Sr. Network Automation Engineer (Rahoof)
About the role
Netskope stands as the foremost leader in Security Service Edge (SSE), establishing the benchmark for how modern enterprises secure access across cloud, web, and private applications. The platform is trusted by more than 4,000 organizations worldwide, including 30+ of the Fortune 100, providing Zero Trust Network Access, Cloud Access Security Broker, and Secure Web Gateway capabilities through a single-pass, cloud-native architecture.
This expansive infrastructure consists of hundreds of Points of Presence across every major region, hundreds of BGP sessions spanning internet exchanges, transit providers, and direct peering partners, and a robust multi-vendor stack of routers, switches, firewalls, and load balancers that enterprises trust with their most security-critical traffic.
The platform delivers:
- 99.999% availability with guaranteed low-latency performance for enterprise customers worldwide
- Hundreds of globally distributed Points of Presence providing best-path routing and regional redundancy
- Hundreds of BGP peering, transit, and internet exchange relationships managed and optimized continuously
- A multi-vendor network infrastructure (Cisco, Juniper, Arista, F5, Palo Alto) spanning data centers across every major region
- GTM and GSLB-driven traffic management ensuring seamless failover and performance at global scale
- Strict RTO and RPO objectives with zero-downtime change execution across a live production network
- Continuous capacity expansion as Netskope grows into new markets and enterprise segments
Responsibilities
Configure, maintain, and troubleshoot routers and switches across a multi-vendor environment — Cisco IOS/NX-OS, Juniper Junos, and Arista EOS
Manage BGP peering sessions with transit providers, internet exchanges, and direct peering partners; tune route policy, path selection, and prefix filtering to optimize performance and cost across hundreds of sessions
Install and configure new ISP transit links; manage circuit turn-up, capacity monitoring, and provider coordination globally
Configure and maintain firewalls including rulesets, NAT policies, zone-based security, and periodic policy audit and cleanup
Configure and manage load balancers including GTM/GSLB components, virtual servers, health monitors, persistence profiles, and SSL offload for multi-region traffic management
Maintain network health continuously — reviewing dashboards and utilization trends, identifying degradation patterns, and acting proactively before issues escalate to customer impact
Upgrade software on production routers, switches, firewalls, and load balancers with minimal disruption; plan and execute changes with documented rollback procedures
Configure and maintain IPsec/IKE VPN tunnels across the global PoP footprint
Perform packet captures and traffic analysis to diagnose issues and support incident investigations
Troubleshoot problems from the network layer through the application layer, own root cause analysis, and drive permanent remediations
Build and extend monitoring tools and dashboards to improve visibility into network performance and availability across all regions
Use BGP policies and traffic engineering to minimize latency to customers, balance load across providers, and manage congestion across internet exchange relationships
Requirements
7+ years of hands-on network engineering experience in production internet-facing data center or SaaS environments
Multi-vendor routing and switching expertise — Cisco, Juniper, and Arista; comfortable configuring and troubleshooting across all three in production
Expert-level BGP — peering and transit configurations, route policy design, path optimization, and troubleshooting for IPv4 and IPv6 at scale
Firewall operations experience in production environments — Juniper SRX, Palo Alto, Cisco ASA/FTD, or equivalent
Load balancer and GTM/GSLB experience — F5 BIG-IP, Citrix ADC, or equivalent; virtual server management, health monitoring, global traffic management across multiple regions
Strong L2 through L7 protocol knowledge — spanning-tree, LACP, MLAG, VLANs, BGP, OSPF, DNS, NTP, SNMP, SSH, Syslog, HTTP/S, SSL/TLS
Experience with network monitoring platforms and dashboard tooling; ability to read utilization trends and build meaningful alert thresholds
Proficiency with packet capture and traffic analysis tools (Wireshark, tcpdump)
Solid Linux experience including basic scripting
Background in KVM/ESXI hypervisor networking
Strong documentation habits — change records, runbooks, architecture diagrams, and post-incident write-ups
Prior experience in a public-facing SaaS, cloud, or internet infrastructure environment strongly preferred
BSCS or equivalent required, MSCS or equivalent strongly preferred
Qualifications
$111,000—$225,500 USD