Senior Zero Trust Network Access (ZTNA) Engineer- Arlington, VA
Arlington, TX - USA
Job Summary
Job Description
Overview
CoStar Group (CSGP) is a leading global provider of commercial and residential real estate information analytics and online marketplaces. Included in the S&P 500 Index CoStar Group is on a mission to digitize the worlds real estate empowering all people to discover properties insights and connections that improve their businesses and lives.
We have been living and breathing the world of real estate information and online marketplaces for over 35 years giving us the perspective to create truly unique and valuable offerings to our customers. Weve continually refined transformed and perfected our approach to our business creating a language that has become standard in our industry for our customers and even our competitors. We continue that effort today and are always working to improve and drive innovation. This is how we deliver for our customers our employees and investors. By equipping the brightest minds with the best resources available we provide an invaluable edge in real estate.
This Senior Zero Trust Network Access (ZTNA) Engineer role will augment CoStars zero-trust engineering teams providing expertise in the architecture implementation operation and continuous improvement of the companys cloud-delivered ZTNA and Security Service Edge (SSE) platforms. This role will directly support CoStars global population of 9000 employees by helping to provide secure reliable and high-performing access to enterprise resources.
Our team is seeking a Senior Zero Trust Network Access Engineer who combines deep expertise in modern secure access technologies with advanced network troubleshooting skills. This is not solely a ZTNA platform administration role. The successful candidate must understand end-to-end network behavior and independently diagnose complex connectivity authentication routing DNS performance and application-access issues across endpoints enterprise networks cloud security platforms identity providers and applications. This engineer will be a hands-on technical leader who owns critical services from design through production operations leads difficult troubleshooting efforts and drives solutions that help the company scale.
This position is in Arlington VA and offers a schedule of Monday through Thursday in office with the option to work from home on Friday.
Responsibilities
- Design deploy configure operate and optimize enterprise Zero Trust Network Access (ZTNA) and Security Service Edge (SSE) platforms such as Zscaler Netskope Cloudflare Palo Alto Prisma Access or Cisco Secure Access.
- Design and manage ZTNA security and access policies including traffic steering application segmentation policy evaluation access controls and performance optimization.
- Lead migrations from traditional VPN on-premises security architectures and other ZTNA or SaaS solutions to modern cloud-delivered ZTNA platforms while maintaining secure and reliable access.
- Serve as a senior technical escalation point for complex connectivity authentication routing application-access and performance issues.
- Lead cross-domain troubleshooting across endpoints DNS routing NAT proxies firewalls identity providers ZTNA and SSE services cloud networks and enterprise applications.
- Perform packet-level and session-level analysis using tools such as Wireshark TCPDump platform logs flow records endpoint telemetry and digital experience monitoring data.
- Diagnose TCP/IP DNS DHCP TLS MTU and MSS fragmentation asymmetric routing proxy firewall-session tunnel and application-performance issues across end-to-end traffic paths.
- Troubleshoot advanced ZTNA and SSE components and features including PAC files GRE and IPsec tunnels App Connectors Client Connectors Branch Connectors private access internet access log streaming services digital experience monitoring and platform configurations.
- Lead technical response during high-impact incidents coordinating troubleshooting across network security endpoint identity cloud and application teams.
- Monitor platform health performance availability logs security events and user experience; proactively identify issues and drive remediation.
- Integrate ZTNA platforms with enterprise identity providers and security platforms including Entra ID Okta multifactor authentication services and SIEM solutions.
- Own technical designs and implementation standards for ZTNA connectivity traffic steering private application access internet access branch connectivity and service resilience.
- Lead architecture reviews proofs of concept technical evaluations technology refreshes security migrations root-cause analyses and corrective-action planning.
- Create and maintain architecture diagrams engineering standards standard operating procedures deployment guides runbooks and incident and change records.
- Automate operational monitoring and reporting tasks using PowerShell Python and other infrastructure automation tools.
- Collaborate with network security systems cloud operations and compliance teams to strengthen the organizations security posture and service reliability.
- Provide technical guidance design reviews and troubleshooting mentorship to other engineers while staying current with ZTNA SSE networking identity and cloud security technologies.
Basic Qualifications
- Bachelors Degree required from an accredited not-for-profit in-person university or college.
- A track record of commitment to prior employers.
- 7 years of progressive experience in enterprise networking network security engineering or related infrastructure engineering roles.
- 3 years of hands-on experience implementing operating and supporting one or more enterprise ZTNA or SSE platforms such as Zscaler Netskope Cloudflare Palo Alto Prisma Access or Cisco Secure Access.
- Strong experience supporting globally distributed endpoints users applications and networks within a large enterprise.
- Expert-level knowledge of TCP/IP DNS DHCP routing NAT TLS proxies VPN technologies firewalls and application traffic flows.
- Proven ability to use packet captures flow data routing tables firewall sessions endpoint telemetry and platform logs to isolate complex connectivity and performance problems.
- Experience troubleshooting across networking identity endpoint cloud security-platform and application domains.
- Experience leading Tier-3 incident response and root-cause analysis for business-critical services.
- Experience independently designing and implementing highly available enterprise network or security services.
- Strong analytical problem-solving documentation and communication skills.
- Ability to clearly communicate technical findings risk and remediation plans to engineering teams and technology leadership.
- Ability to independently own services and projects from technical design through implementation production support and continuous improvement.
Preferred Qualifications and Skills
- Subject matter expertise in one or more enterprise ZTNA or SSE platforms including Zscaler Netskope Cloudflare Palo Alto Prisma Access or Cisco Secure Access.
- Hands-on experience leading enterprise-scale migrations between ZTNA or SSE platforms or from legacy VPN and on-premises solutions.
- Experience integrating ZTNA platforms with Entra ID Okta multifactor authentication services SIEM solutions and other enterprise security tooling.
- Strong proficiency in scripting and automation using PowerShell or Python.
- Experience supporting cloud networking environments in Azure AWS or Google Cloud Platform.
- Experience leading major-incident root-cause analysis and remediation efforts.
- Ability to create clear architecture diagrams operational procedures technical standards incident analyses and recommendations for engineering and leadership audiences.
- Relevant industry or vendor certifications such as Zscaler ZCCA or ZCCP Netskope NCCSA or NCCSP Palo Alto PCNSE Cisco CCNP Enterprise or CCNP Security or Microsoft Certified: Azure Network Engineer Associate.
Whats in it for You
When you join CoStar Group youll experience a collaborative and innovative culture working alongside the best and brightest to empower our people and customers to offer you generous compensation and performance-based incentives. CoStar Group also invests in your professional and academic growth with internal training and tuition reimbursement.
Our benefits package includes (but is not limited to):
- Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
- Life legal and supplementary insurance
- Virtual and in person mental health counseling services for individuals and family
- Commuter and parking benefits
- 401(K) retirement plan with matching contributions
- Employee stock purchase plan
- Paid time off
- Tuition reimbursement
- On-site fitness center and/or reimbursed fitness center membership costs (location dependent) with yoga studio Pelotons personal training group exercise classes
- Access to CoStar Groups Employee Resource Groups
- Complimentary gourmet coffee tea hot chocolate fresh fruit and other healthy snacks
The final salary or hourly rate offered for this role will fall within the range set forth below based on a variety of factors including but not limited to geographic location skills and competencies.
Base Compensation: $118000-$176000 Annually
We welcome all qualified candidates who are currently eligible to work full-time in the United States to apply. However please note that CoStar Group is not able to provide visa sponsorship for this position.
#LI-MC5
CoStar Group is an Equal Employment Opportunity Employer; we maintain a drug-free workplace and perform pre-employment substance abuse testing
Required Experience:
Senior IC
About Company
The most recommended lease management platform for office and retail tenant portfolios of commercial real estate.