We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
Remote New

Technical Consultant - Network Security SASE

AHEAD
vision insurance, paid time off, 401(k)
United States
Sep 24, 2026
AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.
At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD.
We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.
We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.

We are seeking a Technical Consultant to deliver Secure Access Service Edge (SASE) and Security Service Edge (SSE) engagements for enterprise clients. This role covers a single technology pillar spanning four core platforms: Zscaler Internet Access and Private Access, Palo Alto Networks Prisma Access, Cisco Secure Access, and Netskope Security Cloud. Technical Consultants independently lead remote and on-site SASE/SSE deployment workstreams, configuring and operating Zero Trust architectures against a design produced by a Senior Technical Consultant or Principal Technical Consultant. This role owns hands-on configuration, testing, and knowledge transfer for assigned workstreams, contributes to client-facing documentation, and mentors junior engineers, while building deep expertise in one SASE/SSE platform as the foundation for advancement to Senior Technical Consultant.


Key Responsibilities - SASE & Zero Trust:

  • Configure and deploy Zscaler Internet Access (ZIA) components including Secure Web Gateway policy, SSL inspection, URL filtering, cloud firewall rules, and sandbox policy against an established design.
  • Configure and deploy Zscaler Private Access (ZPA) application segments, App Connectors, and browser-based access for Zero Trust remote access.
  • Configure Palo Alto Prisma Access GlobalProtect remote user connectivity, explicit proxy setup for branch offices, and service connections to on-premises infrastructure through Strata Cloud Manager or Panorama.
  • Configure Cisco Secure Access Zero Trust Network Access, Secure Web Gateway, Cloud Access Security Broker, and resource connector deployment for private application access.
  • Configure Netskope Security Cloud Next Gen SWG, CASB (API-enabled and inline), and Netskope Private Access traffic steering and policy enforcement.
  • Implement traffic forwarding methods including GRE tunnels, IPsec tunnels, PAC files, and client connectors according to the design provided by the engagement architect.
  • Configure identity-based access controls integrating with Okta, Microsoft Entra ID, SAML 2.0, and SCIM provisioning to enforce conditional access policy across SASE/SSE platforms.
  • Deploy and tune Cloud Access Security Broker and Data Loss Prevention policy in inline and API-based modes under established policy guidelines.
  • Execute platform health checks, policy tuning, and day-2 operational tasks across assigned SASE/SSE platforms.
  • Support SASE and SD-WAN convergence testing, validating policy consistency across direct internet access and backhauled traffic paths.
  • Contribute platform-specific input to client Zero Trust maturity roadmaps under the direction of the engagement lead.

Architecture, Delivery & Documentation:

  • Participate in client-facing discovery sessions and design workshops, gathering requirements and validating current-state configuration for SASE/SSE scope.
  • Contribute to High-Level Design and Low-Level Design documentation, network diagrams, and as-built documentation for assigned SASE/SSE workstreams.
  • Execute migration and cutover tasks according to documented runbooks, rollback procedures, and change management workflows.
  • Support knowledge transfer sessions, training client operations teams on day-2 SASE/SSE platform administration.
  • Track assigned workstream milestones and escalate risks or scope changes to the project lead or Senior Technical Consultant.
  • Identify client requests that fall outside the documented scope and escalate to the project manager or engagement lead before delivery impact occurs.

Practice Contribution:

  • Mentor Associate and Senior Associate Technical Consultants on SASE/SSE platform fundamentals and troubleshooting techniques.
  • Contribute to reusable delivery assets including configuration checklists, runbook templates, and knowledge base articles for the SASE/SSE practice.
  • Pursue certification progression toward professional-level SASE/SSE credentials in the platform of primary focus.
  • Support sales campaigns by validating technical scope and providing delivery continuity input to the account team, under the direction of the engagement Solutions Lead.

Required Qualifications:

  • 3 to 5 years of network security, infrastructure security, or security engineering experience, including client-facing or internal project delivery experience.
  • Production experience configuring at least one of the following SASE/SSE platforms: Zscaler (ZIA and ZPA), Palo Alto Prisma Access, Cisco Secure Access, or Netskope Security Cloud.
  • Working knowledge of Zero Trust architecture principles, Secure Web Gateway, CASB, and ZTNA concepts across the broader SASE/SSE platform landscape.
  • Understanding of identity and access management integration (Okta, Microsoft Entra ID, SAML 2.0, SCIM) with SASE/SSE policy enforcement.
  • Familiarity with routing and connectivity fundamentals (BGP, OSPF, IPsec, GRE) sufficient to implement traffic forwarding designs provided by an architect.
  • Ability to produce clear technical documentation and communicate configuration status and issues to both technical and non-technical stakeholders.
  • Ability to travel at least 25 percent.

Preferred Qualifications:

  • Zscaler Digital Transformation Administrator (ZDTA); Palo Alto Networks Security Service Edge (SSE) Engineer certification; Cisco Certified Specialist - Secure Cloud Access; Netskope Certified Cloud Security Administrator (NCCSA).
  • CompTIA Security+, CCNA, or equivalent foundational networking or security certification.
  • Production experience with a second SASE/SSE platform beyond the primary area of focus.
  • Exposure to CASB and DLP policy tuning in inline or API-based deployment modes.
  • Prior consulting, professional services, or managed services experience.
  • Experience with cloud platforms (AWS VPC, Azure VNet) sufficient to support hybrid SASE/SSE connectivity designs.

Expectations:

  • Independently leads remote and on-site SASE/SSE deployment workstreams within an established design.
  • Operates with limited supervision on moderately complex configuration and troubleshooting tasks.
  • Builds deep expertise in one SASE/SSE platform as the primary specialty, with working knowledge across the broader practice.
  • Mentors junior engineers and contributes to SASE/SSE practice enablement content.
  • Clearly articulates the scope of assigned work and how it supports the engagement's business objectives.
  • Proactively raises schedule or scope concerns to the project lead or Senior Technical Consultant.
  • Identifies out-of-scope client requests and escalates before delivery impact occurs.
  • Carries a 70 percent target utilization.

Soft Skills:

  • Clear written and verbal communication skills, with the ability to produce client-ready configuration and status documentation.
  • Ability to manage assigned workstream timelines and communicate progress within a consulting delivery model.
  • Self-directed and detail-oriented, comfortable operating on-site at client facilities or in a remote delivery capacity.
  • Collaborative approach to working with senior engineers, project leads, and cross-functional delivery teams.
  • Receptive to mentorship and structured skill development, with an active interest in advancing technical depth.

The compensation range indicated in this posting reflects the On-Target Earnings ("OTE") for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate's relevant experience, qualifications, and geographic location.
Why AHEAD:
Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.
We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.
USA Employment Benefits include:
- Medical, Dental, and Vision Insurance
- 401(k)
- Paid company holidays
- Paid time off
- Paid parental and caregiver leave
- Plus more! See benefits https://www.aheadbenefits.com/ for additional details.
Use of AI:
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, or to capture recordings and create transcriptions or summaries during interviews. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.
If you would like more information about how your data is processed, please refer to the Candidate Privacy Notice or contact us at privacy@ahead.com.
You may opt-out of the review or analysis of your application and resume by AI tools by using the General Application. Please include the role you wish to apply for in the Additional Information field. You may also choose to opt-out of recording and transcription at any time, including after joining an interview. Candidates will not be penalized for choosing to opt-out.
Applied = 0

(web-9db6c7984-kcqxd)