Senior Engineer, Network Security

TDToronto, ON
CA$96,900 - CA$136,800Onsite

About The Position

The Senior Engineer, Network Security role is responsible for the engineering and design of TD's cloud SaaS Secure Web Gateway (SWG) and Secure Access Service Edge (SASE) infrastructure. The successful candidate will be highly versed in managing large scale enterprise deployments of Data Loss Prevention (DLP), Borderless WAN VPN functions and related network security experience for cohesive network access security. This is a hands-on senior engineering role with platform level accountability across the Netskope stack. This position sits at the intersection of network security, data protection, and enterprise connectivity in a heavily regulated GSiB financial services environment. Meaningful work is fueled by meaningful performance and career development conversations with your manager.

Requirements

  • Bachelors degree in Computer Science or related degree type. Equivalent experience considered.
  • 7+ years relevant experience in network security technologies – hands on in production deployments, operations, and build teams.
  • Deep understanding of Netskope steering architecture, real-time policy enforcement, the NewEdge network, and data plane/tunnel design.
  • Operational maturity in incident response workflow design, triage, and policy tuning.
  • Strong foundation of Layer 2/Layer 3 network frameworks.
  • Excellent understanding of TCP/IP networking and OSPF, BGP routing protocols. QoS configuration on routers and switches in enterprise environments.
  • Knowledge in WAN/LAN network architecture and operations in the enterprise (Firewalls, Routers, Switches) as it relates to SaaS interoperability.
  • Demonstrated skills in physical network tasks and advanced troubleshooting.
  • Interest in enhancing expertise, staying current with emerging industry trends, new technologies and best practices to help deliver effective solutions.
  • Previous experience working independently and autonomously as a lead on diverse, highly-complex and multi-faceted assignments and can be an inspiring and reliable coach and educator for small teams.
  • Strength as a key resource in technical knowledge transfer between project teams, the business and/or outside vendors.
  • Must be eligible for employment under regulatory standards applicable to the position.

Nice To Haves

  • Previous experience operating in a financial services role – supporting branch, campus, datacenter, and colocation topologies in support.
  • Relevant Netskope experience and/or certifications (i.e NCCSA/NCCSP) or equivalent.
  • Broader SASE/SSE ecosystem exposure and comparative understanding of adjacent vendors (Zscaler, Palo Alto Prisma Access).
  • Experience with SIEM workflows as it relates to security automation, infrastructure as code approaches to policy and configuration management.
  • Prior experience migrating from legacy proxy or on-premise web security architectures to cloud delivered SASE models.
  • Desire to pursue network automation and support infrastructure as code (IaC) efforts utilizing Ansible, Terraform, Python.
  • Proficiency in at least one scripting language such as Python or shell scripting.
  • Proficiency with network automation using orchestration platforms, scripting and REST APIs.
  • Outstanding communication skills are a must. Demonstrated ability to communicate effectively at a variety of levels and to communicate intricate technical and procedural matters to both technical and non-technical team members.
  • Network implementation using SDN technologies and frameworks.
  • Technical certification in technology of expertise (i.e CCNA, CCNP, CCIE, or related).

Responsibilities

  • Provide engineering and delivery support for Netskope SSE products across CASB, SWG, ZTNA, DLP, Private Access, and BWAN technologies.
  • Architect and deliver traffic steering & traffic engineering solutions at scale across IPsec, GRE tunnel termination, as well as implementing effective failover strategies utilizing SDWAN endpoints and transit connectivity.
  • Assist in coordinated maintenance, platform optimization, and line of business specific tuning for performant traffic routing.
  • Understanding a multi-WAN carrier topology – consisting of MPLS, Direct Internet Access DIA) and private MAN connectivity configurations as transit for steering.
  • Proficient in SDWAN topologies (Cisco Catalyst SDWAN/Viptela, Aruba EdgeConnect, Silverpeak) used as terminating agents/steering control points for branch site traffic origination.
  • Partner and collaborate on design and functionality of security platforms with Global Security Defence (GSD) across Identity & Access Management and DLP design considerations to serve the enterprise.
  • Design and implement traffic steering using private line services (dark fiber, carrier interconnects, point to point circuits) using BGP.
  • Provide escalation support to Network Operations organization for advanced troubleshooting of traffic routing, policy, user or system access issues in applications & systems.

Benefits

  • health and well-being benefits
  • savings and retirement programs
  • paid time off
  • banking benefits and discounts
  • career development
  • reward and recognition programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service