Netskope Architect – Design & Implementation
AMroute LLC · United States · 3 wk ago
RemoteRemoteOTHRFull-time
About the role
We are seeking an experienced Netskope Architect to lead the architecture, design, deployment, and implementation of enterprise-wide Netskope Security Cloud solutions. The ideal candidate will have expertise in Security Service Edge (SSE), Zero Trust architecture, cloud security, and secure internet access. This role requires strong technical leadership, hands-on implementation experience, and the ability to deliver secure, scalable solutions for global enterprise environments.
Responsibilities
- Design and architect enterprise-wide Netskope Security Cloud solutions aligned with business and security requirements.
- Lead end-to-end implementation and deployment of Netskope Security Service Edge (SSE) solutions.
- Design, configure, and implement:
- Secure Web Gateway (SWG)
- Cloud Access Security Broker (CASB)
- Zero Trust Network Access (ZTNA)
- Data Loss Prevention (DLP)
- Private Access
- Cloud Firewall
- Remote Browser Isolation (RBI) (preferred)
- Conduct discovery workshops and gather business, technical, and security requirements.
- Develop high-level and low-level solution designs, implementation plans, and migration strategies.
- Lead migrations from legacy proxy and security platforms (Blue Coat, Zscaler, Cisco Umbrella, Palo Alto Prisma Access, Forcepoint, etc.) to Netskope.
- Configure steering policies, security policies, traffic management, SSL inspection, and authentication mechanisms.
- Integrate Netskope with enterprise identity providers including Microsoft Entra ID (Azure AD), Okta, Active Directory, SAML, OAuth, and SCIM.
- Integrate with SIEM and SOAR platforms such as Splunk, Microsoft Sentinel, QRadar, and other security monitoring solutions.
- Design and implement DLP policies to protect sensitive data across SaaS, web, and private applications.
- Perform troubleshooting, root cause analysis, performance tuning, and optimization of Netskope deployments.
- Collaborate with network, cloud, endpoint, and security teams throughout project delivery.
- Produce architecture documentation, deployment guides, operational runbooks, and knowledge transfer documentation.
- Provide technical leadership, mentor engineers, and support operational teams after implementation.
Requirements
- 7+ years of experience in Cybersecurity, Network Security, Cloud Security, or Security Engineering.
- Minimum 3+ years of hands-on experience implementing and architecting Netskope Security Cloud solutions.
- Strong experience designing and deploying:
- Netskope Secure Web Gateway (SWG)
- CASB
- ZTNA
- DLP
- Private Access
- Cloud Firewall
- Strong understanding of Security Service Edge (SSE) and Zero Trust architecture.
- Experience with Microsoft 365, Azure, AWS, and Google Cloud Platform.
- Strong networking fundamentals including:
- TCP/IP
- DNS
- HTTP/HTTPS
- SSL/TLS
- VPN
- Proxy technologies
- Routing and Network Security
- Experience integrating identity and authentication technologies including Microsoft Entra ID (Azure AD), Okta, Active Directory, SAML, OAuth, and SCIM.
- Experience with SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar.
- Strong troubleshooting, analytical, and problem-solving skills.
- Excellent communication and stakeholder management skills.
Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field. Equivalent professional experience will also be considered.
- Netskope certifications are strongly preferred, including one or more of the following:
- Netskope Certified Cloud Security Administrator (NCCSA)
- Netskope Certified Cloud Security Integrator (NCCSI)
- Netskope Certified Cloud Security Architect (Architect-level certification preferred)
- Microsoft Certified: Azure Security Engineer Associate
- AWS Certified Security - Specialty
Preferred Experience
- Enterprise cloud security transformation projects.
- Large-scale Netskope implementation and migration projects.
- SASE/SSE architecture and deployment.
- Secure Internet Access modernization initiatives.
- Cloud security governance and compliance.
- Endpoint security integration with Microsoft Defender, CrowdStrike, or SentinelOne.
- Infrastructure as Code (Terraform, Ansible) and automation using PowerShell or Python.
Skills
- Strong customer-facing and consulting skills.
- Excellent written and verbal communication.
- Ability to lead technical discussions and architecture reviews.
- Strong documentation and presentation skills.
- Ability to work independently and collaboratively in cross-functional teams.
- Proven ability to manage multiple priorities in a fast-paced environment.