Job Description
Company – Our esteemed client is a leading organization in the financial services industry that operates a large-scale, security-focused enterprise environment. They are investing heavily in modern Zero Trust initiatives and enterprise cloud security, offering the opportunity to lead the transformation of critical security infrastructure at a global scale.
\n
\n
Job Title – Lead Enterprise SASE Security Engineer (Netskope Focus)
\n
Location – Tysons, VA (preferred) or San Antonio, TX | 5 days/week onsite
\n
Role Type – Contract
\n
\n
Must Have Skills:
\n
- \n
- Expert-level hands-on experience deploying and operationalizing enterprise-scale Netskope Security Cloud (SWG, CASB, ZTNA, DLP, RBI) or equivalent enterprise SASE platforms such as Zscaler or Prisma Access
- Proven experience leading enterprise migrations from legacy firewalls to SASE, including policy normalization, Zero Trust adoption, and cloud-native security policy design
- Deep expertise in Zero Trust Network Access (ZTNA), identity-based security, SSL inspection/decryption, NGFW policy optimization, and enterprise network security architecture
- Strong networking background across OSI Layers 1–7, SD-WAN, traditional firewalls, and integration with Azure AD, Ping Identity, and endpoint security solutions
- Strong automation experience using Python or another scripting language to integrate with security APIs, automate reporting, configuration management, and operational workflows
\n
\n
\n
\n
\n
\n
\n
Responsibilities and Job Details:
\n
- \n
- Serve as the technical lead responsible for the deployment and operational ownership of the organization's enterprise SASE architecture
- Lead the transition from legacy network security to a modern Zero Trust architecture
- Design, deploy, and optimize Netskope Security Service Edge (SSE) capabilities, including SWG, CASB, DLP, ZTNA, and RBI
- Drive major migration initiatives involving ZTNA policy engineering, firewall policy consolidation, SSL inspection optimization, firewall rule cleanup, and identity-based policy transformation
- Integrate Netskope with enterprise identity providers such as Azure AD and/or Ping Identity, as well as Endpoint Detection & Response (EDR) platforms
- Provide Tier 3 support for complex issues involving the Netskope Client, traffic steering, policy enforcement, and Windows/macOS endpoints
- Develop and maintain SASE architecture documentation, deployment standards, configuration guides, and operational procedures
- Partner with security, networking, and infrastructure teams to design scalable, cloud-native security solutions
- Lead enterprise security architecture discussions and provide hands-on technical leadership throughout implementation efforts
- Champion best practices for Zero Trust, policy governance, automation, and long-term operational excellence
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n