Cloud Security Engineer-Netskope

Denken Solutions
Foster City, CA, United States
2 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$176,800.0 - $208,000.0
Working hours
Regular working hours
Job source

Tech stack

Access Network Artificial Intelligence Software as a Service Cloud Computing Cloud Computing Security Complex Networks CompTIA Security+ Cyber Security Data Governance Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language)
+19 more
Network Security Log Analysis PCI Data Security Standards Performance Tuning Windows PowerShell Azure Active Directory Zero Trust Network Access Runbook Security Assertion Markup Language (SAML) Web Application Security Security Information and Event Management Systems Integration Data Logging Scripting Transport Layer Security Okta Information Technology Microsoft Sentinel Splunk

Job description

In this role, you will be responsible for the end-to-end administration and health of the Netskope tenant, ensuring that all deployed products are correctly configured, consistently enforced, and aligned with the client’s security policies and risk posture. You will manage the NG SWG to inspect, control, and secure web traffic across the enterprise, leveraging Skope AI’s threat intelligence and behavioral analytics to detect and respond to anomalous activity in real time. You will be expected to build and maintain SSL inspection policies, URL filtering categories, threat protection profiles, and Cloud app controls with a clear understanding of how these layers interact.

  • Netskope NG SWG Implementation & Management
  • Lead the full lifecycle deployment of Netskope NG SWG, including architecture design, tenant configuration, traffic steering, and integration with existing security infrastructure
  • Configure and maintain SSL/TLS inspection, URL filtering, cloud application controls, and threat protection policies
  • Integrate Netskope with identity providers (e.g., Okta, Azure AD) for user-based policy enforcement
  • Manage Netskope client deployment across endpoints in coordination with endpoint and IT teams
  • Establish and maintain logging, alerting, and reporting pipelines from the Netskope platform into SIEM tools
  • Netskope NPA Implementation & Management
  • Lead the design and deployment of Netskope NPA to replace or supplement traditional VPN infrastructure, enabling zero-trust application access
  • Define publisher placement, application segmentation, and access policies aligned to least-privilege principles
  • Collaborate with application owners and IT teams to onboard private applications to the NPA framework
  • Continuously evaluate and refine NPA policies based on access patterns and security posture requirements
  • DLP Policy Development & Testing
  • Develop a comprehensive DLP strategy covering web, cloud, and private application traffic traversing the Netskope platform
  • Create, tune, and maintain DLP profiles and policies for sensitive data categories, including PII, PHI, PCI, intellectual property, and other regulated or confidential data types
  • Conduct structured DLP policy testing using representative data samples to validate detection accuracy and minimize false positives
  • Establish a formal policy review and tuning cadence in partnership with Legal, Compliance, and Data Governance teams
  • Investigate and respond to DLP policy alerts, escalating incidents per established procedures
  • Stakeholder Collaboration & Documentation
  • Serve as the subject matter expert for Netskope NG SWG, NPA, and DLP across security, IT, and business teams
  • Produce and maintain architecture diagrams, runbooks, policy documentation, and operational procedures
  • Provide guidance and knowledge transfer to junior engineers and security operations staff
  • Engage with Netskope TAM and support resources to stay current on platform capabilities and roadmap

Requirements

Do you have experience in Zero trust architecture design?, Do you have a Bachelor’s degree?, The ideal candidate is a hands-on security engineer with deep Netskope expertise who can independently lead enterprise-wide NG SWG, NPA, and DLP initiatives while partnering effectively with security, networking, infrastructure, compliance, and business stakeholders. Experience with Zero Trust architectures, DLP policy development, and enterprise-scale

Security deployments is essential., * 8+ years of experience in network security, cloud security, or information security engineering

  • 2+ years of hands-on experience deploying and managing Netskope NG SWG and/or NPA in an enterprise environment
  • Demonstrated experience developing and managing DLP policies, including policy design, testing, and tuning
  • Strong understanding of zero-trust network access (ZTNA) concepts and architectures
  • Proficiency with SSL/TLS inspection, proxy architectures, and cloud access security broker (CASB) functionality
  • Working knowledge of identity and access management platforms (Okta, Azure AD, SAML, SCIM)
  • Familiarity with regulatory frameworks relevant to DLP (HIPAA, PCI-DSS, GDPR, CCPA, etc.)
  • Strong analytical and troubleshooting skills with the ability to work through complex network and policy issues

Preferred Qualifications:

  • Netskope One Professional or equivalent Netskope certification
  • Experience integrating Netskope with SIEM/SOAR platforms (Splunk, Microsoft Sentinel, etc.)
  • Background in endpoint security, SASE architecture, or broader SSE framework implementation
  • Experience with scripting or automation (Python, PowerShell) for policy management or log analysis
  • Familiarity with additional DLP tools or platforms beyond Netskope

Education:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field - or equivalent hands-on experience in lieu of a degree

Preferred Certifications:

  • CISSP, CCSP (ISC²), CISM or equivalent security certification
  • CompTIA Security+ or Network+

Benefits & conditions

4100 East 3rd Avenue, Foster City, CA 94404, Hybrid work $85 - $100 an hour - Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

10:19 min

Continuous learning strategies and emerging industry trends

Kurt Eder · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

7:50 min

Prioritizing cybersecurity and zero trust in development

Ash Ryan Arnwine Ash Ryan Arnwine +3 · WWC 2024

Videos

See all

Related articles

See all