What are the responsibilities and job description for the SASE Security Engineer position at Covenant HR?
Company – Our client is a nationally recognized cybersecurity solutions provider partnering with some of the most prestigious names in financial services and beyond. They deliver cutting-edge cloud and network security transformations with a proven track record of large-scale deployments across Fortune 500 enterprises. This opportunity supports one of the largest and most security-conscious financial organizations in the U.S.
Job Title – SASE Security Engineer (Netskope Focus)
Location – Tysons, Virginia (Hybrid – onsite 3 days per week)
Role Type – 6-Month Contract (1,040 hours)
Must Have Skills:
- 5 years of hands-on experience in security engineering roles, with at least 3 years specifically focused on enterprise-scale SASE/SSE deployments
- Deep expertise in Netskope Security Cloud (SWG, CASB, ZTNA) or similar SASE platforms such as Zscaler or Prisma Access
- Proven success in migrating from legacy firewalls (Check Point, Cisco, etc.) to Zero Trust, cloud-delivered SASE architectures
- Strong grasp of networking principles across OSI layers 1–7, SD-WAN, and NGFW policy optimization
- Experience integrating Netskope with IdP platforms (Ping/Azure AD) and EDR tools to enable contextual access control
Responsibilities and Job Details:
- Own the design, deployment, and operationalization of the global SASE environment using Netskope as the core SSE solution
- Define and engineer Zero Trust Network Access (ZTNA) policies tailored by user group and application sensitivity
- Lead legacy policy migration, replacing traditional firewall rules with a tag-oriented unified security policy aligned with Zero Trust principles
- Optimize SSL inspection by minimizing unnecessary exclusions and improving visibility into encrypted traffic
- Clean up and harden legacy firewall rule sets, eliminating redundancies and reducing overly permissive access
- Oversee full lifecycle deployment of Netskope modules including SWG, CASB, ZTNA, RBI, and DLP
- Ensure seamless integration with enterprise IdPs and EDR solutions to support adaptive, real-time access decisions
- Serve as Tier 3 technical escalation for Netskope-related issues across Windows and macOS endpoints
- Lead Zero Trust transformation efforts across the enterprise security stack
- Document architecture, design decisions, and configuration standards to support long-term maintainability
- Work onsite in Tysons, VA three days per week
- Must commit to this engagement exclusively with no overlapping contracts