Network Security Engineer - SASE

Jobs.cargill.com

Apply to this job
Until 9/22/2026 5+ years exp First posted July 24, 2026 Last posted July 24, 2026
Job description

Job Purpose and Impact

The Network Engineer - SASE will implement, operate, automate, and continuously improve Cargill's global Secure Access Service Edge (SASE) and Security Service Edge (SSE) services. This role will support the migration from legacy web proxy and remote-access technologies to cloud-delivered security and will configure capabilities such as Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), and threat protection. The engineer will work within established architecture and collaborate with senior engineers and partner teams to deliver reliable and secure access for users, sites, and applications.

Key Accountabilities

  • Implement, configure, test, and support SASE and SSE capabilities in accordance with established architecture, security standards, and engineering practices.
  • Configure and maintain SWG policies, ZTNA application access, traffic steering, endpoint clients, tunnels, connectors, and related platform components.
  • Support migrations from legacy web proxy and VPN technologies through discovery, testing, deployment validation, cutover support, and post-implementation stabilization.
  • Monitor and troubleshoot connectivity, authentication, certificate, SSL/TLS inspection, performance, and application-access issues across hybrid and cloud environments.
  • Support integrations with identity, endpoint security, SIEM/XDR, cloud, and IT service management platforms.
  • Automate repeatable configuration, validation, reporting, and operational tasks using APIs, scripting, and infrastructure-as-code practices.
  • Maintain technical documentation, implementation records, low-level designs, operational runbooks, and knowledge articles.
  • Participate in Agile delivery, change management, incident and problem management, and continuous service improvement activities.
  • Collaborate with global network, security, identity, cloud, endpoint, and application teams and contribute recommendations that improve team-level engineering practices.
  • Other duties as assigned.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
  • Minimum of 3 years of relevant experience in network engineering, network security, cybersecurity engineering, or infrastructure operations.
  • Hands-on experience supporting enterprise network or security technologies, with exposure to SASE, SSE, SWG, ZTNA, cloud security, or secure remote-access solutions.
  • Strong understanding of enterprise networking fundamentals, including TCP/IP, routing, switching, DNS, DHCP, VPNs, SSL/TLS, certificates, and network security principles.
  • Experience troubleshooting connectivity, authentication, and application-access issues in enterprise environments.
  • Ability to create clear technical documentation and work effectively with geographically distributed engineering and operations teams.
  • 5+ years of experience supporting enterprise network or security solutions within a large-scale, distributed IT environment.
  • Hands-on experience with one or more leading SASE/SSE platforms, such as Netskope, Palo Alto Prisma Access, Zscaler Internet Access (ZIA), or Zscaler Private Access (ZPA).
  • Experience administering SWG capabilities, including URL filtering, SSL/TLS inspection, cloud application controls, malware protection, DLP, threat prevention, and policy enforcement.
  • Experience configuring ZTNA access to private applications and supporting initiatives that reduce reliance on traditional VPN technologies.
  • Familiarity with endpoint traffic steering, GRE/IPsec tunnels, private access connectors or publishers, dedicated egress, and high-availability designs.
  • Understanding of identity-driven security and integration with Microsoft Entra ID, Okta, Ping Identity, or similar identity providers using SAML, OAuth, OIDC, or SCIM.
About this role

Summary

Support, configure, and improve enterprise SASE, SSE, and cloud security solutions.

Job title

Network Security Engineer - SASE

Experience level

5+ years

Minimum experience

5+ years exp

Industry

software

Location requirements

Remote work possible, candidate must be within the region.

Salary

Not specified

Management role

No

Skills & keywords

Required skills

sasesseswgztnacloud securityssl/tlscertificates

Preferred skills

netskopepalo alto prisma accesszscaler ziazscaler zpasamloauth

Specializations

sasessenetwork securitycloud securityvpn
Locations

Structured locations inferred from the posting.

No structured locations extracted for this role yet.