Senior Network Engineer

Fitch Group•New York, NY
•Hybrid

About The Position

Fitch Group is currently seeking a Senior Network Engineer based out of our New York office. As a leading, global financial information services provider, Fitch Group delivers vital credit and risk insights, robust data, and dynamic tools to champion more efficient, transparent financial markets. With over 100 years of experience and colleagues in over 30 countries, Fitch Group’s culture of credibility, independence, and transparency is embedded throughout its structure, which includes Fitch Ratings, one of the world’s top three credit ratings agencies, and Fitch Solutions, a leading provider of insights, data and analytics. With dual headquarters in London and New York, Fitch Group is owned by Hearst. At Fitch Group, the combined power of our global perspectives is what differentiates us. It is the strength of our business. It comes from people around the world in a shared pursuit: to equal something greater than they could ever accomplish alone. Every team member is essential to our business and every perspective is critical for our success. Develop yourself in a new culture that values flexibility, expects your opinion and trusts your decisions. Together we evolve and so will you, in an environment that asks you to challenge yourself – and us. About the Team The Network Engineering team designs, operates, and continuously improves the secure connectivity platforms that enable Fitch colleagues to work reliably across office, remote, and cloud environments. This role will partner closely with Security, Endpoint, Cloud, Reliability Engineering, Operations, and business teams to deliver supportable secure access designs and reduce operational dependency on a small number of subject matter experts.

Requirements

  • Hands-on engineering experience with Zscaler ZIA and ZPA, along with a strong understanding of SSE, SASE, Zero Trust, secure web gateway, private application access, DLP, CASB, SSL inspection, and cloud security concepts.
  • Strong networking fundamentals across routing, switching, DNS, proxy behavior, firewall policy, internet edge design, cloud connectivity, and troubleshooting.
  • Comfortable evaluating security-sensitive access designs, policy changes, traffic flows, and exceptions using sound judgment that balances business needs, risk reduction, and protection of sensitive data.
  • Ability to work effectively across engineering, security, cloud, endpoint, operations, and business teams with strong ownership, clear communication, and a focus on supportable outcomes.

Nice To Haves

  • Experience with scripting, APIs, automation, log analysis, packet capture tools, configuration validation, policy reporting, health checks, change readiness, or operational dashboards.
  • Cisco, Meraki, SD-WAN, or traditional enterprise networking experience, especially in environments undergoing network modernization.
  • Experience contributing to modernization programs such as Office Zero Trust, Wi-Fi, Meraki, cloud security enhancements, SD-WAN planning, and east-west inspection initiatives.
  • A track record of creating architecture diagrams, design documentation, standards, runbooks, troubleshooting guides, and knowledge-transfer materials that improve supportability and reduce single points of expertise.

Responsibilities

  • Design, deploy, operate , and continuously improve Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) as core platforms for secure internet access, private application access, and user-to-application connectivity.
  • Implement and mature Zero Trust Network Access, application segmentation, least-privilege access controls, and secure access patterns across remote, office, and cloud environments.
  • Define, tune, and enforce security policies including URL filtering, SSL inspection, cloud application controls, browser isolation, DLP, and AI/LLM usage controls.
  • Enable secure access to workloads and applications hosted in AWS, Azure, OCI, and GCP while aligning access designs with operational resilience, supportability, and long-term network modernization goals.
  • Lead complex troubleshooting for user access, application connectivity, authentication, policy enforcement, service health, and performance issues, including log analysis, packet captures, and high-impact incident escalation support.

Benefits

  • Hybrid Work Environment: 2 to 3 days a week in office based on your line of business and location
  • A Culture of Learning & Mobility: Dedicated trainings, leadership development and mentorship programs designed to ensure that your time at Fitch will be a continuous learning opportunity
  • Investing in Your Future: Retirement planning and tuition reimbursement programs that empower you to achieve your short and long-term goals
  • Promoting Health & Wellbeing: Comprehensive healthcare offerings that enable physical, mental, financial, social, and occupational wellbeing
  • Supportive Parenting Policies: Family-friendly policies, including a generous global parental leave plan, designed to help you balance career and family life effectively
  • Inclusive Work Environment: A collaborative workplace where all voices are valued, with Employee Resource Groups that unite and empower our colleagues around the globe
  • Dedication to Giving Back: Paid volunteer days, matched funding for donations and ample opportunities to volunteer in your community
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service