Senior Network Security Engineer SASE
Atlanta, GA - USA
Job Summary
Cargill is committed to providing food and agricultural solutions to nourish the world in a safe responsible and sustainable way. Sitting at the heart of the supply chain we partner with farmers and customers to source make and deliver products that are vital for living.
Our 155000 team members innovate with purpose providing customers with lifes essentials so businesses can grow communities prosper and consumers live well. With over 160 years of experience as a family company we look ahead while remaining true to our values. We put people first. We reach higher. We do the right thingtoday and for generations to come.
The Senior Network Engineer - SASE will lead the design deployment automation operation and continuous improvement of Cargills global Secure Access Service Edge (SASE) and Security Service Edge (SSE) capabilities. This role will help transform secure connectivity by migrating legacy web proxy and remote-access technologies to cloud-delivered security services including Secure Web Gateway (SWG) Zero Trust Network Access (ZTNA) Cloud Access Security Broker (CASB) Data Loss Prevention (DLP) and threat protection. The engineer will provide technical leadership across network security identity cloud endpoint and application teams to deliver reliable scalable and policy-driven access for users sites and applications.
- NETWORK SOLUTIONS: Designs implements and maintains network solutions to meet organizational needs including creating network diagrams and blueprints.
- NETWORK DEVICES CONFIGURATION: Sets up and configures various complex network devices such as routers switches firewalls virtual private networks and software defined networking to maintain optimal performance and security.
- TROUBLESHOOTING & DIAGNOSTICS: Performs complex troubleshooting and diagnostics to resolve network issues ensuring minimal downtime and maintaining network reliability.
- NETWORK MAINTENANCE: Leads routine maintenance and updates on network systems including applying patches service packs and security configurations.
- PERFORMANCE MONITORING & OPTIMIZATION: Monitors network performance maintains system availability and reliability and makes necessary adjustments to optimize performance.
- SECURITY MEASURES: Sustains network security by leading the implementation of appropriate measures such as firewalls intrusion detection systems and encryption technologies.
- DISASTER RECOVERY PLANNING: Develops and implements disaster recovery plans to ensure business continuity in case of network failures.
- NETWORK AUTOMATION: Develops and implements automation and tools to streamline network operations including configuration management device provisioning and software updates.
- Minimum requirement of 4 years of relevant work experience. Typically reflects 5 years or more of relevant experience.
- Minimum of 5 years of relevant experience in network engineering network security or cybersecurity engineering.
- Hands-on experience implementing and supporting SASE or SSE solutions in an enterprise environment.
- Experience deploying and managing SWG and ZTNA technologies.
- Strong understanding of enterprise networking fundamentals including TCP/IP routing switching DNS DHCP VPNs SSL/TLS certificates and network security principles.
- Experience troubleshooting complex connectivity authentication and application-access issues across hybrid and cloud environments.
Preferred:
- Experience implementing and administering one or more leading SASE/SSE platforms such as Netskope Palo Alto Prisma Access Zscaler Internet Access (ZIA) or Zscaler Private Access (ZPA).
- Experience designing implementing and supporting enterprise firewall platforms such as Check Point Palo Alto Networks or Fortinet including security policy management network segmentation NAT VPN connectivity and integration with SASE architectures.
- Deep understanding of SWG capabilities including URL filtering SSL/TLS inspection cloud application visibility and control malware protection DLP threat prevention and policy enforcement.
- Experience designing ZTNA solutions for secure access to private applications and reducing reliance on traditional VPN technologies.
- Experience with SASE traffic steering and service components including endpoint clients GRE/IPsec tunnels private access connectors or publishers dedicated egress and high-availability designs.
- Strong understanding of identity-driven security and integration with Microsoft Entra ID Okta Ping Identity or similar identity providers using SAML OAuth OIDC and SCIM.
- Experience integrating SASE platforms with endpoint security SIEM XDR and security operations workflows.
- Knowledge of cloud networking and security architectures across AWS Azure and Google Cloud Platform.
- Experience with policy lifecycle management security posture assessments exception governance and change control for cloud-delivered security services.
- Experience with automation and scripting using Python PowerShell REST APIs Terraform Ansible GitHub or similar tools.
- Experience with network security and digital-experience observability tools used to monitor user experience application performance and security events.
- Ability to develop technical architecture documentation low-level design artifacts implementation plans operational runbooks and support models for SASE deployments.
- Experience working within Agile engineering teams using modern engineering and DevSecOps practices.
- Demonstrated ability to provide technical leadership mentor engineers and collaborate across network security identity cloud endpoint and application teams.
#HiPo
Equal Opportunity Employer including Disability/Vet.
Required Experience:
Senior IC
About Company
Cargill, Incorporated is an American privately held global corporation based in Minnetonka, Minnesota, and incorporated in Wilmington, Delaware. Founded in 1865, it is the largest privately held corporation in the United States in terms of revenue.