Senior Network Security Engineer
Zayo Group United States · $95K–$146K/yr
Telecommunications · 5,001-10,000 employees
About the role
The Senior Network Security Engineer will design, implement, and optimize enterprise network security solutions across on-premises and cloud environments. This role also serves as a senior technical escalation point for complex security incidents and provides leadership to engineering teams.
What they look for
Requirements
Candidates must have at least seven years of experience in network security and a minimum of three years of hands-on experience with Zscaler technologies. Strong proficiency in Zero Trust principles, firewall management, and cloud security architectures is required.
Benefits
Full description
Company Description
Zayo provides mission-critical bandwidth to the world’s most impactful companies, fueling the innovations that are transforming our society. Zayo’s 141,000-mile network in North America and Europe includes extensive metro connectivity to thousands of buildings and data centers. Zayo’s communications infrastructure solutions include dark fiber, private data networks, wavelengths, Ethernet, and dedicated Internet access. Zayo serves wireless and wireline carriers, media, tech, content, finance, healthcare and other large enterprises.
We are seeking a highly experienced Senior Network Security Architect to serve as a technical leader responsible for the design, implementation, optimization, and operational support of our enterprise network security environment. This role combines hands-on engineering, solution architecture, and Level 3 operational support responsibilities across multiple network security technologies, with a strong emphasis on Zscaler, Zero Trust, and cloud security.
The ideal candidate is an experienced network security professional who can balance strategic architecture with day-to-day operational leadership. You will partner closely with Network, Security, Identity, Infrastructure, and Application teams to deliver scalable, secure, and highly available solutions while mentoring engineers, leading complex troubleshooting efforts, and driving operational excellence.
Key Responsibilities
Network Security Architecture
- Design, implement, and optimize enterprise network security solutions supporting on-premises, cloud, and hybrid environments.
- Architect scalable Zero Trust security solutions utilizing technologies including Zscaler, next-generation firewalls, VPNs, secure web gateways, cloud security services, and network segmentation.
- Lead evaluations, Proofs of Concept (POCs), and implementation of new security technologies and services.
- Develop technology roadmaps, standards, and best practices for enterprise network security.
- Collaborate with network, security, infrastructure, and identity teams to ensure secure and resilient architectures.
Engineering & Operations
- Serve as the senior technical escalation point for complex network security incidents and production issues.
- Troubleshoot advanced networking, DNS, routing, authentication, proxy, SSL/TLS, and application connectivity issues.
- Configure, manage, and optimize enterprise security technologies including firewalls, VPNs, secure web gateways, cloud access security solutions, and Zero Trust platforms.
- Perform root cause analysis for recurring or high-impact incidents and drive long-term remediation.
- Monitor platform health, performance, and user experience using enterprise monitoring and observability tools.
- Participate in critical incident response and support a highly available production environment.
- Zscaler Administration
- Administer and optimize Zscaler services including ZIA, ZPA, and ZDX.
- Configure security policies, SSL inspection, traffic forwarding, PAC files, IPSec/GRE tunnels, and App Connector deployments.
- Support Zero Trust access policies, secure application access, and cloud security initiatives.
- Collaborate with identity teams to integrate authentication platforms including Microsoft Entra ID (Azure AD), CyberArk, SailPoint, and other enterprise identity providers.
Security Governance & Automation
- Develop and maintain security standards, configuration management processes, and operational procedures.
- Implement automation to improve deployment, monitoring, configuration management, and operational efficiency.
- Support compliance initiatives by ensuring network security solutions align with organizational policies and regulatory requirements.
- Develop and maintain runbooks, playbooks, technical documentation, and operational standards.
Leadership & Collaboration
- Provide technical leadership and mentorship to engineering and operations teams.
- Lead technical discussions across infrastructure, networking, security, identity, and application teams.
- Share knowledge through documentation, training, and operational guidance.
- Drive continuous improvement initiatives focused on service reliability, operational maturity, and customer experience.
Required Qualifications
- Minimum of seven (7) years of experience in network security, cybersecurity, or infrastructure engineering.
- Strong experience designing, implementing, and supporting enterprise network security technologies.
- Minimum of three (3) years of hands-on experience with Zscaler technologies, including ZIA, ZPA, and/or ZDX.
- Experience administering one or more enterprise firewall platforms such as Palo Alto, Cisco, Fortinet, or Check Point.
- Strong understanding of:
- Network security architecture
- Zero Trust principles
- Secure Web Gateway technologies
- VPN technologies
- DNS
- Routing and switching fundamentals
- SSL/TLS
- Identity and authentication
- Experience with cloud security and hybrid network architectures.
- Experience troubleshooting complex production issues and serving as a senior escalation resource.
- Familiarity with enterprise identity providers such as Microsoft Entra ID (Azure AD), SailPoint, or CyberArk.
- Excellent analytical, troubleshooting, documentation, and communication skills.
Preferred Qualifications
- Zscaler certifications (ZCP, ZDTA, ZDTE, ZDXA).
- CISSP, CISM, Security+, Network+, GIAC, CCNP Security, PCNSE, or equivalent certifications.
- Experience with scripting and automation using Python, PowerShell, or Shell.
- Experience with CI/CD, Infrastructure as Code, and configuration management tools.
- Familiarity with compliance frameworks such as PCI-DSS, SOX, HIPAA, or NIST.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).
What We're Looking For
We're looking for a hands-on network security expert who enjoys solving complex technical challenges and improving enterprise security services. The ideal candidate combines broad network security expertise with strong experience supporting cloud security and Zero Trust technologies, including Zscaler.
Success in this role requires someone who can:
- Design and implement scalable network security solutions.
- Lead complex troubleshooting and serve as a senior technical escalation resource.
- Balance strategic architecture with hands-on engineering.
- Collaborate effectively across security, networking, infrastructure, and identity teams.
- Continuously improve security operations through automation, process improvement, and technical leadership.
Estimated base salary range: $95,100.00 - 146,300.00 USD/annually.
Work Authorization Requirement: Applicants must be currently authorized to work in the United States on a full-time basis, and this position is not eligible for employer-sponsored work authorization, such as OPT, TN, H1B, or any other type of work visa, now or in the future.
The base pay range shown is a guideline and reasonable estimate for this role. It takes into account the wide variety of factors that are considered in making compensation decisions. Actual compensation offered may vary from the posted range based upon geographic location, work experience, skill level, certifications, and other business and organizational needs. Non- sales roles may be eligible to participate in a discretionary annual incentive plan. Sales roles may be eligible to participate in a sales incentive plan.
Additionally, this position may be eligible for certain benefits, such as health insurance, life insurance, disability retirement plans, paid time off.
The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.
Benefits, Rewards & Wellness
- Excellent Health, Dental & Vision Insurance
- Retirement 401(k) Savings Plan
- Generous paid time off policy including paid parental leave
Zayo is an equal opportunity employer to all protected groups, including protected veterans and individuals with disabilities. If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact us.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
As part of the application, hiring, onboarding, and/or employment process, Zayo or its affiliates, partners, and vendors may collect, store, and use biometric identifiers and biometric information (collectively, “Biometric Data”), such as fingerprints, facial geometry scans or other unique biological characteristics. Zayo uses CLEAR1, a third-party identity verification service, to verify applicant identity during the hiring process. CLEAR1 may collect Biometric Data, including facial geometry scans and/or other biometric identifiers, to authenticate your identity. Biometric Data will be retained pursuant to CLEAR1’s policies, which can be found here: https://www.clearme.com/clear1-credential-policy-crp. Zayo will not sell, lease, trade, or otherwise profit from any applicant's or employee's Biometric Data. By proceeding with your application, you acknowledge this disclosure. Prior to any collection of Biometric Data — including through CLEAR — you may be presented with a separate consent form and asked to provide your written authorization in accordance with applicable federal, state, and local laws, including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and other applicable biometric privacy statutes.
Similar roles
-
Senior Security Engineer
Commonwealth Bank Bengaluru, Karnataka, India
-
Security Engineer, Vulnerability Management (ACAS/Tenable.sc) - Secret clearance
PGTEK Ogden, Utah, United States · $130K–$160K/yr
-
Security Engineer, GKE
Google Seattle, Washington, United States · $174K–$252K/yr
-
Cybersecurity Incident Response Triage Analyst
Accenture Federal Services Careers Marketplace Arlington, Virginia, United States · $57K–$109K/yr
-
Cybersecurity Incident Response Triage Analyst
Accenture Federal Services Arlington, Virginia, United States · $57K–$109K/yr
-
Information Security Engineer
EverBank Jacksonville, Florida, United States