{"id":1203777,"url":"https://alion.io/job/ahead-technical-consultant-network-security-sase","title":"Technical Consultant - Network Security SASE","company":{"id":3614,"name":"AHEAD","domain":"ahead.com","url":"https://alion.io/company/ahead","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Lever","truth_index":{"grade":"B","score":73,"open_postings":42,"ghost_share":0,"stale_share":0.881,"repost_share":0,"time_to_fill_p50_days":63,"computed_at":"2026-09-26T05:45:00Z"}},"role":"Solutions","role_family":"Solutions","seniority":"middle","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":{"min":100000,"max":130000,"currency":"USD","period":"year","gross":null,"usd_annual":130000},"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"BGP","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Okta","optional":false},{"name":"OSPF","optional":false},{"name":"Zero Trust","optional":false},{"name":"Zscaler","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"DLP","optional":true}],"status":"live","first_seen_at":"2026-09-24T17:36:08Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-27T02:40:37Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"We are seeking a Technical Consultant to deliver Secure Access Service Edge (SASE) and Security Service Edge (SSE) engagements for enterprise clients. This role covers a single technology pillar spanning four core platforms: Zscaler Internet Access and Private Access, Palo Alto Networks Prisma Access, Cisco Secure Access, and Netskope Security Cloud. Technical Consultants independently lead remote and on-site SASE/SSE deployment workstreams, configuring and operating Zero Trust architectures against a design produced by a Senior Technical Consultant or Principal Technical Consultant. This role owns hands-on configuration, testing, and knowledge transfer for assigned workstreams, contributes to client-facing documentation, and mentors junior engineers, while building deep expertise in one SASE/SSE platform as the foundation for advancement to Senior Technical Consultant.\nKey Responsibilities - SASE & Zero Trust:\nConfigure and deploy Zscaler Internet Access (ZIA) components including Secure Web Gateway policy, SSL inspection, URL filtering, cloud firewall rules, and sandbox policy against an established design.\nConfigure and deploy Zscaler Private Access (ZPA) application segments, App Connectors, and browser-based access for Zero Trust remote access.\nConfigure Palo Alto Prisma Access GlobalProtect remote user connectivity, explicit proxy setup for branch offices, and service connections to on-premises infrastructure through Strata Cloud Manager or Panorama.\nConfigure Cisco Secure Access Zero Trust Network Access, Secure Web Gateway, Cloud Access Security Broker, and resource connector deployment for private application access.\nConfigure Netskope Security Cloud Next Gen SWG, CASB (API-enabled and inline), and Netskope Private Access traffic steering and policy enforcement.\nImplement traffic forwarding methods including GRE tunnels, IPsec tunnels, PAC files, and client connectors according to the design provided by the engagement architect.\nConfigure identity-based access controls integrating with Okta, Microsoft Entra ID, SAML 2.0, and SCIM provisioning to enforce conditional access policy across SASE/SSE platforms.\nDeploy and tune Cloud Access Security Broker and Data Loss Prevention policy in inline and API-based modes under established policy guidelines.\nExecute platform health checks, policy tuning, and day-2 operational tasks across assigned SASE/SSE platforms.\nSupport SASE and SD-WAN convergence testing, validating policy consistency across direct internet access and backhauled traffic paths.\nContribute platform-specific input to client Zero Trust maturity roadmaps under the direction of the engagement lead.\nArchitecture, Delivery & Documentation:\nParticipate in client-facing discovery sessions and design workshops, gathering requirements and validating current-state configuration for SASE/SSE scope.\nContribute to High-Level Design and Low-Level Design documentation, network diagrams, and as-built documentation for assigned SASE/SSE workstreams.\nExecute migration and cutover tasks according to documented runbooks, rollback procedures, and change management workflows.\nSupport knowledge transfer sessions, training client operations teams on day-2 SASE/SSE platform administration.\nTrack assigned workstream milestones and escalate risks or scope changes to the project lead or Senior Technical Consultant.\nIdentify client requests that fall outside the documented scope and escalate to the project manager or engagement lead before delivery impact occurs.\nPractice Contribution:\nMentor Associate and Senior Associate Technical Consultants on SASE/SSE platform fundamentals and troubleshooting techniques.\nContribute to reusable delivery assets including configuration checklists, runbook templates, and knowledge base articles for the SASE/SSE practice.\nPursue certification progression toward professional-level SASE/SSE credentials in the platform of primary focus.\nSupport sales campaigns by validating technical scope and providing delivery continuity input to the account team, under the direction of the engagement Solutions Lead.\nRequired Qualifications:\n3 to 5 years of network security, infrastructure security, or security engineering experience, including client-facing or internal project delivery experience.\nProduction experience configuring at least one of the following SASE/SSE platforms: Zscaler (ZIA and ZPA), Palo Alto Prisma Access, Cisco Secure Access, or Netskope Security Cloud.\nWorking knowledge of Zero Trust architecture principles, Secure Web Gateway, CASB, and ZTNA concepts across the broader SASE/SSE platform landscape.\nUnderstanding of identity and access management integration (Okta, Microsoft Entra ID, SAML 2.0, SCIM) with SASE/SSE policy enforcement.\nFamiliarity with routing and connectivity fundamentals (BGP, OSPF, IPsec, GRE) sufficient to implement traffic forwarding designs provided by an architect.\nAbility to produce clear technical documentation and communicate configuration status and issues to both technical and non-technical stakeholders.\nAbility to travel at least 25 percent.\nPreferred Qualifications:\nZscaler Digital Transformation Administrator (ZDTA); Palo Alto Networks Security Service Edge (SSE) Engineer certification; Cisco Certified Specialist - Secure Cloud Access; Netskope Certified Cloud Security Administrator (NCCSA).\nCompTIA Security+, CCNA, or equivalent foundational networking or security certification.\nProduction experience with a second SASE/SSE platform beyond the primary area of focus.\nExposure to CASB and DLP policy tuning in inline or API-based deployment modes.\nPrior consulting, professional services, or managed services experience.\nExperience with cloud platforms (AWS VPC, Azure VNet) sufficient to support hybrid SASE/SSE connectivity designs.\nExpectations:\nIndependently leads remote and on-site SASE/SSE deployment workstreams within an established design.\nOperates with limited supervision on moderately complex configuration and troubleshooting tasks.\nBuilds deep expertise in one SASE/SSE platform as the primary specialty, with working knowledge across the broader practice.\nMentors junior engineers and contributes to SASE/SSE practice enablement content.\nClearly articulates the scope of assigned work and how it supports the engagement's business objectives.\nProactively raises schedule or scope concerns to the project lead or Senior Technical Consultant.\nIdentifies out-of-scope client requests and escalates before delivery impact occurs.\nCarries a 70 percent target utilization.\nSoft Skills:\nClear written and verbal communication skills, with the ability to produce client-ready configuration and status documentation.\nAbility to manage assigned workstream timelines and communicate progress within a consulting delivery model.\nSelf-directed and detail-oriented, comfortable operating on-site at client facilities or in a remote delivery capacity.\nCollaborative approach to working with senior engineers, project leads, and cross-functional delivery teams.\nReceptive to mentorship and structured skill development, with an active interest in advancing technical depth.","description_format":"text","description_chars":7131,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Network Security","IT Consulting & Digital Transformation","Managed IT Services (MSP)","AI Consulting & Integration"],"lifecycle":[{"event":"open","at":"2026-09-24T22:35:00Z"}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":1,"expected_fill_days":63,"reasons":["conf:0","stale_co","velocity","win:early","comp:brand,attention"],"computed_at":"2026-09-26T05:45:00Z"},"pay":{"stated_usd_annual":130000,"is_top_pay":false},"html_url":"https://alion.io/job/ahead-technical-consultant-network-security-sase","json_url":"https://alion.io/job/ahead-technical-consultant-network-security-sase.json","meta":{"generated_at":"2026-09-27T05:10:43Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4542,"day_limit":5000,"remaining_today":458,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}