Job Description
1. Role Summary
We are looking for a senior network and security engineer to act as the single technical owner for the SASE/ZTNA/Enterprise Security engagements. The role owns solution architecture, implementation oversight, and the client-facing technical relationship across a portfolio of engagements .The role also requires the flexibility to own engagements on other SASE/SSE OEM platforms beyond Cisco (e.g., Zscaler, Palo Alto Networks Prisma Access, Fortinet FortiSASE, Netskope, Check Point Harmony SASE), coordinating with each OEM's own support channel as appropriate.
2. Key Responsibilities
Architecture & Design
- Own SASE/SSE solution architecture across assigned accounts global PoP-to-user routing, data center egress, local internet breakout, and secure private access (ZTNA).
- Author or sign off on High-Level and Low-Level Design (HLD/LLD) documents and configuration diagrams.
- Own RFP compliance matrix responses and technical use case write-ups across supported OEM platforms.
Implementation & Delivery
- Lead discovery workshops to capture use cases, applications, identity sources, network topology, and access policies.
- Deploy and configure SWG, ZTNA, CASB, DLP, FWaaS, and DNS-layer security during POC and production rollout.
- Integrate identity providers (Active Directory, Microsoft Entra ID) and configure SSO / conditional access.
- Configure connectivity — BGP, IPSec tunnels, SD-WAN integration, DNS forwarding, VPN profiles — in coordination with customer network teams.
- Execute production rollout for large user bases (10,000+ users) in a phased, wave-based manner.
- Deliver documentation and formal knowledge transfer to customer operations teams.
Ongoing Operations & Support
- Own policy governance, RBAC administration, and change management oversight across accounts (execution may be logged directly or delegated, but ownership sits here).
- Log and manage Cisco TAC cases for day-to-day P1/P2 issues; validate TAC's diagnosis, drive resolution, and personally step in only for issues TAC cannot resolve or that require architecture/policy changes.
- Oversee SIEM/log forwarding (e.g., Microsoft Sentinel) and security operations monitoring across accounts.
- Use REST APIs, Terraform, PowerShell, or Python for automation and policy-as-code where applicable.
- Own SLA reporting, quarterly business reviews, and act as the named technical point of contact for each assigned account.
Multi-OEM & Multi-Account Management
- Act as named technical owner across multiple concurrent Konverge engagements, prioritizing time and attention across accounts.
- Maintain working proficiency across at least one SASE/SSE OEM platform beyond Cisco (e.g., Zscaler, Palo Alto Prisma Access, Fortinet FortiSASE, Netskope, Cato Networks, Versa), and coordinate with the respective OEM's support/TAC channel on those accounts.
- Evaluate and compare OEM capabilities during presales/architecture phases for new or non-Cisco engagements.
- Manage OEM escalations, bug/defect reporting, and roadmap alignment across vendors as needed.
- Stay current on OEM product roadmaps, licensing models, and certification requirements across the practice's supported vendor list.
3. Required Skills & Technical Expertise
- SASE/SSE components: Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), CASB, DNS Security, Firewall-as-a-Service (FWaaS), Remote Browser Isolation.
- Next-Generation Firewall (NGFW) fundamentals: App-ID/policy enforcement, IPS, SSL/TLS decryption — SASE is largely cloud-delivered NGFW, and this underpins the FWaaS and hybrid private-access (local firewall enforcement) components.
- Cisco Identity Services Engine (ISE): posture assessment, RADIUS/TACACS+, network access control (NAC), integration with VPNaaS/ZTNA authentication flows.
- Identity & Access: Active Directory, Microsoft Entra ID (Azure AD), SAML/SSO, device posture validation, conditional access.
- Networking: BGP, IPSec VPN, SD-WAN (e.g., Cisco Catalyst SD-WAN), DNS architecture, multi-carrier ISP resilience.
- Data protection: DLP policy design (EDM/IDM/OCR), CASB tenant restrictions, GenAI/shadow-AI usage controls.
- Automation: REST APIs, Terraform, PowerShell, Python SDKs for policy and configuration automation.
- Security operations: SIEM integration (Microsoft Sentinel or equivalent), log analysis, incident triage and response.
- Working exposure to at least one alternative SASE OEM platform in addition to Cisco Secure Access.
- Strong documentation skills — HLD/LLD authoring, compliance matrices, runbooks.
Preferred / nice-to-have
- Exposure to on-premises NGFW/scale-out platforms from other OEMs — e.g., Check Point (including Maestro hyperscale orchestration), Palo Alto Networks NGFW, or Fortinet FortiGate — as evidence of broader multi-vendor firewall depth beyond cloud SASE.
4. Certifications
Required (at least one)
- CCNP Security, or Cisco Secure Access / SSE Specialist certification.
Strongly preferred
- Cisco ISE / SISE (Implementing and Configuring Cisco Identity Services Engine) or equivalent hands-on NAC experience.
Preferred (multi-OEM breadth — one or more)
- Zscaler ZCCA-IA / ZCCP
- Palo Alto Networks PCNSE or PCSAE (Prisma Access)
- Fortinet NSE 4 or higher (FortiSASE)
- Netskope NCCP
- Check Point Certified Security Administrator/Expert (CCSA/CCSE), with exposure to Maestro orchestration a plus
Other useful certifications
- Microsoft SC-200 (Security Operations Analyst) or SC-300 (Identity and Access Administrator)
- ITIL Foundation
5. Experience & Qualifications
- 8–12 years of overall experience in network and security engineering, including at least 3 years of hands-on experience on SASE, SSE, or ZTNA platforms.
- Hands-on experience with NGFW policy administration and Cisco ISE (or equivalent NAC platform) in a production environment.
- Prior experience owning enterprise rollouts (5,000+ users) and managing an ongoing platform relationship through an OEM TAC/support channel (i.e., as the escalation owner rather than the front-line fixer).
- Experience managing multiple concurrent client engagements or accounts as a named technical owner is strongly preferred.
- Exposure to at least one SASE/SSE OEM platform beyond Cisco is preferred, given the multi-account, multi-OEM scope of this role.
- Bachelor's degree in Computer Science, Information Technology, Electronics, or a related field; equivalent practical experience will be considered.
6. Soft Skills & Attributes
- Comfortable as the named technical point of contact across multiple client accounts simultaneously, including escalation and quarterly review settings.
- Strong prioritization and time management across a portfolio of accounts with competing demands.
- Strong stakeholder management — able to lead discovery workshops and communicate technical trade-offs to non-technical audiences.
- Willingness to build and maintain skills across multiple OEM platforms rather than specializing in a single vendor.
- Mentoring ability, for guiding junior/delivery engineers as the practice scales.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.