teams using modern engineering and DevSecOps practices.
  • Demonstrated ability to provide technical leadership, mentor engineers, and collaborate across network, security, identity, cloud, endpoint, and application teams.

About the company

Cargill is committed to providing food and agricultural solutions to nourish the world in a safe, responsible, and sustainable way. Sitting at the heart of the supply chain, we partner with farmers and customers to source, make and deliver products that are vital for living. Our 155,000 team members innovate with purpose, providing customers with life?s essentials so businesses can grow, communities prosper, and consumers live well. With over 160 years of experience as a family company, we look ahead while remaining true to our values. We put people first. We reach higher. We do the right thing?today and for generations to come.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · WWC 2022

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all