Network Security Engineer

Legato Security

Salt Lake City (UT)

Hybrid

USD 110,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical and dental benefits
Office in downtown Salt Lake City
Professional development

Job summary

Legato Security is seeking a Network Security Engineer to join our Network team. You will support, design, and improve customer networks and security environments, focusing on firewalls, Zscaler, Netskope, and VPN technologies.

This hybrid role requires strong troubleshooting, clear communication, and the ability to handle multiple customers and projects. The ideal candidate has hands-on experience with security platforms, solid networking foundations, and a proactive approach to learning.

Qualifications

  • Hands-on experience with network security technologies such as firewalls, Zscaler, Netskope, VPNs, SSE/SASE.
  • Strong troubleshooting and analytical skills with the ability to diagnose network and security issues.
  • Knowledge of routing concepts and protocols (TCP/IP, BGP, OSPF, EIGRP, IS‑IS, RIP, SD‑WAN).
  • LAN technologies including Ethernet switching, VLANs, STP, Port security, and WAN architecture.
  • Experience with physical, virtual, and cloud firewall technologies.
  • Ability to communicate clearly with technical and non-technical audiences.
  • Ability to manage multiple tickets, incidents, and priorities simultaneously.
  • Willingness to learn new technologies and deepen expertise across networking/security platforms.

Responsibilities

  • Support, administer, configure, and troubleshoot firewalls, Zscaler, Netskope, VPNs, and related security platforms.
  • Collaborate with customers to understand requirements, troubleshoot problems, evaluate solutions, and implement changes.
  • Respond to and resolve service tickets, incidents, requests, and escalations involving network connectivity and security tooling.
  • Escalate complex issues and provide troubleshooting guidance beyond initial support.
  • Configure and maintain firewall and network environments to meet customer connectivity and security needs.
  • Participate in implementation, migration, upgrade, replacement, and configuration projects.
  • Assist with ZIA, ZPA, ZCC, Netskope One platform configuration including SSE, CASB, SWG, Private Access, SD‑WAN.
  • Support policy enforcement, including URL filtering, SSL inspection, VPNs, NAT, DNS, DHCP, and VLANs.

Skills

Network security
Troubleshooting
Routing concepts
LAN/WAN
Customer facing
Communication
Team collaboration
Time management

Tools

Firewalls
Zscaler
Netskope
VPNs
SSE/SASE
ZIA
ZPA

Job description

Remote Office; Salt Lake City, Utah, United States

Who We Are

Legato Security is an information security firm founded upon the belief that every organization has the right to keep its data private and secure. Our mission is to build close partnerships with our clients, serving them not as just a vendor, but as trusted advisors helping to build effective, proactive plans. Our focus is always on both the technical and human elements within an organization. We believe in comprehensive strategies designed to harden networks, deflect attackers, and rapidly recover from any accidents. As technology progresses, so do our tactics, ensuring our experts are always prepared to serve forward-looking leaders eager to stay ahead of emerging threats.

Position Overview

We are seeking a Network Security Engineer to join our Network team. This role will support the administration, implementation, troubleshooting, design, and ongoing improvement of our customers networks and security environments.

The ideal candidate will have hands‑on experience with network security technologies such as firewalls, Zscaler, Netskope, VPNs, routing, switching, or related technologies. Extensive experience with every platform is not required, but a strong networking foundation, practical troubleshooting ability, good communication skills, and a willingness to continually learn are essential.

This position will work across a variety of operational and project-based activities, including customer requests, incidents, service tickets, troubleshooting, implementations, migrations, upgrades and changes, and technical projects. Because the role supports multiple customers and environments, the successful candidate must be able to communicate effectively, manage competing priorities, adapt to different technical requirements, and see issues through to resolution.

This position is hybrid and mostly remote in nature, but may require some time in office (Downtown Salt Lake City) for troubleshooting, updating, and replacing network equipment; client visits as required, etc. Some time on‑call is required, but this will rotational and not extensive.

Specific Job Responsibilities
  • Support, administer, configure, and troubleshoot firewalls, Zscaler services, Netskope, VPN technologies, and related network security platforms, both internal and in customer environments
  • Work directly with customers to understand business and technical requirements, troubleshoot problems, evaluate potential solutions, and implement appropriate changes
  • Respond to and resolve service tickets, incidents, requests, and escalations involving network connectivity, firewalls, Zscaler, Netskope, and related technology
  • Serve as an escalation point for technical issues that require additional troubleshooting, analysis, or expertise beyond initial support
  • Support, configure, and troubleshoot firewall and network product environments to meet customer connectivity and security requirements
  • Participate in firewall, Zscaler, and Netskope implementation, migration, upgrade, replacement, and configuration projects.
  • Assist with the configuration and maintenance of Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, and related services
  • Assist with the configuration and maintenance of the Netskope One platform including SASE, SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN, and more
  • Support Zscaler and Netskope policies including URL filtering, firewall policies, SSL inspection, authentication, access policies, application access, traffic forwarding, connectivity, routing, DNS, DHCP, NAT, VPNs, authentication, traffic forwarding, SSL/TLS inspection, application access, VLANs, switching technologies, and policy enforcement
  • Configure and troubleshoot VPN technologies including SSL VPN, IPsec, Remote Access VPN, and Site-to-Site VPN connections
  • Review firewall logs, Zscaler logs, Netskope logs, packet captures, routing tables, traffic flows, error messages, and other diagnostic information to determine root cause
  • Assist with customer onboarding and changes to existing customer network and security environments, testing and validation of new configurations, and other changes prior to production deployment
  • Create and maintain firewall documentation, configuration records, troubleshooting procedures, implementation notes, and customer-specific technical documentation.
  • Participate in incident response, problem management, and root‑cause analysis activities as needed
  • Have the ability to manage multiple unresolved tickets, incidents, projects, and customer requests with assistance from other team members or technical resources as needed, both individually and in collaboration with team members
  • Assist engineers and analysts and with troubleshooting processes, technical methodologies, and network security best practices
  • Identify opportunities to improve network configurations, security controls, operational processes, troubleshooting methods, documentation, and customer experience
  • Maintain awareness of emerging networking and cybersecurity technologies, vendor platform changes, vulnerabilities, security capabilities, and industry best practices
Qualifications
Required Qualifications
  • Hands‑on experience with one or more network security technologies such as firewalls, Zscaler, Netskope, VPNs, secure web gateways, SSE/SASE platforms, proxies, or zero‑trust technologies
  • Strong troubleshooting and analytical skills with the ability to methodically diagnose network and security issues
  • Working knowledge of routing concepts and protocols such as TCP/IP, BGP, OSPF, EIGRP, IS‑IS, RIP, Static Routing, and SD‑WAN
  • Working knowledge of LAN technologies including Ethernet switching, VLANs, Spanning Tree Protocol (STP), Port security, Link/port aggregation, and LAN and WAN architecture
  • Experience or familiarity with physical, virtual, and cloud firewall technologies
  • Understanding of firewall concepts including Security policies, zones and interfaces, objects and object groups, routing, NAT, VPNs, Application and Service policies, Logging, and traffic analysis
  • Knowledge or familiarity of VPN technologies including IPsec, SSL VPN, Remote Access VPN, and Site‑to‑Site VPN
  • Working knowledge of concepts including NAT (Source NAT, Destination NAT, and U‑Turn/Hairpin NAT), DNS, and DHCP
  • Familiarity with authentication and identity technologies such as SAML, SSO, MFA, Active Directory, Entra ID, and SCIM
  • Ability to capture, analyze, and interpret network traffic using Wireshark or similar packet‑analysis tools
  • Ability to interpret network and security logs, packet captures, routing information, error messages, and other diagnostic information
  • Ability to design and document network and related security solutions would be helpful
  • Strong customer‑facing skills, including the ability to listen, evaluate requirements, ask appropriate questions, and clearly explain technical issues and solutions
  • Ability to communicate effectively with both technical and non‑technical audiences
  • The ability to work both within a team environment and individual situations are required
  • Ability to work with multiple customers, environments, projects, incidents, and priorities simultaneously
  • Ability to manage time effectively and see incidents, requests, and technical issues through to resolution
  • Willingness and ability to learn new technologies and develop deeper expertise across networking and network security platforms
Preferred Qualifications

Experience with one or more of the following technologies or disciplines is beneficial but not required:

Firewall and Network Security Platforms
  • Fortinet FortiGate
  • Check Point
  • SonicWall
  • Sophos
  • WatchGuard
  • Microsoft Azure network security technologies
  • Amazon Web Services network security technologies
  • Zscaler Internet Access (ZIA)
  • Zscaler Private Access (ZPA)
  • Zscaler Digital Experience (ZDX)
  • Zscaler Cloud Firewall
  • Zscaler traffic forwarding technologies
  • Zscaler API integrations and automation
Netskope Technologies
  • Netskope One SASE
  • Netskope One SSE
  • Cloud Access Security Broker (CASB)
  • Next Generation Secure Web Gateway (SWG)
  • Private Access
  • SD‑WAN
  • SkopeAI

Understanding or experience with cloud networking and security technologies within Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP) would be helpful.

Experience with cloud technologies such as Virtual networks/VPCs, subnets, route tables, security groups, cloud firewalls, VPN gateways, private connectivity, cloud routing, hybrid network connectivity

Additional Technologies

Familiarity or experience with the following would be beneficial:

  • Wireless network security, protocols, troubleshooting, and design
  • SNMP monitoring and alerting solutions
  • Network monitoring and performance‑management platforms
  • Packet capture and network troubleshooting tools
  • REST APIs, PowerShell, and/or Python
  • Infrastructure scripting or automation
Certifications

Relevant networking, security, firewall, cloud, Netskope, or Zscaler certifications are considered a plus but are not required. However, preference will be given towards active and actively maintained certification along the lines of Zscaler and firewalls vendors.

Examples may include:

  • Zscaler Digital Transformation Administrator (ZDTA) or Zscaler Digital Transformation Engineer (ZDTE)
  • Netskope Certified Cloud Security Integrator (NCCSI - NSK200), Netskope Certified Cloud Security Architect (NCCSA - NSK300), or Netskope SASE Accredidation
  • Cisco CCNA or CCNP
  • Palo Alto Networks CSA or CSP
  • CompTIA Network+ or Security+
  • Other relevant networking or cybersecurity certifications

Start-up company in a growth phase with opportunity for advancement based on performance

Start-up culture with an office in downtown Salt Lake City, UT

Competitive medical and dental benefits for employee and family members

Other company-provided benefits such as short-term disability, basic life insurance, children's orthodontia, with additional voluntary benefits available

Professional Development opportunities specific to role

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Perimeter Security Engineer
Senior Network Perimeter Security Engineer

Insight Global • Sugar Land (TX)

On-site
USD 140,000 - 190,000
Remote Network Security Engineer (Zscaler & Netskope)
Remote Network Security Engineer (Zscaler & Netskope)

Legato Security • Salt Lake City (UT)

Hybrid
USD 110,000 - 150,000
Medical and dental benefits
Office in downtown Salt Lake City
Professional development
Principal Technical Marketing Engineer
Principal Technical Marketing Engineer

Zscaler, Inc. • San Jose (CA)

Hybrid
USD 172,000 - 245,000
Senior Network Engineer
Senior Network Engineer

Red Cat Holdings • Salt Lake City (UT)

On-site
USD 120,000 - 160,000
Network Security Engineer (Zscaler)
Network Security Engineer (Zscaler)

Uvcyber • Arlington (VA)

On-site
USD 140,000 - 165,000
401(k) employer match
Medical, Dental, and Vision Insurance
Discretionary Time Off (DTO)
Senior Manager, Zscaler
Senior Manager, Zscaler

Vanguard • Wayne (PA)

On-site
USD 100,000 - 130,000
Senior Manager, Zscaler
Senior Manager, Zscaler

Vanguard • Scottsdale (AZ)

On-site
USD 140,000 - 190,000
Senior Network Security Engineer
Senior Network Security Engineer

xAI • Washington

On-site
USD 140,000 - 170,000
Health insurance
Life and AD&D insurance
Fertility benefits
+3
Senior Specialist Network Security
Senior Specialist Network Security

Linde • Houston (TX)

On-site
USD 120,000 - 180,000
ZScaler SME Network Engineer
ZScaler SME Network Engineer

Agile Defense • Ashburn (VA), Northern (KY)

Hybrid
USD 170,000 - 185,000