SASE Operations and Support Engineer

TekSynapAlexandria, VA
$81,000 - $110,000Remote

About The Position

We are seeking a SASE Operations and Support Engineer to join our team. The SASE Operations & Support Engineer is responsible for supporting daily operations, troubleshooting activities, documentation updates, coordination with internal and external technical teams, and executing enterprise processes related to SASE, Zero Trust, remote access, and cloud security services. This role ensures consistent operational performance, accurate reporting, and smooth deployment of SASE-related technologies across the environment.

Requirements

  • Active Public Trust or ability to obtain
  • Experience with SASE platforms (e.g., Netskope), ZTNA, SWG, NPA, and cloud security principles.
  • Knowledge of enterprise ticketing, CHG processes, and operational workflows.
  • Ability to collect logs, perform basic troubleshooting, and engage with TAC support.
  • Familiarity with identity platforms such as Active Directory, Okta, SCIM provisioning, and conditional access.
  • Understanding of cloud environments (AWS/Azure) and application publishing concepts.
  • Strong communication skills with ability to coordinate across engineering, NOS, CyberOps, and packaging teams.
  • Ability to produce clear documentation, update KBAs/SOPs, and maintain technical diagrams.

Nice To Haves

  • Exposure to MECM packaging workflows.
  • Understanding of network flow diagramming and architecture documentation.
  • Experience with enterprise security dashboards, incident review, and alert tuning.

Responsibilities

  • Maintain and update Rally/Agile user stories and task boards; ensure team task accuracy and assist members with updates.
  • Monitor remote-access mailbox and triage incoming issues from NOS, Service Desk, and WebFilter teams.
  • Assign or escalate requests to NOS or SASE team members as appropriate.
  • Create and track CHGs, DARTID entries, and ITAs for deployments and operational updates.
  • Follow up on open tasks, CHGs, SMP tickets, and ensure accurate documentation in Rally.
  • Collect and provide GFE client logs, Publisher logs, and PCAPs for investigations.
  • Assist NOS in end-to-end application troubleshooting and support TAC case creation and follow-ups.
  • Run and schedule reports using preconfigured templates for NOS and OCIO requests.
  • Support monthly/quarterly updates for on-premises Publisher connectors and validate internal applications post-update.
  • Monitor UBEA dashboards and escalate abnormal behavior for CyberOps investigation.
  • Review Malware, Malicious Sites, DLP, and credential compromise alerts in Netskope and coordinate with CyberOps.
  • Execute detailed testing scenarios involving SWG, NPA, BWAN, conditional 2FA policies, Okta/SCIM provisioning, GFE access, pre-logon behavior, AVD client, and Generative AI access controls.
  • Validate application behavior across on-premises and off-premises environments.
  • Document test results and provide summary pages for NOS/APR migration assessments.
  • Update SOPs, KBAs, and troubleshooting guides based on team inputs; remove outdated or legacy references (e.g., AnyConnect).
  • Create new KBAs for SDWAN, Private Access, auto-scaling Publisher deployment (AWS/Azure), and Cloud Exchange/WebTx flows.
  • Support the creation and maintenance of SASE network flow diagrams, architecture diagrams, IP assignments, Azure Publisher connectivity, and end-to-end flow documentation.
  • Create Netskope packaging for SCT and enterprise deployment; work with DSSD for MECM packaging and push Phase 0 testing.
  • Coordinate enterprise deployment schedules, create supporting CHGs, DARTIDs, and update deployment reports.
  • Participate in weekly deployment status meetings with prepared updates.
  • Assist in testing and validating migration paths from ADImport to SCIM/Okta provisioning workflows.
  • Document caveats found during testing and coordinate with Netskope for resolution.
  • Maintain documentation of API service account tokens and RBACv3 tokens, including expiration tracking.
  • Coordinate token rotation every 90 days and remove expired or unused tokens.

Benefits

  • health
  • dental
  • vision
  • 401K
  • life insurance
  • short-term and long-term disability plans
  • vacation time
  • holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service