- Location
- GF Unit G01 and G02, , Block C4, Brigade Tech Gardens, ITPL Main Road, Brookefield, Kundalahalli, India
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Education
- Master
- Source
- Workday
Description
Job descriptions may display in multiple languages based on your language selection.
What we offer:
Group Summary:
Job Responsibilities:
Major Responsibilities
- Provide Level 3 engineering support for SSE services, including ZTNA, SWG, CASB, and DLP, with a focus on operational stability, secure policy enforcement, and user experience.
- Design, implement, review, and refine ZTNA access policies, SWG web controls, CASB SaaS controls, and DLP policies based on business requirements, risk, and least-privilege principles.
- Troubleshoot complex issues related to private application access, proxy behavior, SSL/TLS inspection, SaaS access, DLP policy enforcement, user authentication, endpoint client behavior, and traffic steering.
- Analyze logs, alerts, packet flows, policy matches, identity claims, and endpoint posture signals to identify root cause and drive sustainable fixes.
- Monitor and optimize performance for remote, office, and mobile users by reviewing traffic paths, SSE platform telemetry, policy impact, and application access patterns.
- Work with identity providers, endpoint security tools, network teams, security teams, application owners, and service desks to ensure reliable authentication, policy enforcement, and secure access.
- Support incident, problem, and change management activities, including RCA, permanent corrective actions, implementation planning, validation, and operational handover.
- Create and maintain technical documentation, troubleshooting guides, operational runbooks, policy standards, and knowledge articles for SSE and ZTNA services.
- Coach and mentor Level 2 resources on issue triage, log analysis, escalation quality, repeatable troubleshooting, and operational best practices.
- Collaborate with vendors and managed service providers to resolve advanced platform issues, validate product behavior, and evaluate relevant feature enhancements.
- Identify opportunities to improve policy governance, reporting, alerting, automation, and operational readiness across SSE services.
Required Qualifications & Skills:
- Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent work experience.
- 7+ years of experience in network security, network engineering, remote access, proxy, cloud security, or related infrastructure domains.
- Hands-on experience supporting SSE technologies, including ZTNA, SWG, CASB, and DLP, preferably with Netskope or comparable platforms such as Zscaler, Palo Alto Prisma Access, Cisco, Cloudflare, or Broadcom/Symantec.
- Strong working knowledge of ZTNA concepts, private application access, connector/publisher architecture, identity-based access controls, device posture, and least-privilege access models.
- Experience creating, tuning, and troubleshooting SWG, CASB, and DLP policies, including web categories, SSL/TLS inspection, SaaS controls, sensitive data detection, policy exceptions, and false positive analysis.
- Strong network fundamentals across LAN, WAN, TCP/IP, DNS, routing, NAT, firewalls, VPN, SD-WAN, proxy, certificates, and packet flow analysis.
- Ability to analyze platform logs, SIEM events, endpoint client behavior, authentication flows, and traffic steering outcomes to resolve complex incidents.
- Effective written and verbal communication skills, including the ability to explain technical issues, document decisions, coordinate changes, and work with global stakeholders.
- Demonstrated ability to coach, mentor, and guide Level 2 support resources through structured troubleshooting and knowledge transfer.
- Relevant certifications such as Netskope, Zscaler, CCNP, CCNP Security, Azure, cloud security, or CISSP are a plus.
Preferred Qualifications:
- Experience with identity providers such as Microsoft Entra ID, Okta, or Ping Identity, including SAML, OAuth, conditional access, MFA, and group-based policy assignment.
- Experience supporting SSE policy rollouts, user migrations, operational readiness, and change communication in a large enterprise environment.
- Familiarity with Microsoft 365, SaaS governance, cloud application risk, data protection controls, and DLP policy lifecycle management.
- Experience improving operational processes through runbooks, dashboards, automation, reporting, and recurring issue reduction.
Additional Information:
- This role requires working with global teams across multiple time zones.
- Candidate must participate in global on-call rotation roster.
- The candidate will provide Level 3 support and serve as senior technical resource for SSE/ZTNA, including guidance and mentoring for Level 2 support teams.
- Occasional travel may be required for key project implementations and strategy discussions.
If you are a seasoned network security engineer with hands-on SSE experience, strong ZTNA fundamentals, practical SWG, CASB, and DLP policy knowledge, and the ability to solve complex issues while guiding others, we encourage you to apply.
Awareness, Unity, Empowerment:
At Magna, we believe that a diverse workforce is critical to our success. That’s why we are proud to be an equal opportunity employer. We hire on the basis of experience and qualifications, and in consideration of job requirements, regardless of, in particular, color, ancestry, religion, gender, origin, sexual orientation, age, citizenship, marital status, disability or gender identity. Magna takes the privacy of your personal information seriously. We discourage you from sending applications via email or traditional mail to comply with GDPR requirements and your local Data Privacy Law.
AI-Assisted Screening Disclosure
As part of our commitment to a fair, consistent, and efficient recruitment process, we may use artificial intelligence (AI) tools to assist in the initial screening of applications submitted through our Workday system. These tools help identify qualifications and experience that align with the role requirements. Please note that AI is used solely to support our recruiters. Final decisions are always made by the hiring manager and the hiring team. Importantly, no applicant data is shared externally through these AI tools. All information remains securely within our systems and is handled in accordance with our privacy and data protection policies.
Under conditions defined by applicable law, you may have the right to request an explanation of how AI is used to support decision-making.
If you have any questions or concerns about this process, feel free to contact our Talent Attraction team.