Jobs Companies Legato Security Network Security Engineer

À propos de ce poste Network Security Engineer chez Legato Security

Legato Security · Hybride · Remote Office; Salt Lake City, Utah, United States

Enter Job Title 

 

Who We Are 

Legato Security is an information security firm founded upon the belief that every organization has the right to keep its data private and secure. Our mission is to build close partnerships with our clients, serving them not as just a vendor, but as trusted advisors helping to build effective, proactive plans. Our focus is always on both the technical and human elements within an organization. We believe in comprehensive strategies designed to harden networks, deflect attackers, and rapidly recover from any accidents. As technology progresses, so do our tactics, ensuring our experts are always prepared to serve forward-looking leaders eager to stay ahead of emerging threats. 

 

Position Overview 

We are seeking a Network Security Engineer to join our Network team. This role will support the administration, implementation, troubleshooting, design, and ongoing improvement of our customers’ networks and security environments.

The ideal candidate will have hands-on experience with network security technologies such as firewalls, Zscaler, Netskope, VPNs, routing, switching, or related technologies. Extensive experience with every platform is not required, but a strong networking foundation, practical troubleshooting ability, good communication skills, and a willingness to continually learn are essential.

This position will work across a variety of operational and project-based activities, including customer requests, incidents, service tickets, troubleshooting, implementations, migrations, upgrades and changes, and technical projects. Because the role supports multiple customers and environments, the successful candidate must be able to communicate effectively, manage competing priorities, adapt to different technical requirements, and see issues through to resolution.

This position is hybrid and mostly remote in nature, but may require some time in office (Downtown Salt Lake City) for troubleshooting, updating, and replacing network equipment; client visits as required, etc.  Some time on-call is required, but this will rotational and not extensive.

 

Specific Job Responsibilities 

  • Support, administer, configure, and troubleshoot firewalls, Zscaler services, Netskope, VPN technologies, and related network security platforms, both internal and in customer environments
  • Work directly with customers to understand business and technical requirements, troubleshoot problems, evaluate potential solutions, and implement appropriate changes
  • Respond to and resolve service tickets, incidents, requests, and escalations involving network connectivity, firewalls, Zscaler, Netskope, and related technology
  • Serve as an escalation point for technical issues that require additional troubleshooting, analysis, or expertise beyond initial support
  • Support, configure, and troubleshoot firewall and network product environments to meet customer connectivity and security requirements
  • Participate in firewall, Zscaler, and Netskope implementation, migration, upgrade, replacement, and configuration projects.
  • Assist with the configuration and maintenance of Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, and related services
  • Assist with the configuration and maintenance of the Netskope One platform including SASE, SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN, and more
  • Support Zscaler and Netskope policies including URL filtering, firewall policies, SSL inspection, authentication, access policies, application access, traffic forwarding, connectivity, routing, DNS, DHCP, NAT, VPNs, authentication, traffic forwarding, SSL/TLS inspection, application access, VLANs, switching technologies, and policy enforcement
  • Configure and troubleshoot VPN technologies including SSL VPN, IPsec, Remote Access VPN, and Site-to-Site VPN connections
  • Review firewall logs, Zscaler logs, Netskope logs, packet captures, routing tables, traffic flows, error messages, and other diagnostic information to determine root cause
  • Assist with customer onboarding and changes to existing customer network and security environments, testing and validation of new configurations, and other changes prior to production deployment
  • Create and maintain firewall documentation, configuration records, troubleshooting procedures, implementation notes, and customer-specific technical documentation.
  • Participate in incident response, problem management, and root-cause analysis activities as needed
  • Have the ability to manage multiple unresolved tickets, incidents, projects, and customer requests with assistance from other team members or technical resources as needed, both individually and in collaboration with team members
  • Assist engineers and analysts and with troubleshooting processes, technical methodologies, and network security best practices
  • Identify opportunities to improve network configurations, security controls, operational processes, troubleshooting methods, documentation, and customer experience
  • Maintain awareness of emerging networking and cybersecurity technologies, vendor platform changes, vulnerabilities, security capabilities, and industry best practices

 Qualifications 

Required Qualifications: 

  • Hands-on experience with one or more network security technologies such as firewalls, Zscaler, Netskope, VPNs, secure web gateways, SSE/SASE platforms, proxies, or zero-trust technologies
  • Strong troubleshooting and analytical skills with the ability to methodically diagnose network and security issues
  • Working knowledge of routing concepts and protocols such as TCP/IP, BGP, OSPF, EIGRP, IS-IS, RIP, Static Routing, and SD-WAN
  • Working knowledge of LAN technologies including Ethernet switching, VLANs, Spanning Tree Protocol (STP), Port security, Link/port aggregation, and LAN and WAN architecture
  • Experience or familiarity with physical, virtual, and cloud firewall technologies
  • Understanding of firewall concepts including Security policies, zones and interfaces, objects and object groups, routing, NAT, VPNs, Application and Service policies, Logging, and traffic analysis
  • Knowledge or familiarity of VPN technologies including IPsec, SSL VPN, Remote Access VPN, and Site-to-Site VPN
  • Working knowledge of concepts including NAT (Source NAT, Destination NAT, and U-Turn/Hairpin NAT), DNS, and DHCP
  • Familiarity with authentication and identity technologies such as SAML, SSO, MFA, Active Directory, Entra ID, and SCIM
  • Ability to capture, analyze, and interpret network traffic using Wireshark or similar packet-analysis tools
  • Ability to interpret network and security logs, packet captures, routing information, error messages, and other diagnostic information
  • Ability to design and document network and related security solutions would be helpful 
  • Strong customer-facing skills, including the ability to listen, evaluate requirements, ask appropriate questions, and clearly explain technical issues and solutions
  • Ability to communicate effectively with both technical and non-technical audiences
  • The ability to work both within a team environment and individual situations are required
  • Ability to work with multiple customers, environments, projects, incidents, and priorities simultaneously
  • Ability to manage time effectively and see incidents, requests, and technical issues through to resolution
  • Willingness and ability to learn new technologies and develop deeper expertise across networking and network security platforms

Preferred Qualifications: 

Experience with one or more of the following technologies or disciplines is beneficial but not required:

Firewall and Network Security Platforms

  • Palo Alto Networks
  • Cisco ASA / Cisco Secure Firewall
  • Fortinet FortiGate
  • Check Point
  • Juniper SRX
  • SonicWall
  • Cisco Meraki
  • Sophos
  • WatchGuard
  • Microsoft Azure network security technologies
  • Amazon Web Services network security technologies

Zscaler Technologies

  • Zscaler Internet Access (ZIA)
  • Zscaler Private Access (ZPA)
  • Zscaler Client Connector
  • Zscaler Digital Experience (ZDX)
  • Zscaler Cloud Firewall
  • Zscaler Data Loss Prevention (DLP)
  • Zscaler traffic forwarding technologies
  • Zscaler API integrations and automation

Netskope Technologies

  • Netskope One SASE
  • Netskope One SSE
  • Cloud Access Security Broker (CASB)
  • Next Generation Secure Web Gateway (SWG)
  • Private Access
  • Cloud Firewall
  • SD-WAN
  • SkopeAI

Cloud Networking

Understanding or experience with cloud networking and security technologies within Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP) would be helpful.

Experience with cloud technologies such as Virtual networks/VPCs, subnets, route tables, security groups, cloud firewalls, VPN gateways, private connectivity, cloud routing, hybrid network connectivity

Additional Technologies

Familiarity or experience with the following would be beneficial:

  • Wireless network security, protocols, troubleshooting, and design
  • SNMP monitoring and alerting solutions
  • Network monitoring and performance-management platforms
  • Packet capture and network troubleshooting tools
  • Network automation
  • REST APIs, PowerShell, and/or Python
  • Infrastructure scripting or automation

Certifications

Relevant networking, security, firewall, cloud, Netskope, or Zscaler certifications are considered a plus but are not required.  However, preference will be given towards active and actively maintained certification along the lines of Zscaler and firewalls vendors.

Examples may include:

    • Zscaler Digital Transformation Administrator (ZDTA) or Zscaler Digital Transformation Engineer (ZDTE)
    • Netskope Certified Cloud Security Integrator (NCCSI - NSK200), Netskope Certified Cloud Security Architect (NCCSA - NSK300), or Netskope SASE Accredidation
    • Cisco CCNA or CCNP
    • Palo Alto Networks CSA or CSP
    • CompTIA Network+ or Security+
    • Other relevant networking or cybersecurity certifications

Perks 

·       Start-up company in a growth phase with opportunity for advancement based on performance 

·       Start-up culture with an office in downtown Salt Lake City, UT 

·       Competitive medical and dental benefits for employee and family members 

·       Other company-provided benefits such as short-term disability, basic life insurance, children’s orthodontia, with additional voluntary benefits available

·       Flexible Paid Time Off policy 

·       Professional Development opportunities specific to role 

 

 

Prêt à postuler chez Legato Security ?
Postuler chez Legato Security

À propos de Legato Security

Legato Security is a Managed Security Services Provider (MSSP) founded upon the belief that every organization has the right to keep its data private and secure.

Our focus is to build close partnerships with our customers, serving them not just as a vendor, but as trusted advisors helping to build comprehensive security strategies that protect them from today’s most advanced attacks.

We partner with our customers and offer security solutions that scale to any size organization, through a combination of best-of-breed security tools and state-of-the-art security strategies. We offer a number of managed detection and response (MDR, strategic and professional security services that will instantly improve an organization’s security posture and minimize the chances of an incident.

Our employees and security experts are at the core of everything that we do. We recognize that individuals bring unique skill sets through a wide range of experiences and we are always on the hunt for forward-thinking and driven individuals to join the team.

Voir tous les emplois chez Legato Security →

Emplois similaires

Accenture
Azure Cloud Security Engineer
Accenture
⚡ Postuler tôt Lisbon Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 7 min
GQ
Grupo QuintoAndar | Senior Security Engineer - CSIRT
Grupo QuintoAndar
⚡ Postuler tôt Brasil Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 3 h
GQ
Grupo QuintoAndar | Sênior Security Engineer (DataSecurity)
Grupo QuintoAndar
⚡ Postuler tôt Brasil Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 3 h
Harvey
Staff Product Security Engineer
Harvey
⚡ Postuler tôt San Francisco Hybride $220,000–$330,000
● Nouveau 👁 Vu ✓ Postulé il y a 6 h
Harvey
Senior Product Security Engineer
Harvey
⚡ Postuler tôt San Francisco Hybride $188,000–$282,000
● Nouveau 👁 Vu ✓ Postulé il y a 6 h
Baseten
Security Engineer
Baseten
⚡ Postuler tôt San Francisco Hybride $150,000–$250,000
● Nouveau 👁 Vu ✓ Postulé il y a 6 h
ME
Platform Engineer, Application Security
Metr
⚡ Postuler tôt Berkeley Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 6 h
Databricks
Sr. Forward Deployed Engineer - National Security
Databricks
⚡ Postuler tôt United States Hybride $182,000–$250,208
● Nouveau 👁 Vu ✓ Postulé il y a 7 h
MetroStar
Sr. Information Systems Security Engineer (ISSE) II (6836)
MetroStar
⚡ Postuler tôt Reston, VA Sur site $190,000–$250,000
● Nouveau 👁 Vu ✓ Postulé il y a 7 h

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit