EngineerJobs.io
← Back to all jobs

Job Description

Legato Security is seeking a Network Security Engineer to support the administration, implementation, troubleshooting, design, and continuous improvement of customers’ networks and security environments. This hybrid/mostly remote role includes some on-call time and may require occasional time in the office in downtown Salt Lake City, UT, along with client visits as needed.

Responsibilities

  • Support, administer, configure, and troubleshoot firewalls, Zscaler services, Netskope, VPN technologies, and related network security platforms across internal and customer environments.
  • Collaborate with customers to understand business and technical requirements, troubleshoot issues, evaluate solutions, and implement changes.
  • Respond to and resolve service tickets, incidents, requests, and escalations involving network connectivity, firewalls, Zscaler, Netskope, and related technologies.
  • Act as an escalation point for technical issues requiring additional troubleshooting, analysis, or specialized expertise beyond initial support.
  • Support and configure firewall and network product environments to meet customer connectivity and security requirements.
  • Participate in firewall, Zscaler, and Netskope implementation, migration, upgrade, replacement, and configuration projects.
  • Assist with configuration and maintenance of Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, and related services.
  • Assist with configuration and maintenance of the Netskope One platform, including SASE, SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN, and more.
  • Support Zscaler and Netskope policies, including URL filtering, firewall policies, SSL inspection, authentication, access policies, application access, traffic forwarding, connectivity, routing, DNS, DHCP, NAT, VPNs, SSL/TLS inspection, VLANs, switching technologies, and policy enforcement.
  • Configure and troubleshoot VPN technologies including SSL VPN, IPsec, Remote Access VPN, and Site-to-Site VPN connections.
  • Review firewall logs, Zscaler logs, Netskope logs, packet captures, routing tables, traffic flows, error messages, and other diagnostics to determine root cause.
  • Assist with customer onboarding and changes to existing network and security environments, including testing and validation prior to production deployment.
  • Create and maintain firewall documentation, configuration records, troubleshooting procedures, implementation notes, and customer-specific technical documentation.
  • Participate in incident response, problem management, and root-cause analysis activities as needed.
  • Manage multiple unresolved tickets, incidents, projects, and customer requests, individually and in collaboration with team members and technical resources.
  • Support engineers and analysts through troubleshooting processes, technical methodologies, and network security best practices.
  • Identify opportunities to improve network configurations, security controls, operational processes, troubleshooting methods, documentation, and customer experience.
  • Maintain awareness of emerging networking and cybersecurity technologies, vendor platform changes, vulnerabilities, security capabilities, and industry best practices.

Requirements

  • Hands-on experience with one or more network security technologies such as firewalls, Zscaler, Netskope, VPNs, secure web gateways, SSE/SASE platforms, proxies, or zero-trust technologies.
  • Strong troubleshooting and analytical skills to diagnose network and security issues methodically.
  • Working knowledge of routing concepts and protocols including TCP/IP, BGP, OSPF, EIGRP, IS-IS, RIP, Static Routing, and SD-WAN.
  • Working knowledge of LAN technologies including Ethernet switching, VLANs, Spanning Tree Protocol (STP), port security, link/port aggregation, and LAN/WAN architecture.
  • Experience or familiarity with physical, virtual, and cloud firewall technologies.
  • Understanding of firewall concepts including security policies, zones and interfaces, objects and object groups, routing, NAT, VPNs, application and service policies, logging, and traffic analysis.
  • Knowledge or familiarity of VPN technologies including IPsec, SSL VPN, Remote Access VPN, and Site-to-Site VPN.
  • Working knowledge of NAT concepts (Source NAT, Destination NAT, and U-Turn/Hairpin NAT), DNS, and DHCP.
  • Familiarity with authentication and identity technologies such as SAML, SSO, MFA, Active Directory, Entra ID, and SCIM.
  • Ability to capture, analyze, and interpret network traffic using Wireshark or similar packet-analysis tools.
  • Ability to interpret network and security logs, packet captures, routing information, error messages, and other diagnostics.
  • Ability to design and document network and related security solutions would be helpful.
  • Strong customer-facing skills, including active listening, evaluating requirements, asking appropriate questions, and clearly explaining technical issues and solutions.
  • Ability to communicate effectively with both technical and non-technical audiences.
  • Ability to work in team environments and independently as needed.
  • Ability to handle multiple customers, environments, projects, incidents, and priorities simultaneously.
  • Ability to manage time effectively and see incidents, requests, and technical issues through to resolution.
  • Willingness and ability to learn new technologies and build deeper expertise across networking and network security platforms.

Technologies

  • firewalls, Zscaler, Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, Zscaler Digital Experience (ZDX), Zscaler Cloud Firewall, Zscaler Data Loss Prevention (DLP)
  • Netskope, Netskope One, SASE, SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN
  • Zscaler traffic forwarding technologies, Zscaler API integrations and automation, Netskope One SASE, Netskope One SSE, SkopeAI
  • VPN technologies, SSL VPN, IPsec, Remote Access VPN, Site-to-Site VPN connections
  • TCP/IP, BGP, OSPF, EIGRP, IS-IS, RIP, Static Routing
  • Ethernet switching, VLANs, Spanning Tree Protocol (STP), Port security, Link/port aggregation
  • NAT, Source NAT, Destination NAT, U-Turn/Hairpin NAT, DNS, DHCP
  • SAML, SSO, MFA, Active Directory, Entra ID, SCIM, SSL inspection, SSL/TLS inspection
  • Wireshark, packet captures

Benefits

  • Growth-phase startup environment with opportunity for advancement based on performance.
  • Startup culture with an office in downtown Salt Lake City, UT.
  • Competitive medical and dental benefits for employees and family members.
  • Additional company-provided benefits such as short-term disability, basic life insurance, children’s orthodontia, and optional voluntary benefits.
  • Flexible Paid Time Off policy.
  • Professional Development opportunities specific to the role.

Preferred Qualifications

  • Experience with firewall and network security platforms (examples listed): Palo Alto Networks; Cisco ASA / Cisco Secure Firewall; Fortinet FortiGate; Check Point; Juniper SRX; SonicWall; Cisco Meraki; Sophos; WatchGuard; Microsoft Azure network security technologies; Amazon Web Services network security technologies.
  • Experience with Zscaler technologies (examples listed): ZIA, ZPA, Zscaler Client Connector, ZDX, Zscaler Cloud Firewall, Zscaler DLP, Zscaler traffic forwarding technologies, Zscaler API integrations and automation.
  • Experience with Netskope technologies (examples listed): Netskope One SASE, Netskope One SSE, CASB, Next Generation Secure Web Gateway (SWG), Private Access, Cloud Firewall, SD-WAN, SkopeAI.
  • Understanding or experience with cloud networking and security technologies within Microsoft Azure, AWS, and GCP would be helpful.
  • Experience with cloud networking concepts such as Virtual networks/VPCs, subnets, route tables, security groups, cloud firewalls, VPN gateways, private connectivity, cloud routing, and hybrid network connectivity.
  • Familiarity with wireless network security, troubleshooting, and design.
  • Familiarity with SNMP monitoring and alerting solutions.
  • Familiarity with network monitoring and performance-management platforms.
  • Familiarity with packet capture and network troubleshooting tools.
  • Familiarity with network automation.
  • Familiarity with REST APIs, PowerShell, and/or Python.
  • Familiarity with infrastructure scripting or automation.
  • Relevant networking, security, firewall, cloud, Netskope, or Zscaler certifications are a plus but not required, with preference for active and actively maintained certifications (examples listed): Zscaler ZDTA or ZDTE; Netskope NCCSI (NSK200), Netskope NCCSA (NSK300), or Netskope SASE Accreditation; Cisco CCNA or CCNP; Palo Alto Networks CSA or CSP; CompTIA Network+ or Security+.

Position Overview

  • Supports the administration, implementation, troubleshooting, design, and ongoing improvement of customers’ networks and security environments.
  • Works across operational and project-based activities including customer requests, incidents, service tickets, troubleshooting, implementations, migrations, upgrades and changes, and technical projects.
  • Must communicate effectively, manage competing priorities, adapt to different technical requirements, and see issues through to resolution due to support across multiple customers and environments.
  • Hybrid and mostly remote, with potential time in office (downtown Salt Lake City) for troubleshooting, updating, and replacing network equipment; client visits as required.
  • Some rotational on-call time is required and described as not extensive.

Similar Jobs