Citizens logo

Principal SASE Engineer

Citizens

Westwood, MAHybridFull-time$142–175K/yrTracked 3w agoSeen in employer's feed 5 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$142–175K/yr
Location
Westwood, MAHybrid
Schedule
Full-time
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

Bachelor's degree

Job overview

Citizens is hiring a Principal SASE Engineer. At Citizens, the Principal SASE Engineer serves as a senior technical leader responsible for engineering, administration, and strategic evolution of the Secure Access Service Edge platform, focusing on Netskope, and partners across multiple teams to deliver secure, scalable access solutions aligned with Zero Trust strategy.

Key focus areas include Serve as the primary technical owner and subject matter expert for the enterprise Netskope platform, Design, deploy, and support Netskope services including SWG, CASB, ZTNA, DLP, Cloud Firewall, and SSE capabilities, and Lead implementation of Zero Trust access solutions and modernize remote access technologies.

Important skills include Netskope, Secure Web Gateway, Cloud Access Security Broker, Zero Trust Network Access, DLP, and Secure Service Edge. Preferred (not required): Publisher, Borderless SD-WAN, Advanced Policy Management, and Zscaler Internet Access.

Skills & qualifications

RequiredNice to have

Skills

NetskopeSecure Web GatewayCloud Access Security BrokerZero Trust Network AccessDLPSecure Service EdgeNetwork SecurityTCP/IPDNSRoutingProxy TechnologiesTLS InspectionMicrosoft Entra IDOktaPing IdentityAnalytical SkillsTroubleshootingProblem-SolvingCommunication SkillsPublisherBorderless SD-WANAdvanced Policy ManagementZscaler Internet AccessZscaler Private AccessAWSAzureMulti-Cloud NetworkingMulti-Cloud Security ArchitecturesPowerShellPythonREST APIsInfrastructure as CodeSplunkSIEM PlatformsSecurity Monitoring TechnologiesOut-of-Band Management SolutionsOpengearLantronixZPEConsole ServersLTE Failover TechnologiesRemote Infrastructure Recovery CapabilitiesDatacenter ModernizationResiliencyDisaster Recovery Initiatives

Qualifications

Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Engineering or Equivalent Experience8+ Years Network Engineering Experience8+ Years Security Engineering Experience8+ Years Infrastructure Engineering Experience5+ Years SASE Experience5+ Years SSE Experience5+ Years Zero Trust Experience5+ Years Cloud-Delivered Security Platforms ExperienceLarge Enterprise Netskope Solutions ExperienceLarge-Scale Endpoint Deployments ExperienceEnterprise Remote Access Transformations Experience

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Paid Time Off
Parental Leave

Full job description

Description

4 Days in the office from any of our locations in Johnston RI, Dallas TX, Nashville TN, Iselin NJ, Westwood or Medford MA, or Phoenix AZ and couple other locations

Role is not relocation eligible.

Principal SASE Engineer

Description

At Citizens, we're more than a bank. Here, you'll experience new things, create new opportunities, think beyond your role, and make an impact. While in this role, you'll serve as a senior technical leader responsible for the engineering, administration, and strategic evolution of our Secure Access Service Edge (SASE) platform, with a primary focus on Netskope.

As a Principal SASE Engineer, you will lead the design, implementation, and optimization of cloud-delivered security services that enable secure access for colleagues, applications, and customers. You will partner across Infrastructure, Cybersecurity, Network Engineering, Architecture, and Operations teams to deliver secure, scalable, and resilient access solutions aligned with the organization's Zero Trust strategy.

The ideal candidate will possess deep hands-on expertise with Netskope technologies, strong network and security engineering experience, and a demonstrated ability to lead large-scale enterprise deployments. Experience with Zscaler and Out-of-Band (OOB) Management solutions is highly desirable.

Primary Responsibilities

  • Serve as the primary technical owner and subject matter expert for the enterprise Netskope platform.

  • Design, deploy, and support Netskope services, including Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), Data Loss Prevention (DLP), Cloud Firewall, and related Security Service Edge (SSE) capabilities.

  • Lead the implementation of Zero Trust access solutions and initiatives focused on modernizing traditional remote access technologies.

  • Engineer scalable and secure access solutions supporting hybrid workforce, cloud connectivity, and enterprise applications.

  • Develop and maintain security policies, traffic steering configurations, access controls, and user experience optimization strategies.

  • Provide advanced troubleshooting and Tier III support for complex platform, network, and security incidents.

  • Collaborate with Cybersecurity, Identity & Access Management, Cloud Engineering, and Network teams to ensure secure infrastructure integration.

  • Evaluate emerging technologies and drive continuous improvement initiatives across the SASE and secure access landscape.

  • Develop operational procedures, technical standards, architecture documentation, and knowledge transfer materials.

  • Mentor engineers and provide technical leadership across security and infrastructure teams.

  • Participate in strategic planning, architecture reviews, and vendor evaluations.

Qualifications

Required Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or equivalent experience.

  • 8+ years of experience in Network Engineering, Security Engineering, Infrastructure Engineering, or related disciplines.

  • 5+ years of hands-on experience with SASE, SSE, Zero Trust, or cloud-delivered security platforms.

  • Extensive hands-on experience administering and engineering Netskope solutions within a large enterprise environment.

  • Strong understanding of:

  • Secure Web Gateway (SWG)

  • Cloud Access Security Broker (CASB)

  • Zero Trust Network Access (ZTNA)

  • Data Loss Prevention (DLP)

  • Secure Service Edge (SSE)

  • Network Security and TCP/IP

  • DNS, Routing, Proxy Technologies, and TLS Inspection

  • Experience integrating identity providers such as Microsoft Entra ID, Okta, Ping Identity, or equivalent platforms.

  • Strong analytical, troubleshooting, and problem-solving skills.

  • Excellent communication skills with the ability to influence technical and non-technical stakeholders.

Preferred Qualifications

  • Experience with Netskope Private Access (NPA), Publisher, Borderless SD-WAN, and advanced policy management.

  • Experience with Zscaler Internet Access (ZIA) and/or Zscaler Private Access (ZPA).

  • Experience supporting large-scale endpoint deployments and enterprise remote access transformations.

  • Experience with AWS, Azure, or multi-cloud networking and security architectures.

  • Experience with automation and scripting using PowerShell, Python, REST APIs, or Infrastructure as Code methodologies.

  • Experience with Splunk, SIEM platforms, and security monitoring technologies.

Bonus Qualifications

  • Experience designing, deploying, or supporting Out-of-Band Management solutions.

  • Familiarity with Opengear, Lantronix or ZPE, console servers, LTE failover technologies, and remote infrastructure recovery capabilities.

  • Experience supporting datacenter modernization, resiliency, and disaster recovery initiatives.

Hours & Work Schedule

  • Hours per Week: 40

  • Work Schedule: Monday – Friday

  • Hybrid work model based on business needs.

Pay Transparency

‌The salary range for this position is $142,000 – $175,000 per year, plus an opportunity to earn additional incentive earnings (if applicable). Actual pay is based on various factors including, but not limited to, the budget, work location, and relevant skills and experience. .

We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens’ paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits

Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Why Work for Us

At Citizens, you'll find a customer-centric culture built around helping our customers and giving back to our local communities. When you join our team, you are part of a supportive and collaborative workforce, with access to training and tools to accelerate your potential and maximize your career growth

Background Check

Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.

08/31/2026

You've read the whole posting — now see how you match it.