Principal SASE Engineer

Citizens Financial GroupJohnston, RI
Hybrid

About The Position

At Citizens, you'll serve as a senior technical leader responsible for the engineering, administration, and strategic evolution of our Secure Access Service Edge (SASE) platform, with a primary focus on Netskope. As a Principal SASE Engineer, you will lead the design, implementation, and optimization of cloud-delivered security services that enable secure access for colleagues, applications, and customers. You will partner across Infrastructure, Cybersecurity, Network Engineering, Architecture, and Operations teams to deliver secure, scalable, and resilient access solutions aligned with the organization's Zero Trust strategy. The ideal candidate will possess deep hands-on expertise with Netskope technologies, strong network and security engineering experience, and a demonstrated ability to lead large-scale enterprise deployments. Experience with Zscaler and Out-of-Band (OOB) Management solutions is highly desirable.

Requirements

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or equivalent experience.
  • 8+ years of experience in Network Engineering, Security Engineering, Infrastructure Engineering, or related disciplines.
  • 5+ years of hands-on experience with SASE, SSE, Zero Trust, or cloud-delivered security platforms.
  • Extensive hands-on experience administering and engineering Netskope solutions within a large enterprise environment.
  • Strong understanding of: Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), Data Loss Prevention (DLP), Secure Service Edge (SSE), Network Security and TCP/IP, DNS, Routing, Proxy Technologies, and TLS Inspection.
  • Experience integrating identity providers such as Microsoft Entra ID, Okta, Ping Identity, or equivalent platforms.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent communication skills with the ability to influence technical and non-technical stakeholders.

Nice To Haves

  • Experience with Netskope Private Access (NPA), Publisher, Borderless SD-WAN, and advanced policy management.
  • Experience with Zscaler Internet Access (ZIA) and/or Zscaler Private Access (ZPA).
  • Experience supporting large-scale endpoint deployments and enterprise remote access transformations.
  • Experience with AWS, Azure, or multi-cloud networking and security architectures.
  • Experience with automation and scripting using PowerShell, Python, REST APIs, or Infrastructure as Code methodologies.
  • Experience with Splunk, SIEM platforms, and security monitoring technologies.
  • Experience designing, deploying, or supporting Out-of-Band Management solutions.
  • Familiarity with Opengear, Lantronix or ZPE, console servers, LTE failover technologies, and remote infrastructure recovery capabilities.
  • Experience supporting datacenter modernization, resiliency, and disaster recovery initiatives.

Responsibilities

  • Serve as the primary technical owner and subject matter expert for the enterprise Netskope platform.
  • Design, deploy, and support Netskope services, including Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), Data Loss Prevention (DLP), Cloud Firewall, and related Security Service Edge (SSE) capabilities.
  • Lead the implementation of Zero Trust access solutions and initiatives focused on modernizing traditional remote access technologies.
  • Engineer scalable and secure access solutions supporting hybrid workforce, cloud connectivity, and enterprise applications.
  • Develop and maintain security policies, traffic steering configurations, access controls, and user experience optimization strategies.
  • Provide advanced troubleshooting and Tier III support for complex platform, network, and security incidents.
  • Collaborate with Cybersecurity, Identity & Access Management, Cloud Engineering, and Network teams to ensure secure infrastructure integration.
  • Evaluate emerging technologies and drive continuous improvement initiatives across the SASE and secure access landscape.
  • Develop operational procedures, technical standards, architecture documentation, and knowledge transfer materials.
  • Mentor engineers and provide technical leadership across security and infrastructure teams.
  • Participate in strategic planning, architecture reviews, and vendor evaluations.

Benefits

  • competitive pay
  • comprehensive medical, dental and vision coverage
  • retirement benefits
  • maternity/paternity leave
  • flexible work arrangements
  • education reimbursement
  • wellness programs
  • paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service