高级Netskope SSE工程师 / 高级SASE工程师
Senior Netskope SSE Engineer / Senior SASE Engineer
开发工程职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Info Resume Edge
薪资未公开
工作地点Brazil
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型Full Time
发布时间今天
数据来源Himalayas
注意地域限制:该职位明确限定在 Brazil 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。
负责组织安全服务边缘(SSE)和安全访问服务边缘(SASE)平台的设计、实施和优化,主要聚焦于 Netskope。工程师推动零信任(Zero Trust)的采用,现代化混合办公团队的安全访问,并与安全、网络和云团队合作,提供统一的安全架构。
职位职责
- 设计并部署 Netskope SSE 解决方案,包括 CASB、SWG、ZTNA、DLP、DSPM、云防火墙和私有访问。
- 领导企业范围内的 SASE 设计工作,整合身份、网络和云安全控制。
- 开发并维护用户、设备和应用的零信任访问模式。
- 设计安全访问路径,支持从传统 VPN 迁移到 ZTNA。
- 优化全球环境中的流量引导、客户端部署和策略路由。
- 构建并调整 DLP、威胁防护和访问控制策略。
- 将 Netskope 与身份提供商(Azure AD、Okta)、SIEM 平台和端点安全工具集成。
- 排查复杂的 SSE/SASE 问题,推动持续性能改进。
- 创建操作运行手册、自动化脚本和监控仪表板。
- 作为 SSE/SASE 的专家,指导初级工程师。
职位要求
- 5–8 年以上安全工程、网络工程或云安全经验。
- 3 年以上使用 Netskope SSE(CASB、SWG、ZTNA、DLP、DSPM、客户端引导、私有访问)的实际经验。
- 对 SASE 架构、零信任原则和以身份为中心的安全有深入理解。
- 熟练掌握身份平台(Azure AD、Okta)、网络协议(DNS、TLS、HTTP/HTTPS、IPsec、GRE)和云平台(AWS、Azure、GCP)。
- 有使用 SIEM 工具(如 Splunk、Sentinel 或 QRadar)的经验。
- 熟悉使用 Python、PowerShell 或 Terraform 进行自动化。
- 良好的沟通能力,能够领导跨职能技术项目。
优先条件
- Netskope 认证(NCSA、NCI、NPA)。
- 有 SD-WAN 技术经验(Netskope、VeloCloud、Fortinet)。
- 有 DLP 项目开发或数据分类背景。
- 了解零信任框架,如 NIST 800-207。
- 有支持大型分布式企业环境的经验。
教育背景
- 本科及以上学历,或相关领域至少 12 年工作经验
最初发布于 喜马拉雅山
查看英文原文
This position leads the design, implementation, and optimization of the organization's Security Service Edge (SSE) and Secure Access Service Edge (SASE) platforms, with a primary focus on Netskope. The engineer drives Zero Trust adoption, modernizes secure access for a hybrid workforce, and partners with security, networking, and cloud teams to deliver a unified security architecture.
Job Responsibilities
- Architect and deploy Netskope SSE solutions including CASB, SWG, ZTNA, DLP, DSPM, Cloud Firewall, and Private Access.
- Lead enterprise-wide SASE design efforts integrating identity, networking, and cloud security controls.
- Develop and maintain Zero Trust access patterns for users, devices, and applications.
- Engineer secure access pathways and support migration from legacy VPN to ZTNA.
- Optimize traffic steering, client deployment, and policy routing across global environments.
- Build and tune DLP, threat protection, and access control policies.
- Integrate Netskope with identity providers (Azure AD, Okta), SIEM platforms, and endpoint security tools.
- Troubleshoot complex SSE/SASE issues and drive continuous performance improvements.
- Create operational runbooks, automation scripts, and monitoring dashboards.
- Serve as the subject‑matter expert for SSE/SASE and mentor junior engineers.
Job requirements
- 5–8+ years in security engineering, network engineering, or cloud security.
- 3+ years hands‑on experience with Netskope SSE (CASB, SWG, ZTNA, DLP, DSPM, Client Steering, Private Access).
- Strong understanding of SASE architectures, Zero Trust principles, and identity‑centric security.
- Proficiency with identity platforms (Azure AD, Okta), network protocols (DNS, TLS, HTTP/HTTPS, IPsec, GRE), and cloud platforms (AWS, Azure, GCP).
- Experience with SIEM tools such as Splunk, Sentinel, or QRadar.
- Familiarity with automation using Python, PowerShell, or Terraform.
- Strong communication skills and the ability to lead cross‑functional technical initiatives.
Preferred Qualifications
- Netskope certifications (NCSA, NCI, NPA).
- Experience with SD‑WAN technologies (Netskope, VeloCloud, & Fortinet).
- Background in DLP program development or data classification.
- Knowledge of Zero Trust frameworks such as NIST 800‑207.
- Experience supporting large, distributed enterprise environments.
Education
- Bachelor's Degree or at least 12 years' experience in related field
Originally posted on Himalayas
本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。
本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。