Logo for NES Associates, LLC

Zero Trust Network Engineer

Roles & Responsibilities

  • 5+ years of network engineering / VPN engineering experience
  • 2+ years hands-on experience with SASE, ZTNA, and cloud platforms (Azure preferred)
  • Automation and scripting in Python, PowerShell, and Bash
  • Hands-on experience with Netskope, Zscaler, and Palo Alto Prisma Access

Requirements:

  • Deploy and manage SASE/SSE technologies (SWG, CASB, FWaaS, SD-WAN, ZTNA) and support migration to Zero Trust identity-centric access models
  • Automate security workflows and build API integrations for cloud-native platforms (including Netskope)
  • Troubleshoot complex networking and security issues (routing, proxies, SSL inspection, PAC files, VLANs, NAT, DNS, 802.1X) and perform protocol analysis
  • Monitor and maintain infrastructure with SNMP, SIEM, Grafana, and manage cloud firewall policies across AWS, Azure, and GCP; support SD-WAN/SASE for secure traffic steering

Job description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

None

Clearance Level Must Be Able to Obtain:

None

Public Trust/Other Required:

NACI (T1)

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Microsoft Azure, Microsoft PowerShell, Zero Trust

Certifications:

None

Experience:

5 + years of related experience

US Citizenship Required:

No

Job Description:

ZERO TRUST NETWORK ENGINEER

Job Description

Zero Trust Network Engineer — SASE / ZTNA / SD WAN / Cloud Security

We are hiring a Zero Network Security Engineer with strong experience in SASE, ZTNA, SD WAN, cloud security, network automation, and advanced troubleshooting. This role supports the modernization of our secure access infrastructure using cloud native SASE architecture leveraging Zero Trust Network Access.Success in this role hinges on effectively applying cloud native SASE architecture to seamlessly integrate Zero Trust, SD WAN, and automated security controls into a modern, resilient access infrastructure.

Key Responsibilities (Keyword Focused)

• Deploy and manage SASE/SSE technologies: SWG, CASB, FWaaS, SD WAN, ZTNA• Support migration to Zero Trust and identity centric access models• Automate security workflows using Python, PowerShell, Bash• Develop and maintain API integrations for cloud native platforms, including Netskope• Troubleshoot complex issues involving routing, proxies, PAC files, SSL inspection, VLANs, NAT, DNS, 802.1X, SaaS/COTS apps• Perform protocol analysis using Wireshark and tcpdump• Monitor and maintain infrastructure using SNMP, SIEM, Grafana, syslog• Maintain cloud firewall policies across AWS, Azure, GCP• Support SD WAN and SASE integration for secure traffic steering

Required Skills & Experience:

• 2+ years hands on with SASE, ZTNA, cloud platforms• 5+ years Network Engineering / VPN Engineering• Strong understanding of SD WAN, SSE/SASE architecture, Windows 10/11 networking• Hands on with Netskope, Zscaler, Palo Alto Prisma Access • Expertise in routing protocols, proxy architecture, PAC files• Experience with AnyConnect, firewalls, 802.1X• Automation and scripting in Python, PowerShell, Bash• Familiarity with SNMP, SIEM, Grafana, Docker troubleshooting.

Preferred Qualifications:

• Certifications: Netskope Cloud Security Specialist (NCSS) and/or Zscaler Certified Administrator (ZCSA – ZIA or ZPA track), CCNP Security• Experience with DevOps, CI/CD, hybrid cloud security (AWS/Azure/GCP)

The likely salary range for this position is $123,250 - $166,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

None

Telecommuting Options:

Remote

Work Location:

USA IL Home Office (ILHOME)

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Related jobs

Other jobs at NES Associates, LLC

We help you get seen. Not ignored.

We help you get seen faster — by the right people.

🚀

Auto-Apply

We apply for you — automatically and instantly.

Save time, skip forms, and stay on top of every opportunity. Because you can't get seen if you're not in the race.

AI Match Feedback

Know your real match before you apply.

Get a detailed AI assessment of your profile against each job posting. Because getting seen starts with passing the filters.

Upgrade to Premium. Apply smarter and get noticed.

Upgrade to Premium

Join thousands of professionals who got noticed and hired faster.