Principal Network Engineer
Progressive Leasing · Utah, United States · 2 days ago
Full-time
About the role
The Principal Network Engineer will take ownership of the network that powers the business across a hybrid environment of AWS cloud and on-premise branch offices. This role is a work-from-home position and can be performed remotely anywhere in the continental US.
Responsibilities
- Own and operate our hybrid network end to end, spanning AWS cloud networking and the limited but critical on-premise branch and data center footprint, with a focus on standardization, reliability, and security
- Lead the technical evaluation and deployment of ZTNA and Secure Web Gateway (SWG) capabilities alongside Enterprise Architecture and Cyber Security, driving the organization’s transition from always-on VPN toward a Zero Trust access model
- Manage the Palo Alto environment, including VM-Series firewalls in AWS and Panorama-based policy management, the current GlobalProtect remote-access VPN (including contractor and third-party access groups and HIP checks), and east-west / ingress / egress inspection design
- Drive network infrastructure as code with Terraform as the core tool, building and evolving modular, reusable patterns so network changes are version-controlled, peer-reviewed, and repeatable rather than one-off manual edits
- Treat the network as a self-service platform: build the modules, guardrails, documentation, and tooling that let application and operations teams provision and troubleshoot their own connectivity, and make stepping in for one-off work the exception, not the norm
- Build observability, alerting, and redundancy into the network by default, instrumenting telemetry, logs, and SNMP into our observability stack (Dynatrace and Observe) so issues are caught early and the platform is resilient across regions and availability zones
- Set and enforce network standards across the organization, reduce configuration drift, and partner on the program to detect and alert on manual changes that bypass IaC
- Execute changes through our ServiceNow change-management process, including CAB review for significant changes, and participate in the support and on-call rotation
- Treat every one-off build or manual fix as a signal: either a defect in the platform to be fixed or a missing feature to be added, and close that gap so the work becomes self-service next time
- Use AI-assisted tools to accelerate troubleshooting, draft and improve runbooks, and reduce repetitive operational overhead, with a practical focus on where AI adds value in network operations
Requirements
- Strong, hands-on networking fundamentals across routing, switching, DNS, load balancing, NAT, and segmentation, in both cloud and on-premise contexts
- Proven ability to lead a ZTNA and Secure Web Gateway (SWG) evaluation and deployment (e.g., Zscaler, Netskope, Prisma Access, or comparable), owning the technical direction alongside Enterprise Architecture and Cyber Security as the organization moves from always-on VPN to a Zero Trust access model
- Strong AWS networking experience in a multi-account environment: VPC design, Transit Gateway, Direct Connect, Route 53, IPAM, NACLs and security groups, and VPC sharing patterns
- Practical infrastructure as code experience, with Terraform as the core tool (transferable experience from other IaC tools is acceptable) and a track record of replacing manual changes with version-controlled, peer-reviewed automation
- A platform mindset: experience building reusable modules, guardrails, and self-service capabilities so other teams can provision and troubleshoot without one-off engineering help
- Comfort coordinating and prioritizing a team’s delivery and keeping work on track while you focus on larger initiatives
- A strong instinct for observability, alerting, and redundancy, and experience instrumenting networks for monitoring and resilience
- Security-first thinking, including segmentation, least privilege, and secure connectivity patterns across hybrid environments
- Comfort operating in production with formal change management (CAB / ServiceNow) and on-call responsibility
- Scripting fluency (Python, Bash, or similar) for automation and operational tooling
- Comfort using AI tools (Claude, GitHub Copilot, or similar) to ramp on unfamiliar systems, write automation, and diagnose issues
Qualifications
- Breadth across cloud and network, plus the discipline to build a platform, matter more here than deep specialization in any single tool
Skills
- Strong hands-on networking fundamentals across routing, switching, DNS, load balancing, NAT, and segmentation, in both cloud and on-premise contexts
- Proven ability to lead a ZTNA and Secure Web Gateway (SWG) evaluation and deployment (e.g., Zscaler, Netskope, Prisma Access, or comparable)
- Strong AWS networking experience in a multi-account environment
- Practical infrastructure as code experience, with Terraform as the core tool
- A platform mindset: experience building reusable modules, guardrails, and self-service capabilities
- Comfort coordinating and prioritizing a team’s delivery and keeping work on track while you focus on larger initiatives
- A strong instinct for observability, alerting, and redundancy, and experience instrumenting networks for monitoring and resilience
- Security-first thinking, including segmentation, least privilege, and secure connectivity patterns across hybrid environments
- Comfort operating in production with formal change management (CAB / ServiceNow) and on-call responsibility
- Scripting fluency (Python, Bash, or similar) for automation and operational tooling
- Comfort using AI tools (Claude, GitHub Copilot, or similar) to ramp on unfamiliar systems, write automation, and diagnose issues
Benefits
- Competitive Compensation
- Full Health Benefits; Medical/Dental/Vision/Life Insurance + Paid Parental Leave
- Company-Matched 401(k)
- Paid Time Off + Paid Holidays + Paid Volunteer Hours
- Employee Resource Groups (Black Inclusion Group, Women in Leadership, PRIDE, Adelante)
- Employee Stock Purchase Program
- Tuition Reimbursement
- Charitable Gift Matching
- Job-required equipment and services
Pay
Competitive compensation based on experience and qualifications.
Schedule
This role is a work-from-home position and can be performed remotely anywhere in the continental US.