The Senior Network Engineer - SASE will implement, operate, automate, and continuously improve Cargill's global Secure Access Service Edge (SASE) and Security Service Edge (SSE) services. This role will support the migration from legacy web proxy and remote-access technologies to cloud-delivered security and will configure capabilities such as Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), and threat protection. The engineer will work within established architecture and collaborate with senior engineers and partner teams to deliver reliable and secure access for users, sites, and applications.
.
Key Accountabilities
- Implement, configure, test, and support SASE and SSE capabilities in accordance with established architecture, security standards, and engineering practices.
- Configure and maintain SWG policies, ZTNA application access, traffic steering, endpoint clients, tunnels, connectors, and related platform components.
- Support migrations from legacy web proxy and VPN technologies through discovery, testing, deployment validation, cutover support, and post-implementation stabilization.
- Monitor and troubleshoot connectivity, authentication, certificate, SSL/TLS inspection, performance, and application-access issues across hybrid and cloud environments.
- Support integrations with identity, endpoint security, SIEM/XDR, cloud, and IT service management platforms.
- Automate repeatable configuration, validation, reporting, and operational tasks using APIs, scripting, and infrastructure-as-code practices.
- Maintain technical documentation, implementation records, low-level designs, operational runbooks, and knowledge articles.
- Participate in Agile delivery, change management, incident and problem management, and continuous service improvement activities.
- Collaborate with global network, security, identity, cloud, endpoint, and application teams and contribute recommendations that improve team-level engineering practices.
- Other duties as assigned.
Qualifications
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
Minimum of 6 years of relevant experience in network engineering, network security, cybersecurity engineering, or infrastructure operations.
Hands-on experience supporting enterprise network or security technologies, with exposure to SASE, SSE, SWG, ZTNA, cloud security, or secure remote-access solutions.
Strong understanding of enterprise networking fundamentals, including TCP/IP, routing, switching, DNS, DHCP, VPNs, SSL/TLS, certificates, and network security principles.
Experience troubleshooting connectivity, authentication, and application-access issues in enterprise environments.
Ability to create clear technical documentation and work effectively with geographically distributed engineering and operations teams.
7+ years of experience supporting enterprise network or security solutions within a large-scale, distributed IT environment.
Hands-on experience with one or more leading SASE/SSE platforms, such as Netskope, Palo Alto Prisma Access, Zscaler Internet Access (ZIA), or Zscaler Private Access (ZPA).
Experience administering SWG capabilities, including URL filtering, SSL/TLS inspection, cloud application controls, malware protection, DLP, threat prevention, and policy enforcement.
Experience configuring ZTNA access to private applications and supporting initiatives that reduce reliance on traditional VPN technologies.
Familiarity with endpoint traffic steering, GRE/IPsec tunnels, private access connectors or publishers, dedicated egress, and high-availability designs.
Understanding of identity-driven security and integration with Microsoft Entra ID, Okta, Ping Identity, or similar identity providers using SAML, OAuth, OIDC, or SCIM.
Experience integrating or operating security services with endpoint security, SIEM, XDR, or security operations workflows.
Skills Required
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent practical experience
- Minimum of 6 years of relevant experience in network engineering, network security, cybersecurity engineering, or infrastructure operations
- 7+ years supporting enterprise network or security solutions within a large-scale, distributed IT environment
- Hands-on experience with SASE/SSE platforms (e.g., Netskope, Palo Alto Prisma Access, Zscaler ZIA/ZPA)
- Experience administering SWG capabilities: URL filtering, SSL/TLS inspection, cloud application controls, malware protection, DLP, threat prevention, policy enforcement
- Experience configuring ZTNA access to private applications and reducing reliance on traditional VPN technologies
- Strong understanding of enterprise networking fundamentals: TCP/IP, routing, switching, DNS, DHCP, VPNs, SSL/TLS, certificates, network security principles
- Familiarity with endpoint traffic steering, GRE/IPsec tunnels, private access connectors/publishers, dedicated egress, and high-availability designs
- Understanding of identity-driven security and integrations with Microsoft Entra ID, Okta, Ping Identity using SAML, OAuth, OIDC, SCIM
- Experience integrating or operating security services with endpoint security, SIEM, or XDR platforms
- Ability to automate configuration, validation, reporting, and operational tasks using APIs, scripting, and infrastructure-as-code practices
- Experience troubleshooting connectivity, authentication, certificate, SSL/TLS inspection, performance, and application-access issues in enterprise environments
- Ability to create clear technical documentation, low-level designs, runbooks, and work effectively with geographically distributed teams
Cargill Compensation & Benefits Highlights
-
Retirement Support — Two-layer retirement program combines a 401(k) match (100% on the first 3%, 50% on the next 2%) with an employer-funded Employee Retirement Account of roughly 2.5–7% based on age and service. Match is delivered quarterly in company stock and the ERA adds long-term value through additional employer contributions.
-
Leave & Time Off Breadth — PTO starts at 15 days and scales to 30 days with tenure, governed by a clear June 1–May 31 cycle. This structured ladder provides predictable time away as service grows.
-
Parental & Family Support — Paid family leave offers up to 6 weeks to bond with a new child and 4 weeks to care for a family member or qualifying military needs. Additional supports such as Bright Horizons childcare solutions and Milk Stork reinforce family care.
Cargill Insights
What We Do
We are a family company providing food, ingredients, agricultural solutions and industrial products to nourish the world in a safe, responsible and sustainable way. We connect farmers with markets so they can prosper. We connect customers with ingredients so they can make meals people love. And we connect families with daily essentials— from eggs to edible oils, salt to skincare, feed to flooring. By providing customers with products that are vital for living, we help businesses grow, communities prosper and consumers live well in their daily lives.
Why Work With Us
The decision to join Cargill can open the door to a world of possibility. As part of our Digital, Technology & Data team, you’ll get to be part of a large and diverse group full of unique perspectives united by a common, higher purpose while building a rewarding career full of opportunity, growth and the satisfaction of knowing your work matters.
Gallery
Cargill Teams
Cargill Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.



.jpg)












.jpg)











