P1C3TSTSskilled and proactive Web Security Proxy Engineer to design, implement, and maintain secure web access infrastructure across the enterprise. This role focuses on managing web proxy solutions, enforcing internet usage policies, and protecting users from web-based threats. The ideal candidate will have deep expertise in proxy technologies, secure web gateways, and threat intelligence integration.Engineer Proxy Infrastructure: Design, deploy, configure, and maintain enterprise-grade web proxies, Secure Web Gateways (SWG), and reverse proxy environments globally.
Manage SASE & SSE Platforms: Oversee cloud-delivered proxy solutions and secure edge architectures (e.g., Zscaler, Broadcom/Symantec, Netskope, Cloudflare) across distributed offices and remote workers.Optimize Policy & Routing: Develop, test, and tune complex web filtering rules, URL categorization, SSL/TLS decryption policies, and explicit/transparent proxy routing behaviors (including PAC file management).Lead Threat Prevention: Fine-tune proxy inline protections, combining advanced threat protection (ATP), browser isolation, sandboxing, and Data Loss Prevention (DLP) engines to block malicious web payloads.Troubleshoot Complex Traffic: Perform deep-dive network diagnostic analysis using tools like Wireshark, tcpdump, and Fiddler to resolve intricate SSL/TLS handshake failures, HTTP/2 or HTTP/3 issues, and routing anomalies.Automate Operations: Write scripts to automate infrastructure deployment, bulk policy changes, and configuration backups using Infrastructure as Code (e.g., Terraform) or scripting languages (e.g., Python, Bash).
Monitor & Report: Design comprehensive logging dashboards and alerts via SIEM platforms (e.g., Splunk) to track proxy health, capacity constraints, and anomalous web traffic patterns.Deep Proxy & Gateway Expertise: Proven hands-on engineering experience managing leading web proxy solutions (e.g., Zscaler Internet Access, Symantec ASG/ProxySG, Squid, F5 BIG-IP ASM/APM).Strong Network Protocols Knowledge: Mastery of network and application layer protocols, specifically HTTP/HTTPS, TCP/IP, DNS, SSL/TLS certificates, and authentications like SAML, Kerberos, or OIDC.