> Markdown version of [/jobs/ext/1996559-network-security-engineer-sase](https://www.wearedevelopers.com/jobs/ext/1996559-network-security-engineer-sase). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Security Engineer - SASE - **Company:** Cargill - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Amazon Web Services, Proxy Servers, Application Performance Management, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing, Configuration Management, Complex Networks, Cyber Security, Computer Networks, Information Leak Prevention, Dynamic Host Configuration Protocol, Software Design Documents, Network Address Translation, Disaster Recovery, Domain Name System (DNS), Github, Networking Hardware, Internet Protocol Security (IP SEC), Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Network Troubleshooting, Network Diagrams, Routing, Network Segmentation, OAuth, OpenID, Ping (Networking Utility), Windows PowerShell, Remote Access Technology, Azure Active Directory, Ansible, Zero Trust Network Access, Security Assertion Markup Language (SAML), Scaled Agile Framework, Web Application Security, Service Pack, Security Information and Event Management, TCP/IP, Network Routers, Computer Networking Systems, Transport Layer Security, Google Cloud, Computer Network Operations, Cloud Platform System, Okta, System Availability, Grafana, Reliability of Systems, Firewalls (Computer Science), Network Support, Palo Alto Networks, Performance Monitor, Fortinet, Restful APIs, Terraform, Open Network Automation Platform, Devsecops - **Published:** August 8, 2026 - **Apply:** https://www.dice.com/job-detail/59fe5871-b85a-43e3-8563-86f86f2dc3bb ## About the Role * Minimum requirement of 4 years of relevant work experience. Typically reflects 5 years or more of relevant experience. * Minimum of 5 years of relevant experience in network engineering, network security, or cybersecurity engineering. * Hands-on experience implementing and supporting SASE or SSE solutions in an enterprise environment. * Experience deploying and managing SWG and ZTNA technologies. * Strong understanding of enterprise networking fundamentals, including TCP/IP, routing, switching, DNS, DHCP, VPNs, SSL/TLS, certificates, and network security principles. * Experience troubleshooting complex connectivity, authentication, and application-access issues across hybrid and cloud environments. Preferred: * Experience implementing and administering one or more leading SASE/SSE platforms, such as Netskope, Palo Alto Prisma Access, Zscaler Internet Access (ZIA), or Zscaler Private Access (ZPA). * Experience designing, implementing, and supporting enterprise firewall platforms, such as Check Point, Palo Alto Networks, or Fortinet, including security policy management, network segmentation, NAT, VPN connectivity, and integration with SASE architectures. * Deep understanding of SWG capabilities, including URL filtering, SSL/TLS inspection, cloud application visibility and control, malware protection, DLP, threat prevention, and policy enforcement. * Experience designing ZTNA solutions for secure access to private applications and reducing reliance on traditional VPN technologies. * Experience with SASE traffic steering and service components, including endpoint clients, GRE/IPsec tunnels, private access connectors or publishers, dedicated egress, and high-availability designs. * Strong understanding of identity-driven security and integration with Microsoft Entra ID, Okta, Ping Identity, or similar identity providers using SAML, OAuth, OIDC, and SCIM. * Experience integrating SASE platforms with endpoint security, SIEM, XDR, and security operations workflows. * Knowledge of cloud networking and security architectures across AWS, Azure, and Google Cloud Platform. * Experience with policy lifecycle management, security posture assessments, exception governance, and change control for cloud-delivered security services. * Experience with automation and scripting using Python, PowerShell, REST APIs, Terraform, Ansible, GitHub, or similar tools. * Experience with network, security, and digital-experience observability tools used to monitor user experience, application performance, and security events. * Ability to develop technical architecture documentation, low-level design artifacts, implementation plans, operational runbooks, and support models for SASE deployments. * Experience working within Agile engineering teams using modern engineering and DevSecOps practices. * Demonstrated ability to provide technical leadership, mentor engineers, and collaborate across network, security, identity, cloud, endpoint, and application teams. ## Description The Senior Network Engineer - SASE will lead the design, deployment, automation, operation, and continuous improvement of Cargill\'s global Secure Access Service Edge (SASE) and Security Service Edge (SSE) capabilities. This role will help transform secure connectivity by migrating legacy web proxy and remote-access technologies to cloud-delivered security services, including Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), and threat protection. The engineer will provide technical leadership across network, security, identity, cloud, endpoint, and application teams to deliver reliable, scalable, and policy-driven access for users, sites, and applications., * NETWORK SOLUTIONS: Designs, implements and maintains network solutions to meet organizational needs, including creating network diagrams and blueprints. * NETWORK DEVICES CONFIGURATION: Sets up and configures various complex network devices such as routers, switches, firewalls, virtual private networks and software defined networking to maintain optimal performance and security. * TROUBLESHOOTING & DIAGNOSTICS: Performs complex troubleshooting and diagnostics to resolve network issues, ensuring minimal downtime and maintaining network reliability. * NETWORK MAINTENANCE: Leads routine maintenance and updates on network systems, including applying patches, service packs and security configurations. * PERFORMANCE MONITORING & OPTIMIZATION: Monitors network performance, maintains system availability and reliability, and makes necessary adjustments to optimize performance. * SECURITY MEASURES: Sustains network security by leading the implementation of appropriate measures such as firewalls, intrusion detection systems and encryption technologies. * DISASTER RECOVERY PLANNING: Develops and implements disaster recovery plans to ensure business continuity in case of network failures. * NETWORK AUTOMATION: Develops and implements automation and tools to streamline network operations, including configuration management, device provisioning and software updates. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)