Qualifications- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline preferred; an equivalent combination of education, training, and relevant experience will be considered in lieu of a degree.
- A minimum of 5 years of hands-on experience with SASE/ZTNA platforms in production enterprise environments
- Experience with the following technologies: ZTNA, SASE, CASB, SWG, SD-WAN, TLS/PKI, DNS and core networking/routing, SIEM, SOAR, EDR/device posture integration, SAML/OIDC/SCIM identity federation (Okta and/or Azure AD/Entra), IAM/conditional access, cloud (Azure, AWS), Linux, Windows.
- Experience with the following standards: NIST 800-53, NIST 800-171, CMMC, SOC 1/2, ISO 27001.
- Deep understanding of Zero Trust Network Access and Secure Access Service Edge models applied hands-on rather than at a conceptual level.
- Strong grasp of underlying network fundamentals (TLS/PKI, DNS, routing, TCP/IP) sufficient to troubleshoot below the vendor UI.
- Skilled in identity federation and conditional access policy design across SAML/OIDC/SCIM-based identity providers.
- Proficient in Python, PowerShell, or Bash to automate policy management, reporting, and compliance workflows.
- Working knowledge of NIST 800-53, NIST 800-171, and CMMC control families as they apply to access control.
- Extensive troubleshooting experience in regard to traffic decryption and certificate trusts
- Strong communication skills to work across identity, network, compliance, and leadership teams in both GCCH and Commercial contexts.
- Excellent analytical and problem-solving skills, with the ability to balance operational needs, user experience, and security/compliance risk.
- This position requires U.S. citizenship due to access requirements within the GCCH environment.
Preferred- Experience operating in both FedRAMP High/GCCH and Commercial environments
- Experience with scripting (Python, PowerShell, or Bash) for policy-as-code and automation highly desired.
- Possession of one or more industry-recognized certifications, such as a vendor-specific SASE/ZTNA certification (any major platform), CCNA, CCSP, or CISSP, is preferred but not required.
Certain states and localities require employers to post a reasonable estimate of the salary range. A reasonable estimate of the current base pay range for this position is $116,000 to $145,000 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that are not included in the base pay.
The well-being of WWT employees is essential. When it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:
- Health and Wellbeing: Health (Medical & Prescription), Dental, and Vision Care, Onsite Health Centers (MO & IL), Employee Assistance Program, Wellness program
- Financial Benefits: Competitive Pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Flexible Spending Accounts, Tuition Reimbursement
- Paid Time Off: PTO & Holidays, Parental Leave, Medical Leave, Military Leave, Bereavement, Day of Caring
- Additional Perks: Family Planning Benefits, Nursing Mothers Benefits, Voluntary Legal, Voluntary Supplemental Accident/Illness/Hospital, Voluntary ID Theft, Pet Insurance, Employee Discount Program
Note: This is not an all-encompassing list and should not be used as a complete description of the plan's benefits. For more information, see our US Benefits Website
The SASE/ZTNA Security Engineer designs, implements, and operates Zero Trust Network Access and Secure Access Service Edge architecture across WWT's GCCH and Commercial environments. This role owns ZTNA policy and identity-driven access architecture. Including session management, access policy design, and telemetry integration for compliance reporting.
This position requires U.S. citizenship due to access requirements within the GCCH environment.
Responsibilities- Design, implement, and operate ZTNA and SASE architecture, including access policy, session management, and steering/proxy configuration across both GCCH and Commercial environments.
- Own identity-driven access control integration, including conditional access policy design with SAML/OIDC/SCIM-based identity providers.
- Serve as the senior escalation point for complex ZTNA/SASE incidents, conducting root cause analysis and driving resolution.
- Utilize ZTNA/SASE session telemetry to support user access reviews, compliance reporting, and incident investigation.
- Map ZTNA/SASE controls to NIST 800-53 and CMMC control families (e.g., AC-17, AC-4, SC-7) and produce audit-ready evidence for GCCH and Commercial compliance requirements.
- Develop and maintain dashboards and KPIs that communicate ZTNA/SASE performance, access risk, and policy health to technical stakeholders.
- Build AI integrations and automations for reporting, routine tasks, and recurring compliance workflows, aligned with the broader security automation strategy.
- Collaborate with identity, network, and compliance teams to align ZTNA/SASE initiatives with business and regulatory needs across both operating environments.
- Evaluate and integrate SASE/ZTNA-adjacent technologies (device posture/EDR signal, SOAR-driven response workflows) with existing platforms.
- Mentor junior engineers on ZTNA/SASE architecture, troubleshooting, and secure access principles.
- Engage with external vendors and partners to evaluate and integrate SASE/ZTNA technologies.
- Maintain documentation, runbooks, and knowledge base articles for ZTNA/SASE operations and troubleshooting.