Summary
AHEAD builds platforms for digital business by combining cloud infrastructure, automation, analytics, and software delivery to support enterprise digital transformation. The Technical Consultant will independently deliver remote and on-site SASE/SSE engagements, configuring Zero Trust platforms, executing deployment and migration workstreams, producing documentation, supporting knowledge transfer, and mentoring junior engineers.
Responsibilities
- Configure and deploy Zscaler Internet Access (ZIA) components including Secure Web Gateway policy, SSL inspection, URL filtering, cloud firewall rules, and sandbox policy against an established design
- Configure and deploy Zscaler Private Access (ZPA) application segments, App Connectors, and browser-based access for Zero Trust remote access
- Configure Palo Alto Prisma Access GlobalProtect remote user connectivity, explicit proxy setup for branch offices, and service connections to on-premises infrastructure through Strata Cloud Manager or Panorama
- Configure Cisco Secure Access Zero Trust Network Access, Secure Web Gateway, Cloud Access Security Broker, and resource connector deployment for private application access
- Configure Netskope Security Cloud Next Gen SWG, CASB (API-enabled and inline), and Netskope Private Access traffic steering and policy enforcement
- Implement traffic forwarding methods including GRE tunnels, IPsec tunnels, PAC files, and client connectors according to the design provided by the engagement architect
- Configure identity-based access controls integrating with Okta, Microsoft Entra ID, SAML 2.0, and SCIM provisioning to enforce conditional access policy across SASE/SSE platforms
- Deploy and tune Cloud Access Security Broker and Data Loss Prevention policy in inline and API-based modes under established policy guidelines
- Execute platform health checks, policy tuning, and day-2 operational tasks across assigned SASE/SSE platforms
- Support SASE and SD-WAN convergence testing, validating policy consistency across direct internet access and backhauled traffic paths
- Contribute platform-specific input to client Zero Trust maturity roadmaps under the direction of the engagement lead
- Participate in client-facing discovery sessions and design workshops, gathering requirements and validating current-state configuration for SASE/SSE scope
- Contribute to High-Level Design and Low-Level Design documentation, network diagrams, and as-built documentation for assigned SASE/SSE workstreams
- Execute migration and cutover tasks according to documented runbooks, rollback procedures, and change management workflows
- Support knowledge transfer sessions, training client operations teams on day-2 SASE/SSE platform administration
- Track assigned workstream milestones and escalate risks or scope changes to the project lead or Senior Technical Consultant
- Identify client requests that fall outside the documented scope and escalate to the project manager or engagement lead before delivery impact occurs
- Mentor Associate and Senior Associate Technical Consultants on SASE/SSE platform fundamentals and troubleshooting techniques
- Contribute to reusable delivery assets including configuration checklists, runbook templates, and knowledge base articles for the SASE/SSE practice
- Pursue certification progression toward professional-level SASE/SSE credentials in the platform of primary focus
- Support sales campaigns by validating technical scope and providing delivery continuity input to the account team, under the direction of the engagement Solutions Lead
Skills
- 3 to 5 years of network security, infrastructure security, or security engineering experience, including client-facing or internal project delivery experience
- Production experience configuring at least one of the following SASE/SSE platforms: Zscaler (ZIA and ZPA), Palo Alto Prisma Access, Cisco Secure Access, or Netskope Security Cloud
- Working knowledge of Zero Trust architecture principles, Secure Web Gateway, CASB, and ZTNA concepts across the broader SASE/SSE platform landscape
- Understanding of identity and access management integration (Okta, Microsoft Entra ID, SAML 2.0, SCIM) with SASE/SSE policy enforcement
- Familiarity with routing and connectivity fundamentals (BGP, OSPF, IPsec, GRE) sufficient to implement traffic forwarding designs provided by an architect
- Ability to produce clear technical documentation and communicate configuration status and issues to both technical and non-technical stakeholders
- Ability to travel at least 25 percent
- Clear written and verbal communication skills, with the ability to produce client-ready configuration and status documentation
- Ability to manage assigned workstream timelines and communicate progress within a consulting delivery model
- Self-directed and detail-oriented, comfortable operating on-site at client facilities or in a remote delivery capacity
- Collaborative approach to working with senior engineers, project leads, and cross-functional delivery teams
- Receptive to mentorship and structured skill development, with an active interest in advancing technical depth
- Zscaler Digital Transformation Administrator (ZDTA); Palo Alto Networks Security Service Edge (SSE) Engineer certification; Cisco Certified Specialist – Secure Cloud Access; Netskope Certified Cloud Security Administrator (NCCSA)
- CompTIA Security+, CCNA, or equivalent foundational networking or security certification
- Production experience with a second SASE/SSE platform beyond the primary area of focus
- Exposure to CASB and DLP policy tuning in inline or API-based deployment modes
- Prior consulting, professional services, or managed services experience
- Experience with cloud platforms (AWS VPC, Azure VNet) sufficient to support hybrid SASE/SSE connectivity designs
Qualifications
Must Haves
- 3 to 5 years of network security, infrastructure security, or security engineering experience, including client-facing or internal project delivery experience
- Production experience configuring at least one of the following SASE/SSE platforms: Zscaler (ZIA and ZPA), Palo Alto Prisma Access, Cisco Secure Access, or Netskope Security Cloud
- Working knowledge of Zero Trust architecture principles, Secure Web Gateway, CASB, and ZTNA concepts across the broader SASE/SSE platform landscape
- Understanding of identity and access management integration (Okta, Microsoft Entra ID, SAML 2.0, SCIM) with SASE/SSE policy enforcement
- Familiarity with routing and connectivity fundamentals (BGP, OSPF, IPsec, GRE) sufficient to implement traffic forwarding designs provided by an architect
- Ability to produce clear technical documentation and communicate configuration status and issues to both technical and non-technical stakeholders
- Ability to travel at least 25 percent
- Clear written and verbal communication skills, with the ability to produce client-ready configuration and status documentation
- Ability to manage assigned workstream timelines and communicate progress within a consulting delivery model
- Self-directed and detail-oriented, comfortable operating on-site at client facilities or in a remote delivery capacity
- Collaborative approach to working with senior engineers, project leads, and cross-functional delivery teams
- Receptive to mentorship and structured skill development, with an active interest in advancing technical depth
Nice to Haves
- Zscaler Digital Transformation Administrator (ZDTA); Palo Alto Networks Security Service Edge (SSE) Engineer certification; Cisco Certified Specialist – Secure Cloud Access; Netskope Certified Cloud Security Administrator (NCCSA)
- CompTIA Security+, CCNA, or equivalent foundational networking or security certification
- Production experience with a second SASE/SSE platform beyond the primary area of focus
- Exposure to CASB and DLP policy tuning in inline or API-based deployment modes
- Prior consulting, professional services, or managed services experience
- Experience with cloud platforms (AWS VPC, Azure VNet) sufficient to support hybrid SASE/SSE connectivity designs
Benefits
- Remote delivery capacity
- Cross-department training and development
- Sponsoring certifications and credentials for continued learning
- Medical, Dental, and Vision Insurance
- 401(k)
- Paid company holidays
- Paid time off
- Paid parental and caregiver leave