Staff Network Engineer
About the role
Snowflake's Enterprise Technology Network Services team is looking for a Staff Network Engineer to lead the design, operation, and optimization of our Zero Trust and secure-access platform. This role is Zscaler-centric — you will own the health, performance, and roadmap of our ZIA/ZPA deployment — while working across a modern, multi-cloud network stack that supports a global workforce of 10,000+ users. You'll be the escalation point for the most complex connectivity issues and a driver of automation and observability across the environment.
Responsibilities
- Own and operate the Zscaler platform (ZIA, ZPA, ZDX, ZCC) end-to-end, including policy frameworks, app-segmentation models, PAC/traffic-forwarding standards, App Connector topology, and NSS/log-streaming design.
- Troubleshoot secure-access incidents like tunnel flapping, broker/connector health, SSL inspection edge cases, DNS/DTLS failures, and lead root-cause analysis for systemic issues.
- Manage Palo Alto firewalls, Panorama and GlobalProtect VPN, while planning migration toward Zscaler solutions.
- Support Aruba (Central) Wireless, Ekahau and Cisco Catalyst switches globally.
- Design, install, and configure network devices and ISP circuits at new offices.
- Build automation and observability: leverage log analytics (we run our network telemetry through Snowflake) to create dashboards, alerting, and proactive detection.
- Troubleshoot secure Network constructs in AWS, Azure, and GCP such as NVAs, NSG, VPC, UDR, DirectConnect, ExpressRoute.
- Author technical runbooks, escalation procedures, and knowledge-base content.
- Participate in on-call rotations for the changes and lead responses to major network incidents.
- Travel internationally for short periods of time for site builds.
Requirements
- At least 10 years of enterprise network infrastructure experience, including 3+ years of hands-on Zscaler ZIA/ZPA design and deployment at scale.
- Recognized depth in Zero Trust / SASE architecture with expertise in ZTNA, proxy/SWG, SSL inspection, and cloud security.
- Hands-on Palo Alto (PAN-OS, GlobalProtect, Panorama) and enterprise VPN experience.
- Aruba wireless and Cisco LAN/WAN (routing, switching, 802.1x) fundamentals.
- Strong TCP/IP, DNS, DHCP, TLS/DTLS, BGP, and QoS troubleshooting skills.
- Multi-cloud (AWS/Azure/GCP) networking and site-to-cloud connectivity experience.
- Automation mindset: Python scripting, API config, and log observability (SQL/Snowflake a plus).
- Strong ITSM management, documentation, and communication skills.
Nice to Have
- Certifications: Zscaler (ZCCA-IA/PA, ZDTA), Palo Alto (PCNSE), Aruba (ACMA/ACMP), or Cisco (CCNA/CCNP).
- Experience migrating legacy VPNs (GlobalProtect) to ZPA.
- Familiarity with SASE and network-as-code/IaC (Terraform).
- Experience operating in high-growth SaaS or cloud-native environments.
Pay
The estimated base salary range for this role is $160,000 - $210,000. Additionally, this role is eligible to participate in Snowflake’s bonus and equity plan. The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.
Benefits
- Medical, dental, vision, life, and disability insurance
- 401(k) retirement plan
- Flexible spending & health savings account
- At least 12 paid holidays
- Paid time off
- Parental leave
- Employee assistance program
- Other company benefits
Schedule
- Participation in on-call rotations
- Occasional international travel for short periods