Data Protection Security Engineer – Netskope Lead
Job Description
Data Protection Security Engineer – Netskope Lead. A hands-on security engineer with deep Netskope expertise capable of independently leading enterprise-wide NG SWG, NPA, and DLP initiatives. This hybrid role requires three days onsite and two days remote, based in Foster City, MI, at USD 108 per hour.
Responsibilities
- Oversee end-to-end administration and health of the Netskope tenant, ensuring correct configuration, consistent enforcement, and alignment with the client’s security policies and risk posture.
- Manage the NG SWG to inspect, control, and secure web traffic across the enterprise, leveraging Skope AI's threat intelligence and behavioral analytics for real-time anomaly detection and response.
- Build and maintain SSL inspection policies, URL filtering categories, threat protection profiles, and cloud app controls, with clear understanding of how these layers interact.
- Lead the full lifecycle deployment of Netskope NG SWG, including architecture design, tenant configuration, traffic steering, and integration with existing security infrastructure.
- Configure and maintain SSL/TLS inspection, URL filtering, cloud application controls, and threat protection policies.
- Integrate Netskope with identity providers (Okta, Azure AD) for user-based policy enforcement.
- Manage Netskope client deployment across endpoints in coordination with endpoint and IT teams.
- Establish and maintain logging, alerting, and reporting pipelines from the Netskope platform into SIEM tools.
- Lead the design and deployment of Netskope NPA to enable zero-trust application access and to replace or supplement traditional VPN infrastructure.
- Define publisher placement, application segmentation, and access policies aligned to least-privilege principles.
- Collaborate with application owners and IT teams to onboard private applications to the NPA framework and continuously evaluate policies based on access patterns and security posture requirements.
- Develop a comprehensive DLP strategy for web, cloud, and private application traffic traversing the Netskope platform.
- Create, tune, and maintain DLP profiles and policies for PII, PHI, PCI, intellectual property, and other regulated or confidential data types.
- Conduct structured DLP policy testing using representative data samples to validate detection accuracy and minimize false positives.
- Establish a formal policy review cadence with Legal, Compliance, and Data Governance teams.
- Investigate and respond to DLP policy alerts, escalating incidents per established procedures.
- Serve as the subject matter expert for Netskope NG SWG, NPA, and DLP across security, IT, and business teams.
- Produce and maintain architecture diagrams, runbooks, policy documentation, and operational procedures.
- Provide guidance and knowledge transfer to junior engineers and security operations staff.
- Engage with Netskope TAM and support resources to stay current on platform capabilities and roadmap.
Requirements
- 8+ years of experience in network security, cloud security, or information security engineering.
- 2+ years of hands-on experience deploying and managing Netskope NG SWG and/or NPA in an enterprise environment.
- Proven experience developing and managing DLP policies, including policy design, testing, and tuning.
- Strong understanding of zero-trust network access (ZTNA) concepts and architectures.
- Proficiency with SSL/TLS inspection, proxy architectures, and cloud access security broker (CASB) functionality.
- Working knowledge of identity and access management platforms (Okta, Azure AD, SAML, SCIM).
- Familiarity with regulatory frameworks relevant to DLP (HIPAA, PCI-DSS, GDPR, CCPA, etc.).
- Strong analytical and troubleshooting skills with the ability to work through complex network and policy issues.
Technologies
- Netskope NG SWG
- Netskope NPA
- Okta
- Azure AD
- SAML
- SCIM
- SIEM
- Splunk
- Microsoft Sentinel
- Python
- PowerShell