SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Snowflake's Enterprise Technology Network Services team is seeking a Staff Network Engineer to lead the design, operation, and optimization of the company's Zero Trust and secure-access platform. This role is Zscaler-centric, with ownership of the health, performance, and roadmap of ZIA/ZPA deployment across a modern, multi-cloud network stack supporting 10,000+ global users. You will serve as the escalation point for complex connectivity issues and drive automation and observability initiatives.
Key responsibilities include: end-to-end operation of the Zscaler platform (ZIA, ZPA, ZDX, ZCC) including policy frameworks, app-segmentation models, and App Connector topology; troubleshooting secure-access incidents such as tunnel flapping, broker/connector health, and SSL inspection edge cases; managing Palo Alto firewalls, Panorama, and GlobalProtect VPN while planning migration to Zscaler solutions; supporting Aruba Wireless and Cisco Catalyst switches globally; designing and configuring network devices and ISP circuits at new offices; building automation and observability using log analytics (leveraging Snowflake for network telemetry) to create dashboards and alerting; troubleshooting secure network constructs in AWS, Azure, and GCP; authoring technical runbooks and knowledge-base content; participating in on-call rotations; and traveling internationally for site builds.
Required qualifications: 10+ years of enterprise network infrastructure experience with 3+ years of hands-on Zscaler ZIA/ZPA design and deployment at scale; recognized expertise in Zero Trust/SASE architecture including ZTNA, proxy/SWG, SSL inspection, and cloud security; hands-on Palo Alto (PAN-OS, GlobalProtect, Panorama) and enterprise VPN experience; Aruba wireless and Cisco LAN/WAN fundamentals; strong TCP/IP, DNS, DHCP, TLS/DTLS, BGP, and QoS troubleshooting skills; multi-cloud networking experience; automation mindset with Python scripting and API configuration; and strong ITSM and documentation skills.
Nice-to-have qualifications include relevant certifications (Zscaler, Palo Alto, Aruba, Cisco), experience migrating legacy VPNs to ZPA, familiarity with network-as-code/IaC tools like Terraform, and experience in high-growth SaaS or cloud-native environments.