Principal SASE Engineer

United StatesFull-time$142k–$175kPosted Jul 30, 2026

4 Days in the office from any of our locations in Johnston RI, Dallas TX, Nashville TN, Iselin NJ, Westwood or Medford MA, or Phoenix AZ and couple other locations

Role is not relocation eligible. 

Principal SASE Engineer

Description

At Citizens, we're more than a bank. Here, you'll experience new things, create new opportunities, think beyond your role, and make an impact. While in this role, you'll serve as a senior technical leader responsible for the engineering, administration, and strategic evolution of our Secure Access Service Edge (SASE) platform, with a primary focus on Netskope.

As a Principal SASE Engineer, you will lead the design, implementation, and optimization of cloud-delivered security services that enable secure access for colleagues, applications, and customers. You will partner across Infrastructure, Cybersecurity, Network Engineering, Architecture, and Operations teams to deliver secure, scalable, and resilient access solutions aligned with the organization's Zero Trust strategy.

The ideal candidate will possess deep hands-on expertise with Netskope technologies, strong network and security engineering experience, and a demonstrated ability to lead large-scale enterprise deployments. Experience with Zscaler and Out-of-Band (OOB) Management solutions is highly desirable.

Primary Responsibilities

  • Serve as the primary technical owner and subject matter expert for the enterprise Netskope platform.
  • Design, deploy, and support Netskope services, including Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), Data Loss Prevention (DLP), Cloud Firewall, and related Security Service Edge (SSE) capabilities.
  • Lead the implementation of Zero Trust access solutions and initiatives focused on modernizing traditional remote access technologies.
  • Engineer scalable and secure access solutions supporting hybrid workforce, cloud connectivity, and enterprise applications.
  • Develop and maintain security policies, traffic steering configurations, access controls, and user experience optimization strategies.
  • Provide advanced troubleshooting and Tier III support for complex platform, network, and security incidents.
  • Collaborate with Cybersecurity, Identity & Access Management, Cloud Engineering, and Network teams to ensure secure infrastructure integration.
  • Evaluate emerging technologies and drive continuous improvement initiatives across the SASE and secure access landscape.
  • Develop operational procedures, technical standards, architecture documentation, and knowledge transfer materials.
  • Mentor engineers and provide technical leadership across security and infrastructure teams.
  • Participate in strategic planning, architecture reviews, and vendor evaluations.

 

Qualifications

Required Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or equivalent experience.
  • 8+ years of experience in Network Engineering, Security Engineering, Infrastructure Engineering, or related disciplines.
  • 5+ years of hands-on experience with SASE, SSE, Zero Trust, or cloud-delivered security platforms.
  • Extensive hands-on experience administering and engineering Netskope solutions within a large enterprise environment.
  • Strong understanding of: 
    • Secure Web Gateway (SWG)
    • Cloud Access Security Broker (CASB)
    • Zero Trust Network Access (ZTNA)
    • Data Loss Prevention (DLP)
    • Secure Service Edge (SSE)
    • Network Security and TCP/IP
    • DNS, Routing, Proxy Technologies, and TLS Inspection
  • Experience integrating identity providers such as Microsoft Entra ID, Okta, Ping Identity, or equivalent platforms.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent communication skills with the ability to influence technical and non-technical stakeholders.

 

Preferred Qualifications

  • Experience with Netskope Private Access (NPA), Publisher, Borderless SD-WAN, and advanced policy management.
  • Experience with Zscaler Internet Access (ZIA) and/or Zscaler Private Access (ZPA).
  • Experience supporting large-scale endpoint deployments and enterprise remote access transformations.
  • Experience with AWS, Azure, or multi-cloud networking and security architectures.
  • Experience with automation and scripting using PowerShell, Python, REST APIs, or Infrastructure as Code methodologies.
  • Experience with Splunk, SIEM platforms, and security monitoring technologies.

 

Bonus Qualifications

  • Experience designing, deploying, or supporting Out-of-Band Management solutions.
  • Familiarity with Opengear, Lantronix or ZPE,  console servers, LTE failover technologies, and remote infrastructure recovery capabilities.
  • Experience supporting datacenter modernization, resiliency, and disaster recovery initiatives.

 

Hours & Work Schedule

  • Hours per Week: 40
  • Work Schedule: Monday – Friday
  • Hybrid work model based on business needs.

 

Pay Transparency 

 

‌The salary range for this position is $142,000 – $175,000 per year, plus an opportunity to earn additional incentive earnings (if applicable). Actual pay is based on various factors including, but not limited to, the budget, work location, and relevant skills and experience..

 

We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens’ paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits

 

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free