×
Register Here to Apply for Jobs or Post Jobs. X

Lead Enterprise SASE Security Engineer (Netskope

Job in Tysons, Fairfax County, Virginia, USA
Listing for: Judge Group, Inc.
Full Time position
Listed on 2026-08-04
Job specializations:
  • IT/Tech
    Cybersecurity, Network Security, Systems Engineer, Information Security & Data Protection
Job Description & How to Apply Below
Location: Tysons Corner, VA Salary: Depends on Experience Description:

Lead Enterprise SASE Security Engineer (Netskope Focus)

Type: 6+ Month Contract

Location:
Tysons Corner, VA - 5 days a week

Position Summary

We are seeking a Lead Enterprise SASE Security Engineer to serve as the technical owner for the deployment, optimization, and operationalization of our global Secure Access Service Edge (SASE) architecture. This role will lead the organization's transition from traditional network security models to a Zero Trust, cloud-delivered security framework, with Netskope serving as the core Security Service Edge (SSE) platform.

The ideal candidate is a hands-on security engineering expert with deep experience in SASE/SSE technologies, Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and enterprise-scale security transformations.
Key Responsibilities
Zero Trust Architecture and ZTNA Leadership
  • Design, implement, and manage Zero Trust Network Access (ZTNA) policies using identity-centric security principles.
  • Define and enforce ZTNA access policies for specific user groups using technologies such as Netskope Private Access to ensure least-privilege access.
  • Lead the migration from legacy perimeter-based security controls to cloud-native Zero Trust architectures.
  • Develop and implement a tag-oriented unified SASE security policy strategy using user identity, device posture, application context, and other cloud-native attributes.
  • Eliminate reliance on traditional one-to-one firewall rule migrations by consolidating and modernizing policy frameworks.
  • Review and optimize SSL/TLS inspection and decryption policies to minimize security blind spots while maintaining application functionality.
  • Assess legacy SSL exclusion policies and validate business requirements for all exceptions.
  • Lead firewall and web filtering policy cleanup initiatives, removing redundant, outdated, or overly permissive rules.
  • Create and maintain architecture documentation, implementation standards, operational procedures, and technical design documents.
Netskope Deployment and Operations
  • Lead the end-to-end deployment and ongoing operation of the Netskope Security Cloud platform across a global enterprise environment.
  • Implement and support key Netskope capabilities, including:
    • Secure Web Gateway (SWG)
    • Cloud Access Security Broker (CASB)
    • Data Loss Prevention (DLP)
    • Zero Trust Network Access (ZTNA)
    • Remote Browser Isolation (RBI)
  • Integrate Netskope with Identity Providers (IdPs), including Microsoft Entra  (Azure AD) and Ping Identity.
  • Integrate Endpoint Detection and Response (EDR) solutions to enable adaptive, contextual access controls based on device health and risk posture.
  • Provide Tier 3 technical support and serve as the highest escalation point for complex issues involving Netskope clients, traffic steering, policy enforcement, and endpoint connectivity.
  • Troubleshoot and optimize security controls across Windows and macOS environments.
Automation and Continuous Improvement
  • Develop automation solutions to improve security operations, deployment efficiency, policy management, and reporting.
  • Utilize Python or other scripting languages to automate administrative and operational processes.
  • Integrate with security APIs for configuration management, reporting, monitoring, and remediation workflows.
  • Identify opportunities to streamline processes and improve overall security effectiveness.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline, or equivalent professional experience.
  • 5+ years of hands-on experience in cybersecurity or security engineering roles.
  • 3+ years of experience designing, deploying, and supporting enterprise SASE or SSE solutions.
  • Deep hands-on experience with Netskope Security Cloud, including SWG, CASB, ZTNA, and DLP capabilities, or extensive experience with comparable platforms such as:
    • Zscaler (ZIA, ZPA)
    • Palo Alto Prisma Access
  • Strong expertise in Zero Trust security architectures and identity-based access controls.
  • Experience deploying and managing Secure Web Gateway, CASB, DLP, and ZTNA technologies in large…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary