Network Security Engineer (SASE/ZTNA)

Clearance Level
None
Category
Cyber and IT Risk Management
Location
Falls Church, Virginia
Key Skills For Success

Netskope

Netskope Security Cloud

Zero Trust

REQ#: RQ215198
Public Trust: NACI (T1)
Requisition Type: Regular
Your Impact

Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the well being and support of U.S. citizens.

Job Description

Position Summary:

We are looking for a Network Security Engineer to support the advancement of our secure access infrastructure and play a key role in managing and modernizing our security operations. The individual will play a significant role in transitioning from a legacy Cisco Secure Client environment to a modern, cloud-native SASE (Secure Access Service Edge) architecture, with a strong focus on Zero Trust Network Access (ZTNA).If you are a skilled network engineer with a passion for SASE, ZTNA, and automation, we encourage you to apply and help drive our organization’s secure and efficient future.

Key Responsibilities:

  • Implementation & Maintenance:
    • Assist in deploying and managing SASE/SSE components, including Secure Web Gateways (SWG), Cloud Access Security Brokers (CASB), Firewall-as-a-Service (FWaaS), SD-WAN, and Zero Trust Network Access (ZTNA).
  • Modernizing Access:
    • Support the migration from legacy Cisco Secure Client environments to identity-centric Zero Trust models, ensuring a smooth transition and troubleshooting any challenges.
  • Automation & Integration:
    • Write and understand API scripts (e.g., Python, PowerShell, Bash) for automating manual tasks, pulling security telemetry, and integrating Netskope or other cloud-native services.
  • Advanced Network Troubleshooting:
    • Routing & Proxy: Diagnose and resolve traffic flow issues, PAC file misconfigurations, transparent proxies, and SSL inspection challenges.
    • Protocol Analysis: Utilize Wireshark or tcpdump to troubleshoot complex network paths, including latency, packet loss, and SSL/TLS issues.
    • Connectivity: Resolve issues involving VLANs, NAT, 802.1X supplicants, DNS, and SaaS/COTS applications.
    • SD-WAN Integration: Collaborate on integrating SD-WAN with SASE platforms for secure traffic steering and optimal performance.
  • Infrastructure Monitoring & Health:
    • Manage and monitor network health using SNMP, SIEM, Grafana, and syslog tools.
    • Troubleshoot network connectivity issues within Docker/Linux environments.
  • Cloud Security Support:
    • Maintain firewall policies across AWS, Azure, and GCP while managing API-based security integrations with products such as Netskope.

Required Qualifications:

Competency

Requirement

Experience

- 5+ years in Network/VPN Engineering. 

- 2+ years hands-on experience with SASE/ZTNA platforms and Cloud services.

Critical Skills

- Strong critical thinking and problem-solving skills. 

- Effective communication and teamwork abilities. 

- Fast learner with the ability to adapt to evolving technologies.

Architecture

- Solid understanding of SD-WAN integration with SSE/SASE frameworks.

OS Proficiency

- Deep understanding of Windows 10/11 network behaviors and troubleshooting on client-side devices.

Routing & Proxy

- Strong knowledge of routing protocols, proxy (PAC file configuration), and architecture concepts.

VPN & NAC

- Hands-on experience with Cisco Secure Client (AnyConnect), firewalls, and 802.1X authentication protocols.

Monitoring & Ops

- Proficiency in tools such as SNMP, SIEM, Grafana, and Docker troubleshooting for monitoring operational health.

SASE/ZTNA

- Hands-on expertise with solutions, including NetskopeZscaler, or Palo Alto Networks Prisma Access.

Programming Skills

- Strong experience with scripting and automation using Python, PowerShell, or Bash.

Preferred Qualifications:

  • Certifications such as CCNP Security, NSE4, Zscaler Certified Cloud Engineer, or equivalent are highly desirable.
  • Familiarity with secure DevOps principles and CI/CD in cloud environments.
  • Experience securing hybrid cloud workloads across AWSAzure, and Google Cloud.

Job Benefits:

  • Competitive compensation and benefits package.
  • Opportunity to work on cutting-edge SASE/ZTNA solutions and architectures.
  • Collaborative environment fostering professional growth and innovation.

Work Requirements
Years of Experience

7 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

Travel Required

None

Salary and Benefit Information

The likely salary range for this position is $81,600 - $110,400. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
View information about benefits and our total rewards program.

About Our Work

We are GDIT. A global technology and professional services company that delivers technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across over 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber and application development. Together with our customers, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans