{"id":1311081,"url":"https://alion.io/job/legato-security-network-security-engineer","title":"Network Security Engineer","company":{"id":2462429,"name":"Legato Security","domain":"legatosecurity.com","url":"https://alion.io/company/legatosecurity","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Salt Lake City, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":92000,"max_usd":210000,"period":"year","method":"role_country_seniority_unknown","sample_n":1953},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"BGP","optional":false},{"name":"DHCP","optional":false},{"name":"DNS","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"OSPF","optional":false},{"name":"TCP/IP","optional":false},{"name":"VPN","optional":false},{"name":"Wireshark","optional":false},{"name":"Zero Trust","optional":false},{"name":"Zscaler","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"DLP","optional":true},{"name":"FortiGate","optional":true},{"name":"GCP","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"Rest API","optional":true},{"name":"Sophos","optional":true}],"status":"live","first_seen_at":"2026-09-18T18:19:33Z","employer_posted_date":"2026-09-18","last_verified_at":"2026-09-30T06:06:10Z","board_verified":true,"closed_at":null,"days_open":11,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":11},"description":"Enter Job Title \n\nWho We Are \n\nLegato Security is an information security firm founded upon the belief that every organization has the right to keep its data private and secure. Our mission is to build close partnerships with our clients, serving them not as just a vendor, but as trusted advisors helping to build effective, proactive plans. Our focus is always on both the technical and human elements within an organization. We believe in comprehensive strategies designed to harden networks, deflect attackers, and rapidly recover from any accidents. As technology progresses, so do our tactics, ensuring our experts are always prepared to serve forward-looking leaders eager to stay ahead of emerging threats. \n\nPosition Overview \n\nWe are seeking a Network Security Engineer to join our Network team. This role will support the administration, implementation, troubleshooting, design, and ongoing improvement of our customers’ networks and security environments.\nThe ideal candidate will have hands-on experience with network security technologies such as firewalls, Zscaler, Netskope, VPNs, routing, switching, or related technologies. Extensive experience with every platform is not required, but a strong networking foundation, practical troubleshooting ability, good communication skills, and a willingness to continually learn are essential.\nThis position will work across a variety of operational and project-based activities, including customer requests, incidents, service tickets, troubleshooting, implementations, migrations, upgrades and changes, and technical projects. Because the role supports multiple customers and environments, the successful candidate must be able to communicate effectively, manage competing priorities, adapt to different technical requirements, and see issues through to resolution.\nThis position is hybrid and mostly remote in nature, but may require some time in office (Downtown Salt Lake City) for troubleshooting, updating, and replacing network equipment; client visits as required, etc. Some time on-call is required, but this will rotational and not extensive.\n\nSpecific Job Responsibilities \n\nSupport, administer, configure, and troubleshoot firewalls, Zscaler services, Netskope, VPN technologies, and related network security platforms, both internal and in customer environments\nWork directly with customers to understand business and technical requirements, troubleshoot problems, evaluate potential solutions, and implement appropriate changes\nRespond to and resolve service tickets, incidents, requests, and escalations involving network connectivity, firewalls, Zscaler, Netskope, and related technology\nServe as an escalation point for technical issues that require additional troubleshooting, analysis, or expertise beyond initial support\nSupport, configure, and troubleshoot firewall and network product environments to meet customer connectivity and security requirements\nParticipate in firewall, Zscaler, and Netskope implementation, migration, upgrade, replacement, and configuration projects.\nAssist with the configuration and maintenance of Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, and related services\nAssist with the configuration and maintenance of the Netskope One platform including SASE, SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN, and more\nSupport Zscaler and Netskope policies including URL filtering, firewall policies, SSL inspection, authentication, access policies, application access, traffic forwarding, connectivity, routing, DNS, DHCP, NAT, VPNs, authentication, traffic forwarding, SSL/TLS inspection, application access, VLANs, switching technologies, and policy enforcement\nConfigure and troubleshoot VPN technologies including SSL VPN, IPsec, Remote Access VPN, and Site-to-Site VPN connections\nReview firewall logs, Zscaler logs, Netskope logs, packet captures, routing tables, traffic flows, error messages, and other diagnostic information to determine root cause\nAssist with customer onboarding and changes to existing customer network and security environments, testing and validation of new configurations, and other changes prior to production deployment\nCreate and maintain firewall documentation, configuration records, troubleshooting procedures, implementation notes, and customer-specific technical documentation.\nParticipate in incident response, problem management, and root-cause analysis activities as needed\nHave the ability to manage multiple unresolved tickets, incidents, projects, and customer requests with assistance from other team members or technical resources as needed, both individually and in collaboration with team members\nAssist engineers and analysts and with troubleshooting processes, technical methodologies, and network security best practices\nIdentify opportunities to improve network configurations, security controls, operational processes, troubleshooting methods, documentation, and customer experience\nMaintain awareness of emerging networking and cybersecurity technologies, vendor platform changes, vulnerabilities, security capabilities, and industry best practices\n\n Qualifications \n\nRequired Qualifications: \nHands-on experience with one or more network security technologies such as firewalls, Zscaler, Netskope, VPNs, secure web gateways, SSE/SASE platforms, proxies, or zero-trust technologies\nStrong troubleshooting and analytical skills with the ability to methodically diagnose network and security issues\nWorking knowledge of routing concepts and protocols such as TCP/IP, BGP, OSPF, EIGRP, IS-IS, RIP, Static Routing, and SD-WAN\nWorking knowledge of LAN technologies including Ethernet switching, VLANs, Spanning Tree Protocol (STP), Port security, Link/port aggregation, and LAN and WAN architecture\nExperience or familiarity with physical, virtual, and cloud firewall technologies\nUnderstanding of firewall concepts including Security policies, zones and interfaces, objects and object groups, routing, NAT, VPNs, Application and Service policies, Logging, and traffic analysis\nKnowledge or familiarity of VPN technologies including IPsec, SSL VPN, Remote Access VPN, and Site-to-Site VPN\nWorking knowledge of concepts including NAT (Source NAT, Destination NAT, and U-Turn/Hairpin NAT), DNS, and DHCP\nFamiliarity with authentication and identity technologies such as SAML, SSO, MFA, Active Directory, Entra ID, and SCIM\nAbility to capture, analyze, and interpret network traffic using Wireshark or similar packet-analysis tools\nAbility to interpret network and security logs, packet captures, routing information, error messages, and other diagnostic information\nAbility to design and document network and related security solutions would be helpful \nStrong customer-facing skills, including the ability to listen, evaluate requirements, ask appropriate questions, and clearly explain technical issues and solutions\nAbility to communicate effectively with both technical and non-technical audiences\nThe ability to work both within a team environment and individual situations are required\nAbility to work with multiple customers, environments, projects, incidents, and priorities simultaneously\nAbility to manage time effectively and see incidents, requests, and technical issues through to resolution\nWillingness and ability to learn new technologies and develop deeper expertise across networking and network security platforms\nPreferred Qualifications: \nExperience with one or more of the following technologies or disciplines is beneficial but not required:\nFirewall and Network Security Platforms\nPalo Alto Networks\nCisco ASA / Cisco Secure Firewall\nFortinet FortiGate\nCheck Point\nJuniper SRX\nSonicWall\nCisco Meraki\nSophos\nWatchGuard\nMicrosoft Azure network security technologies\nAmazon Web Services network security technologies\nZscaler Technologies\nZscaler Internet Access (ZIA)\nZscaler Private Access (ZPA)\nZscaler Client Connector\nZscaler Digital Experience (ZDX)\nZscaler Cloud Firewall\nZscaler Data Loss Prevention (DLP)\nZscaler traffic forwarding technologies\nZscaler API integrations and automation\nNetskope Technologies\nNetskope One SASE\nNetskope One SSE\nCloud Access Security Broker (CASB)\nNext Generation Secure Web Gateway (SWG)\nPrivate Access\nCloud Firewall\nSD-WAN\nSkopeAI\nCloud Networking\nUnderstanding or experience with cloud networking and security technologies within Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP) would be helpful.\nExperience with cloud technologies such as Virtual networks/VPCs, subnets, route tables, security groups, cloud firewalls, VPN gateways, private connectivity, cloud routing, hybrid network connectivity\nAdditional Technologies\nFamiliarity or experience with the following would be beneficial:\nWireless network security, protocols, troubleshooting, and design\nSNMP monitoring and alerting solutions\nNetwork monitoring and performance-management platforms\nPacket capture and network troubleshooting tools\nNetwork automation\nREST APIs, PowerShell, and/or Python\nInfrastructure scripting or automation\nCertifications\nRelevant networking, security, firewall, cloud, Netskope, or Zscaler certifications are considered a plus but are not required. However, preference will be given towards active and actively maintained certification along the lines of Zscaler and firewalls vendors.\nExamples may include:\nZscaler Digital Transformation Administrator (ZDTA) or Zscaler Digital Transformation Engineer (ZDTE)\nNetskope Certified Cloud Security Integrator (NCCSI - NSK200), Netskope Certified Cloud Security Architect (NCCSA - NSK300), or Netskope SASE Accredidation\nCisco CCNA or CCNP\nPalo Alto Networks CSA or CSP\nCompTIA Network+ or Security+\nOther relevant networking or cybersecurity certifications\n\nPerks \n\n· Start-up company in a growth phase with opportunity for advancement based on performance \n· Start-up culture with an office in downtown Salt Lake City, UT \n· Competitive medical and dental benefits for employee and family members \n· Other company-provided benefits such as short-term disability, basic life insurance, children’s orthodontia, with additional voluntary benefits available\n· Flexible Paid Time Off policy \n· Professional Development opportunities specific to role","description_format":"text","description_chars":10271,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Life insurance","Professional development"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Network Security","Cybersecurity","Information Security","Managed Security"],"lifecycle":[{"event":"open","at":"2026-09-26T16:21:58Z"}],"liveness":{"score":70,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.705,"p_room":1,"age_days":11,"expected_fill_days":101,"reasons":["conf:15","urgency","win:early"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/legato-security-network-security-engineer","json_url":"https://alion.io/job/legato-security-network-security-engineer.json","meta":{"generated_at":"2026-09-30T06:35:33Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4610,"day_limit":5000,"remaining_today":390,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}