Legato Security
Network Security Engineer
Remote Office · Salt Lake City, Utah, United States
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Mid level
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 21 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Enter Job Title
Who We Are
Legato Security is an information security firm founded upon the belief that every organization has the right to keep its data private and secure. Our mission is to build close partnerships with our clients, serving them not as just a vendor, but as trusted advisors helping to build effective, proactive plans. Our focus is always on both the technical and human elements within an organization. We believe in comprehensive strategies designed to harden networks, deflect attackers, and rapidly recover from any accidents. As technology progresses, so do our tactics, ensuring our experts are always prepared to serve forward-looking leaders eager to stay ahead of emerging threats.
Position Overview
We are seeking a Network Security Engineer to join our Network team. This role will support the administration, implementation, troubleshooting, design, and ongoing improvement of our customers’ networks and security environments.
The ideal candidate will have hands-on experience with network security technologies such as firewalls, Zscaler, Netskope, VPNs, routing, switching, or related technologies. Extensive experience with every platform is not required, but a strong networking foundation, practical troubleshooting ability, good communication skills, and a willingness to continually learn are essential.
This position will work across a variety of operational and project-based activities, including customer requests, incidents, service tickets, troubleshooting, implementations, migrations, upgrades and changes, and technical projects. Because the role supports multiple customers and environments, the successful candidate must be able to communicate effectively, manage competing priorities, adapt to different technical requirements, and see issues through to resolution.
This position is hybrid and mostly remote in nature, but may require some time in office (Downtown Salt Lake City) for troubleshooting, updating, and replacing network equipment; client visits as required, etc. Some time on-call is required, but this will rotational and not extensive.
Specific Job Responsibilities
Support, administer, configure, and troubleshoot firewalls, Zscaler services, Netskope, VPN technologies, and related network security platforms, both internal and in customer environments
Work directly with customers to understand business and technical requirements, troubleshoot problems, evaluate potential solutions, and implement appropriate changes
Respond to and resolve service tickets, incidents, requests, and escalations involving network connectivity, firewalls, Zscaler, Netskope, and related technology
Serve as an escalation point for technical issues that require additional troubleshooting, analysis, or expertise beyond initial support
Support, configure, and troubleshoot firewall and network product environments to meet customer connectivity and security requirements
Participate in firewall, Zscaler, and Netskope implementation, migration, upgrade, replacement, and configuration projects.
Assist with the configuration and maintenance of Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, and related services
Assist with the configuration and maintenance of the Netskope One platform including SASE, SSE, CASB, SWG, Private Access, Cloud Firewall, SD-WAN, and more
Support Zscaler and Netskope policies including URL filtering, firewall policies, SSL inspection, authentication, access policies, application access, traffic forwarding, connectivity, routing, DNS, DHCP, NAT, VPNs, authentication, traffic forwarding, SSL/TLS inspection, application access, VLANs, switching technologies, and policy enforcement
Configure and troubleshoot VPN technologies including SSL VPN, IPsec, Remote Access VPN, and Site-to-Site VPN connections
Review firewall logs, Zscaler logs, Netskope logs, packet captures, routing tables, traffic flows, error messages, and other diagnostic information to determine root cause
Assist with customer onboarding and changes to existing customer network and security environments, testing and validation of new configurations, and other changes prior to production deployment
Create and maintain firewall documentation, configuration records, troubleshooting procedures, implementation notes, and customer-specific technical documentation.
Participate in incident response, problem management, and root-cause analysis activities as needed
Have the ability to manage multiple unresolved tickets, incidents, projects, and customer requests with assistance from other team members or technical resources as needed, both individually and in collaboration with team members
Assist engineers and analysts and with troubleshooting processes, technical methodologies, and network security best practices
Identify opportunities to improve network configurations, security controls, operational processes, troubleshooting methods, documentation, and customer experience
Maintain awareness of emerging networking and cybersecurity technologies, vendor platform changes, vulnerabilities, security capabilities, and industry best practices
Qualifications
Required Qualifications :
Hands-on experience with one or more network security technologies such as firewalls, Zscaler, Netskope, VPNs, secure web gateways, SSE/SASE platforms, proxies, or zero-trust technologies
Strong troubleshooting and analytical skills with the ability to methodically diagnose network and security issues
Working knowledge of routing concepts and protocols such as TCP/IP, BGP, OSPF, EIGRP, IS-IS, RIP, Static Routing, and SD-WAN
Working knowledge of LAN technologies including Ethernet switching, VLANs, Spanning Tree Protocol (STP), Port security, Link/port aggregation, and LAN and WAN architecture
Experience or familiarity with physical, virtual, and cloud firewall technologies
Understanding of firewall concepts including Security policies, zones and interfaces, objects and object groups, routing, NAT, VPNs, Application and Service policies, Logging, and traffic analysis
Knowledge or familiarity of VPN technologies including IPsec, SSL VPN, Remote Access VPN, and Site-to-Site VPN
Working knowledge of concepts including NAT (Source NAT, Destination NAT, and U-Turn/Hairpin NAT), DNS, and DHCP
Familiarity with authentication and identity technologies such as SAML, SSO, MFA, Active Directory, Entra ID, and SCIM
Ability to capture, analyze, and interpret network traffic using Wireshark or similar packet-analysis tools
Ability to interpret network and security logs, packet captures, routing information, error messages, and other diagnostic information
Ability to design and document network and related security solutions would be helpful
Strong customer-facing skills, including the ability to listen, evaluate requirements, ask appropriate questions, and clearly explain technical issues and solutions
Ability to communicate effectively with both technical and non-technical audiences
The ability to work both within a team environment and individual situations are required
Ability to work with multiple customers, environments, projects, incidents, and priorities simultaneously
Ability to manage time effectively and see incidents, requests, and technical issues through to resolution
Willingness and ability to learn new technologies and develop deeper expertise across networking and network security platforms
Preferred Qualifications :
Experience with one or more of the following technologies or disciplines is beneficial but not required:
Firewall and Network Security Platforms
Palo Alto Networks
Cisco ASA / Cisco Secure Firewall
Fortinet FortiGate
Check Point
Juniper SRX
SonicWall
Cisco Meraki
Sophos
WatchGuard
Microsoft Azure network security technologies
Amazon Web Services network security technologies
Zscaler Technologies
Similar jobs
- AI Security Engineer, AWS Security - AISecAmazon · Austin, Texas, USAFirst seen today
- Application Security EngineerAmazon · Arlington, Virginia, USAFirst seen today
- Information Systems Security Engineer (Active DOD Secret Clearance required)CompQsoft Inc. - ACTIVE · KITTERY, MEFirst seen today
- Software Product Security Engineer - HP IQHp · San Francisco, California, United States of AmericaFirst seen today
- Systems Security Engineer I – Anti-Tamper / Program Protection (On-site)Globalhr · US-AZ-TUCSON-801 ~ 1151 E Hermans Rd ~ BLDG 801 (External Site)First seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job