Network Security Engineer
Casb
Cloud Firewall
Cloud Platforms
Cloud Security
Cybersecurity Tools
Data Security
Incident Response
Information Security
Information Technology (IT)
InfoSec
Network Engineering
Network Security
Network Security Analysis
Network Security Tools
Network Security Vpn
Network Support
Networking & Security
Sase/ztna
Security
Security Engineer
Security Engineering
Security Operations
Zscaler
Job Description
Legato Security is seeking a Network Security Engineer to support the administration, implementation, troubleshooting, design, and continuous improvement of customers’ networks and security environments. This hybrid/mostly remote role includes some on-call time and may require occasional time in the office in downtown Salt Lake City, UT, along with client visits as needed.
Responsibilities
- Support, administer, configure, and troubleshoot firewalls, Zscaler services, Netskope, VPN technologies, and related network security platforms across internal and customer environments.
- Collaborate with customers to understand business and technical requirements, troubleshoot issues, evaluate solutions, and implement changes.
- Respond to and resolve service tickets, incidents, requests, and escalations involving network connectivity, firewalls, Zscaler, Netskope, and related technologies.
- Act as an escalation point for technical issues requiring additional troubleshooting, analysis, or specialized expertise beyond initial support.
- Support and configure firewall and network product environments to meet customer connectivity and security requirements.
- Participate in firewall, Zscaler, and Netskope implementation, migration, upgrade, replacement, and configuration projects.
- Assist with configuration and maintenance of Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, and related services.
- Assist with configuration and maintenance of the Netskope One platform, including SASE, SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN, and more.
- Support Zscaler and Netskope policies, including URL filtering, firewall policies, SSL inspection, authentication, access policies, application access, traffic forwarding, connectivity, routing, DNS, DHCP, NAT, VPNs, SSL/TLS inspection, VLANs, switching technologies, and policy enforcement.
- Configure and troubleshoot VPN technologies including SSL VPN, IPsec, Remote Access VPN, and Site-to-Site VPN connections.
- Review firewall logs, Zscaler logs, Netskope logs, packet captures, routing tables, traffic flows, error messages, and other diagnostics to determine root cause.
- Assist with customer onboarding and changes to existing network and security environments, including testing and validation prior to production deployment.
- Create and maintain firewall documentation, configuration records, troubleshooting procedures, implementation notes, and customer-specific technical documentation.
- Participate in incident response, problem management, and root-cause analysis activities as needed.
- Manage multiple unresolved tickets, incidents, projects, and customer requests, individually and in collaboration with team members and technical resources.
- Support engineers and analysts through troubleshooting processes, technical methodologies, and network security best practices.
- Identify opportunities to improve network configurations, security controls, operational processes, troubleshooting methods, documentation, and customer experience.
- Maintain awareness of emerging networking and cybersecurity technologies, vendor platform changes, vulnerabilities, security capabilities, and industry best practices.
Requirements
- Hands-on experience with one or more network security technologies such as firewalls, Zscaler, Netskope, VPNs, secure web gateways, SSE/SASE platforms, proxies, or zero-trust technologies.
- Strong troubleshooting and analytical skills to diagnose network and security issues methodically.
- Working knowledge of routing concepts and protocols including TCP/IP, BGP, OSPF, EIGRP, IS-IS, RIP, Static Routing, and SD-WAN.
- Working knowledge of LAN technologies including Ethernet switching, VLANs, Spanning Tree Protocol (STP), port security, link/port aggregation, and LAN/WAN architecture.
- Experience or familiarity with physical, virtual, and cloud firewall technologies.
- Understanding of firewall concepts including security policies, zones and interfaces, objects and object groups, routing, NAT, VPNs, application and service policies, logging, and traffic analysis.
- Knowledge or familiarity of VPN technologies including IPsec, SSL VPN, Remote Access VPN, and Site-to-Site VPN.
- Working knowledge of NAT concepts (Source NAT, Destination NAT, and U-Turn/Hairpin NAT), DNS, and DHCP.
- Familiarity with authentication and identity technologies such as SAML, SSO, MFA, Active Directory, Entra ID, and SCIM.
- Ability to capture, analyze, and interpret network traffic using Wireshark or similar packet-analysis tools.
- Ability to interpret network and security logs, packet captures, routing information, error messages, and other diagnostics.
- Ability to design and document network and related security solutions would be helpful.
- Strong customer-facing skills, including active listening, evaluating requirements, asking appropriate questions, and clearly explaining technical issues and solutions.
- Ability to communicate effectively with both technical and non-technical audiences.
- Ability to work in team environments and independently as needed.
- Ability to handle multiple customers, environments, projects, incidents, and priorities simultaneously.
- Ability to manage time effectively and see incidents, requests, and technical issues through to resolution.
- Willingness and ability to learn new technologies and build deeper expertise across networking and network security platforms.
Technologies
- firewalls, Zscaler, Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, Zscaler Digital Experience (ZDX), Zscaler Cloud Firewall, Zscaler Data Loss Prevention (DLP)
- Netskope, Netskope One, SASE, SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN
- Zscaler traffic forwarding technologies, Zscaler API integrations and automation, Netskope One SASE, Netskope One SSE, SkopeAI
- VPN technologies, SSL VPN, IPsec, Remote Access VPN, Site-to-Site VPN connections
- TCP/IP, BGP, OSPF, EIGRP, IS-IS, RIP, Static Routing
- Ethernet switching, VLANs, Spanning Tree Protocol (STP), Port security, Link/port aggregation
- NAT, Source NAT, Destination NAT, U-Turn/Hairpin NAT, DNS, DHCP
- SAML, SSO, MFA, Active Directory, Entra ID, SCIM, SSL inspection, SSL/TLS inspection
- Wireshark, packet captures
Benefits
- Growth-phase startup environment with opportunity for advancement based on performance.
- Startup culture with an office in downtown Salt Lake City, UT.
- Competitive medical and dental benefits for employees and family members.
- Additional company-provided benefits such as short-term disability, basic life insurance, children’s orthodontia, and optional voluntary benefits.
- Flexible Paid Time Off policy.
- Professional Development opportunities specific to the role.
Preferred Qualifications
- Experience with firewall and network security platforms (examples listed): Palo Alto Networks; Cisco ASA / Cisco Secure Firewall; Fortinet FortiGate; Check Point; Juniper SRX; SonicWall; Cisco Meraki; Sophos; WatchGuard; Microsoft Azure network security technologies; Amazon Web Services network security technologies.
- Experience with Zscaler technologies (examples listed): ZIA, ZPA, Zscaler Client Connector, ZDX, Zscaler Cloud Firewall, Zscaler DLP, Zscaler traffic forwarding technologies, Zscaler API integrations and automation.
- Experience with Netskope technologies (examples listed): Netskope One SASE, Netskope One SSE, CASB, Next Generation Secure Web Gateway (SWG), Private Access, Cloud Firewall, SD-WAN, SkopeAI.
- Understanding or experience with cloud networking and security technologies within Microsoft Azure, AWS, and GCP would be helpful.
- Experience with cloud networking concepts such as Virtual networks/VPCs, subnets, route tables, security groups, cloud firewalls, VPN gateways, private connectivity, cloud routing, and hybrid network connectivity.
- Familiarity with wireless network security, troubleshooting, and design.
- Familiarity with SNMP monitoring and alerting solutions.
- Familiarity with network monitoring and performance-management platforms.
- Familiarity with packet capture and network troubleshooting tools.
- Familiarity with network automation.
- Familiarity with REST APIs, PowerShell, and/or Python.
- Familiarity with infrastructure scripting or automation.
- Relevant networking, security, firewall, cloud, Netskope, or Zscaler certifications are a plus but not required, with preference for active and actively maintained certifications (examples listed): Zscaler ZDTA or ZDTE; Netskope NCCSI (NSK200), Netskope NCCSA (NSK300), or Netskope SASE Accreditation; Cisco CCNA or CCNP; Palo Alto Networks CSA or CSP; CompTIA Network+ or Security+.
Position Overview
- Supports the administration, implementation, troubleshooting, design, and ongoing improvement of customers’ networks and security environments.
- Works across operational and project-based activities including customer requests, incidents, service tickets, troubleshooting, implementations, migrations, upgrades and changes, and technical projects.
- Must communicate effectively, manage competing priorities, adapt to different technical requirements, and see issues through to resolution due to support across multiple customers and environments.
- Hybrid and mostly remote, with potential time in office (downtown Salt Lake City) for troubleshooting, updating, and replacing network equipment; client visits as required.
- Some rotational on-call time is required and described as not extensive.