finseats

Principal SASE Engineernew

Citizens Financial Group (Citizens) · Other

Apply on official site ↗

Closes in 31 days — 31 Aug 2026

4 Days in the office from any of our locations in Johnston RI, Dallas TX, Nashville TN, Iselin NJ, Westwood or Medford MA, or Phoenix AZ and couple other locations

Role is not relocation eligible. 

Principal SASE Engineer

Description

At Citizens, we're more than a bank. Here, you'll experience new things, create new opportunities, think beyond your role, and make an impact. While in this role, you'll serve as a senior technical leader responsible for the engineering, administration, and strategic evolution of our Secure Access Service Edge (SASE) platform, with a primary focus on Netskope.

As a Principal SASE Engineer, you will lead the design, implementation, and optimization of cloud-delivered security services that enable secure access for colleagues, applications, and customers. You will partner across Infrastructure, Cybersecurity, Network Engineering, Architecture, and Operations teams to deliver secure, scalable, and resilient access solutions aligned with the organization's Zero Trust strategy.

The ideal candidate will possess deep hands-on expertise with Netskope technologies, strong network and security engineering experience, and a demonstrated ability to lead large-scale enterprise deployments. Experience with Zscaler and Out-of-Band (OOB) Management solutions is highly desirable.

Primary Responsibilities

  • Serve as the primary technical owner and subject matter expert for the enterprise Netskope platform.
  • Design, deploy, and support Netskope services, including Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), Data Loss Prevention (DLP), Cloud Firewall, and related Security Service Edge (SSE) capabilities.
  • Lead the implementation of Zero Trust access solutions and initiatives focused on modernizing traditional remote access technologies.
  • Engineer scalable and secure access solutions supporting hybrid workforce, cloud connectivity, and enterprise applications.
  • Develop and maintain security policies, traffic steering configurations, access controls, and user experience optimization strategies.
  • Provide advanced troubleshooting and Tier III support for complex platform, network, and security incidents.
  • Collaborate with Cybersecurity, Identity & Access Management, Cloud Engineering, and Network teams to ensure secure infrastructure integration.
  • Evaluate emerging technologies and drive continuous improvement initiatives across the SASE and secure access landscape.
  • Develop operational procedures, technical standards, architecture documentation, and knowledge transfer materials.
  • Mentor engineers and provide technical leadership across security and infrastructure teams.
  • Participate in strategic planning, architecture reviews, and vendor evaluations.

 

Qualifications

Required Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or equivalent experience.
  • 8+ years of experience in Network Engineering, Security Engineering, Infrastructure Engineering, or related disciplines.
  • 5+ years of hands-on experience with SASE, SSE, Zero Trust, or cloud-delivered security platforms.
  • Extensive hands-on experience administering and engineering Netskope solutions within a large enterprise environment.
  • Strong understanding of: 
    • Secure Web Gateway (SWG)
    • Cloud Access Security Broker (CASB)
    • Zero Trust Network Access (ZTNA)
    • Data Loss Prevention (DLP)
    • Secure Service Edge (SSE)
    • Network Security and TCP/IP
    • DNS, Routing, Proxy Technologies, and TLS Inspection
  • Experience integrating identity providers such as Microsoft Entra ID, Okta, Ping Identity, or equivalent platforms.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent communication skills with the ability to influence technical and non-technical stakeholders.

 

Preferred Qualifications

  • Experience with Netskope Private Access (NPA), Publisher, Borderless SD-WAN, and advanced policy management.
  • Experience with Zscaler Internet Access (ZIA) and/or Zscaler Private Access (ZPA).
  • Experience supporting large-scale endpoint deployments and enterprise remote access transformations.
  • Experience with AWS, Azure, or multi-cloud networking and security architectures.
  • Experience with automation and scripting using PowerShell, Python, REST APIs, or Infrastructure as Code methodologies.
  • Experience with Splunk, SIEM platforms, and security monitoring technologies.

 

Bonus Qualifications

  • Experience designing, deploying, or supporting Out-of-Band Management solutions.
  • Familiarity with Opengear, Lantronix or ZPE,  console servers, LTE failover technologies, and remote infrastructure recovery capabilities.
  • Experience supporting datacenter modernization, resiliency, and disaster recovery initiatives.

 

Hours & Work Schedule

  • Hours per Week: 40
  • Work Schedule: Monday – Friday
  • Hybrid work model based on business needs.

 

Pay Transparency 

 

‌The salary range for this position is $142,000 – $175,000 per year, plus an opportunity to earn additional incentive earnings (if applicable). Actual pay is based on various factors including, but not limited to, the budget, work location, and relevant skills and experience..

 

We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens’ paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits

 

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Equal Employment and Opportunity Employer

Job Applicant Data Privacy Policy

Background Check

Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.


Related finance jobs