EngineerJobs.io
← Back to all jobs

Job Description

Data Protection Security Engineer – Netskope Lead. A hands-on security engineer with deep Netskope expertise capable of independently leading enterprise-wide NG SWG, NPA, and DLP initiatives. This hybrid role requires three days onsite and two days remote, based in Foster City, MI, at USD 108 per hour.

Responsibilities

  • Oversee end-to-end administration and health of the Netskope tenant, ensuring correct configuration, consistent enforcement, and alignment with the client’s security policies and risk posture.
  • Manage the NG SWG to inspect, control, and secure web traffic across the enterprise, leveraging Skope AI's threat intelligence and behavioral analytics for real-time anomaly detection and response.
  • Build and maintain SSL inspection policies, URL filtering categories, threat protection profiles, and cloud app controls, with clear understanding of how these layers interact.
  • Lead the full lifecycle deployment of Netskope NG SWG, including architecture design, tenant configuration, traffic steering, and integration with existing security infrastructure.
  • Configure and maintain SSL/TLS inspection, URL filtering, cloud application controls, and threat protection policies.
  • Integrate Netskope with identity providers (Okta, Azure AD) for user-based policy enforcement.
  • Manage Netskope client deployment across endpoints in coordination with endpoint and IT teams.
  • Establish and maintain logging, alerting, and reporting pipelines from the Netskope platform into SIEM tools.
  • Lead the design and deployment of Netskope NPA to enable zero-trust application access and to replace or supplement traditional VPN infrastructure.
  • Define publisher placement, application segmentation, and access policies aligned to least-privilege principles.
  • Collaborate with application owners and IT teams to onboard private applications to the NPA framework and continuously evaluate policies based on access patterns and security posture requirements.
  • Develop a comprehensive DLP strategy for web, cloud, and private application traffic traversing the Netskope platform.
  • Create, tune, and maintain DLP profiles and policies for PII, PHI, PCI, intellectual property, and other regulated or confidential data types.
  • Conduct structured DLP policy testing using representative data samples to validate detection accuracy and minimize false positives.
  • Establish a formal policy review cadence with Legal, Compliance, and Data Governance teams.
  • Investigate and respond to DLP policy alerts, escalating incidents per established procedures.
  • Serve as the subject matter expert for Netskope NG SWG, NPA, and DLP across security, IT, and business teams.
  • Produce and maintain architecture diagrams, runbooks, policy documentation, and operational procedures.
  • Provide guidance and knowledge transfer to junior engineers and security operations staff.
  • Engage with Netskope TAM and support resources to stay current on platform capabilities and roadmap.

Requirements

  • 8+ years of experience in network security, cloud security, or information security engineering.
  • 2+ years of hands-on experience deploying and managing Netskope NG SWG and/or NPA in an enterprise environment.
  • Proven experience developing and managing DLP policies, including policy design, testing, and tuning.
  • Strong understanding of zero-trust network access (ZTNA) concepts and architectures.
  • Proficiency with SSL/TLS inspection, proxy architectures, and cloud access security broker (CASB) functionality.
  • Working knowledge of identity and access management platforms (Okta, Azure AD, SAML, SCIM).
  • Familiarity with regulatory frameworks relevant to DLP (HIPAA, PCI-DSS, GDPR, CCPA, etc.).
  • Strong analytical and troubleshooting skills with the ability to work through complex network and policy issues.

Technologies

  • Netskope NG SWG
  • Netskope NPA
  • Okta
  • Azure AD
  • SAML
  • SCIM
  • SIEM
  • Splunk
  • Microsoft Sentinel
  • Python
  • PowerShell

Similar Jobs