Job descriptions may display in multiple languages based on your language selection.
What we offer:Job Responsibilities:
Major Responsibilities
- Provide Level 3 engineering support for SSE services, including ZTNA, SWG, CASB, and DLP, with a focus on operational stability, secure policy enforcement, and user experience.
- Design, implement, review, and refine ZTNA access policies, SWG web controls, CASB SaaS controls, and DLP policies based on business requirements, risk, and least-privilege principles.
- Troubleshoot complex issues related to private application access, proxy behavior, SSL/TLS inspection, SaaS access, DLP policy enforcement, user authentication, endpoint client behavior, and traffic steering.
- Analyze logs, alerts, packet flows, policy matches, identity claims, and endpoint posture signals to identify root cause and drive sustainable fixes.
- Monitor and optimize performance for remote, office, and mobile users by reviewing traffic paths, SSE platform telemetry, policy impact, and application access patterns.
- Work with identity providers, endpoint security tools, network teams, security teams, application owners, and service desks to ensure reliable authentication, policy enforcement, and secure access.
- Support incident, problem, and change management activities, including RCA, permanent corrective actions, implementation planning, validation, and operational handover.
- Create and maintain technical documentation, troubleshooting guides, operational runbooks, policy standards, and knowledge articles for SSE and ZTNA services.
- Coach and mentor Level 2 resources on issue triage, log analysis, escalation quality, repeatable troubleshooting, and operational best practices.
- Collaborate with vendors and managed service providers to resolve advanced platform issues, validate product behavior, and evaluate relevant feature enhancements.
- Identify opportunities to improve policy governance, reporting, alerting, automation, and operational readiness across SSE services.
Required Qualifications & Skills:
- Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent work experience.
- 7+ years of experience in network security, network engineering, remote access, proxy, cloud security, or related infrastructure domains.
- Hands-on experience supporting SSE technologies, including ZTNA, SWG, CASB, and DLP, preferably with Netskope or comparable platforms such as Zscaler, Palo Alto Prisma Access, Cisco, Cloudflare, or Broadcom/Symantec.
- Strong working knowledge of ZTNA concepts, private application access, connector/publisher architecture, identity-based access controls, device posture, and least-privilege access models.
- Experience creating, tuning, and troubleshooting SWG, CASB, and DLP policies, including web categories, SSL/TLS inspection, SaaS controls, sensitive data detection, policy exceptions, and false positive analysis.
- Strong network fundamentals across LAN, WAN, TCP/IP, DNS, routing, NAT, firewalls, VPN, SD-WAN, proxy, certificates, and packet flow analysis.
- Ability to analyze platform logs, SIEM events, endpoint client behavior, authentication flows, and traffic steering outcomes to resolve complex incidents.
- Effective written and verbal communication skills, including the ability to explain technical issues, document decisions, coordinate changes, and work with global stakeholders.
- Demonstrated ability to coach, mentor, and guide Level 2 support resources through structured troubleshooting and knowledge transfer.
- Relevant certifications such as Netskope, Zscaler, CCNP, CCNP Security, Azure, cloud security, or CISSP are a plus.
Preferred Qualifications:
- Experience with identity providers such as Microsoft Entra ID, Okta, or Ping Identity, including SAML, OAuth, conditional access, MFA, and group-based policy assignment.
- Experience supporting SSE policy rollouts, user migrations, operational readiness, and change communication in a large enterprise environment.
- Familiarity with Microsoft 365, SaaS governance, cloud application risk, data protection controls, and DLP policy lifecycle management.
- Experience improving operational processes through runbooks, dashboards, automation, reporting, and recurring issue reduction.
Additional Information:
- This role requires working with global teams across multiple time zones.
- Candidate must participate in global on-call rotation roster.
- The candidate will provide Level 3 support and serve as senior technical resource for SSE/ZTNA, including guidance and mentoring for Level 2 support teams.
- Occasional travel may be required for key project implementations and strategy discussions.
If you are a seasoned network security engineer with hands-on SSE experience, strong ZTNA fundamentals, practical SWG, CASB, and DLP policy knowledge, and the ability to solve complex issues while guiding others, we encourage you to apply.
Awareness, Unity, Empowerment:At Magna, we believe that a diverse workforce is critical to our success. That’s why we are proud to be an equal opportunity employer. We hire on the basis of experience and qualifications, and in consideration of job requirements, regardless of, in particular, color, ancestry, religion, gender, origin, sexual orientation, age, citizenship, marital status, disability or gender identity. Magna takes the privacy of your personal information seriously. We discourage you from sending applications via email or traditional mail to comply with GDPR requirements and your local Data Privacy Law.
AI-Assisted Screening Disclosure
As part of our commitment to a fair, consistent, and efficient recruitment process, we may use artificial intelligence (AI) tools to assist in the initial screening of applications submitted through our Workday system. These tools help identify qualifications and experience that align with the role requirements. Please note that AI is used solely to support our recruiters. Final decisions are always made by the hiring manager and the hiring team. Importantly, no applicant data is shared externally through these AI tools. All information remains securely within our systems and is handled in accordance with our privacy and data protection policies.
Under conditions defined by applicable law, you may have the right to request an explanation of how AI is used to support decision-making.
If you have any questions or concerns about this process, feel free to contact our Talent Attraction team.
Skills Required
- Bachelor's degree in Computer Science, Information Technology, or related field, or equivalent work experience
- 7+ years experience in network security, network engineering, remote access, proxy, cloud security, or related infrastructure domains
- Hands-on experience supporting SSE technologies (ZTNA, SWG, CASB, DLP) such as Netskope, Zscaler, Palo Alto Prisma Access, Cloudflare, Broadcom/Symantec
- Strong working knowledge of ZTNA concepts, private application access, connector/publisher architecture, identity-based access controls, device posture, least-privilege models
- Experience creating, tuning, and troubleshooting SWG, CASB, and DLP policies including SSL/TLS inspection, web categories, SaaS controls, sensitive data detection, and false positive analysis
- Strong network fundamentals across LAN, WAN, TCP/IP, DNS, routing, NAT, firewalls, VPN, SD-WAN, proxy, certificates, and packet flow analysis
- Ability to analyze platform logs, SIEM events, endpoint client behavior, authentication flows, and traffic steering outcomes to resolve complex incidents
- Effective written and verbal communication skills for documentation, coordination, and stakeholder engagement
- Demonstrated ability to coach and mentor Level 2 support resources in troubleshooting and operational best practices
- Participation in global on-call rotation roster
- Occasional travel for project implementations and strategy discussions
- Experience with identity providers (Microsoft Entra ID, Okta, Ping Identity), SAML, OAuth, conditional access, MFA, and group-based policy assignment
- Experience supporting SSE policy rollouts, user migrations, operational readiness, and change communication in large enterprises
- Familiarity with Microsoft 365, SaaS governance, cloud application risk, and DLP policy lifecycle management
- Experience improving operational processes via runbooks, dashboards, automation, reporting, and recurring issue reduction
- Relevant certifications (Netskope, Zscaler, CCNP, CCNP Security, Azure, cloud security, CISSP)
What We Do
We are a mobility company that innovates like a start-up and thinks like a technology company. This helps us anticipate change in one of the most complex industries in the world and respond quickly. We depend on a team of 171,000 dynamic, entrepreneurial-minded employees in an environment where great ideas flourish. Our presence spans 343 manufacturing operations and 88 product development, engineering and sales centers in 29 countries. We understand that you need a career as unique as you are. Whether you want to advance your existing expertise or try something completely different, we are committed to your growth.
Why Work With Us
At Magna, our engineering team is advancing mobility for everyone and everything. Joining this team means being a part of the design, development, and manufacturing of the world’s most advanced mobility technology. Innovations that move families, shape communities, and improve lives. You can follow your passions and shape your own career path.
Gallery
Magna International Teams
Magna International Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Majority of roles are hybrid with flexibility. Please speak with our recruiting team for specific details on hybrid work.











