CybersecurityJobs.io
← Back to all jobs

Job Description

Legato Security is hiring a Network Security Engineer to help administer, implement, troubleshoot, design, and continuously improve customers’ network and security environments. The work spans day-to-day support and project delivery across multiple customers, blending operational ticket handling with implementation, migrations, upgrades, and configuration changes. This role is hybrid/mostly remote in Salt Lake City, UT, with some on-call time and occasional time in office or client visits as needed.

What you will do

  • Support, administer, configure, and troubleshoot firewalls, Zscaler services, Netskope, VPN technologies, and related network security platforms across internal and customer environments.
  • Partner with customers to understand business and technical requirements, troubleshoot issues, evaluate solution options, and implement appropriate changes.
  • Respond to and resolve service tickets, incidents, requests, and escalations related to network connectivity, firewalls, Zscaler, Netskope, and supporting technologies.
  • Act as an escalation point for technical problems requiring deeper troubleshooting, analysis, or specialized expertise beyond initial support.
  • Support firewall and network product environments to meet customer connectivity and security requirements.
  • Participate in firewall and SASE/SSE platform projects, including implementation, migration, upgrade, replacement, and configuration work for firewalls, Zscaler, and Netskope.
  • Assist with configuration and maintenance of Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, and related services.
  • Assist with configuration and maintenance of Netskope One, including SASE, SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN, and more.
  • Support Zscaler and Netskope policies, including URL filtering, firewall policies, SSL inspection, authentication and access policies, application access, routing, DNS, DHCP, NAT, VPNs, SSL/TLS inspection, VLANs, switching technologies, and policy enforcement.
  • Configure and troubleshoot VPN technologies including SSL VPN, IPsec, Remote Access VPN, and Site-to-Site VPN connections.
  • Review logs and diagnostic data such as firewall logs, Zscaler logs, Netskope logs, packet captures, routing tables, and traffic flows to determine root cause.
  • Assist with customer onboarding and changes, including testing and validation of new configurations prior to production deployment.
  • Create and maintain firewall documentation, configuration records, troubleshooting procedures, implementation notes, and customer-specific technical documentation.
  • Participate in incident response, problem management, and root-cause analysis when needed.
  • Manage multiple unresolved tickets, incidents, projects, and customer requests with support from team members or technical resources.
  • Assist other engineers and analysts with troubleshooting processes, technical methodologies, and network security best practices.
  • Identify opportunities to improve network configurations, security controls, operational processes, troubleshooting methods, documentation, and the customer experience.
  • Stay current on emerging networking and cybersecurity technologies, vendor platform changes, vulnerabilities, security capabilities, and industry best practices.

Requirements

  • Hands-on experience with one or more network security technologies such as firewalls, Zscaler, Netskope, VPNs, secure web gateways, SSE/SASE platforms, proxies, or zero-trust technologies.
  • Strong troubleshooting and analytical skills to diagnose network and security issues methodically.
  • Working knowledge of routing concepts and protocols including TCP/IP, BGP, OSPF, EIGRP, IS-IS, RIP, static routing, and SD-WAN.
  • Working knowledge of LAN technologies such as Ethernet switching, VLANs, Spanning Tree Protocol (STP), port security, link/port aggregation, and LAN/WAN architecture.
  • Experience or familiarity with physical, virtual, and cloud firewall technologies.
  • Understanding of firewall concepts including security policies, zones and interfaces, objects/object groups, routing, NAT, VPNs, application and service policies, logging, and traffic analysis.
  • Knowledge or familiarity of VPN technologies including IPsec, SSL VPN, Remote Access VPN, and Site-to-Site VPN.
  • Working knowledge of NAT concepts such as Source NAT, Destination NAT, and U-Turn/Hairpin NAT, plus DNS and DHCP.
  • Familiarity with authentication and identity technologies such as SAML, SSO, MFA, Active Directory, Entra ID, and SCIM.
  • Ability to capture, analyze, and interpret network traffic using Wireshark or similar tools.
  • Ability to interpret network and security logs, packet captures, routing information, and error messages.
  • Design and documentation experience would be helpful.
  • Strong customer-facing skills, including listening, evaluating requirements, asking appropriate questions, and explaining technical issues and solutions.
  • Effective communication with both technical and non-technical audiences.
  • Ability to work in team environments and independently.
  • Ability to handle multiple customers, environments, projects, incidents, and priorities simultaneously.
  • Ability to manage time effectively and work issues through to resolution.
  • Willingness and ability to learn new technologies and build deeper expertise across networking and network security platforms.

Technologies you will work with

  • Firewalls; Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, Zscaler Digital Experience (ZDX), Zscaler Cloud Firewall, Zscaler Data Loss Prevention (DLP), and Zscaler traffic forwarding technologies; Zscaler API integrations and automation
  • Netskope; Netskope One (SASE, SSE, CASB, SWG, Private Access, Cloud Firewall); SD-WAN; SkopeAI
  • VPN technologies including SSL VPN, IPsec, Remote Access VPN, and Site-to-Site VPN connections
  • TCP/IP, BGP, OSPF, EIGRP, IS-IS, RIP, Static Routing
  • Ethernet switching, VLANs, Spanning Tree Protocol (STP), Port security, Link/port aggregation
  • NAT (Source NAT, Destination NAT, U-Turn/Hairpin NAT), DNS, DHCP
  • Authentication and identity: SAML, SSO, MFA, Active Directory, Entra ID, SCIM
  • Wireshark and packet captures; SSL inspection and SSL/TLS inspection

Benefits

  • Start-up company in a growth phase with opportunity for advancement based on performance
  • Start-up culture with an office in downtown Salt Lake City, UT
  • Competitive medical and dental benefits for employee and family members
  • Other company-provided benefits such as short-term disability, basic life insurance, children’s orthodontia, and additional voluntary benefits
  • Flexible Paid Time Off policy
  • Professional Development opportunities specific to role

Preferred qualifications

  • Experience with firewall and network security platforms such as Palo Alto Networks, Cisco ASA/Cisco Secure Firewall, Fortinet FortiGate, Check Point, Juniper SRX, SonicWall, Cisco Meraki, Sophos, WatchGuard, Microsoft Azure network security technologies, or Amazon Web Services network security technologies
  • Experience with Zscaler technologies (including ZIA, ZPA, Client Connector, ZDX, Cloud Firewall, DLP, and Zscaler traffic forwarding and automation)
  • Experience with Netskope technologies including Netskope One SASE/SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN, or SkopeAI
  • Understanding or experience with cloud networking and security technologies within Microsoft Azure, AWS, and GCP
  • Experience with cloud networking concepts such as virtual networks/VPCs, subnets, route tables, security groups, cloud firewalls, VPN gateways, private connectivity, cloud routing, and hybrid network connectivity
  • Familiarity with wireless network security, SNMP monitoring and alerting solutions, network monitoring and performance-management platforms, and network automation
  • Familiarity with packet capture and network troubleshooting tools
  • Familiarity with REST APIs, PowerShell, and/or Python, including infrastructure scripting or automation
  • Relevant networking, security, firewall, cloud, Netskope, or Zscaler certifications are a plus (active and actively maintained certifications are preferred), including examples like Zscaler ZDTA/ZDTE; Netskope NCCSI/NCCSA or Netskope SASE accreditation; Cisco CCNA/CCNP; Palo Alto Networks CSA/CSP; CompTIA Network+/Security+; and other relevant certifications

This position supports a mix of operational and project-based activities across multiple customers and environments. Hybrid work is mostly remote, with potential time in office (downtown Salt Lake City) for troubleshooting, updating, and replacing network equipment, and client visits as required. Some time on-call is required and is rotational, described as not extensive.

Similar Jobs