Zoox

Enterprise Security

Senior/StaffNetworkSecurityEngineer

$190–228k Foster City, California, United States FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Senior/Staff Network Security Engineer at Zoox. Skills: Network security, Cloud networking, Automation, Security operations. Design secure hybrid/multi-cloud network architectures. Implement secure hybrid/multi-cloud network architectures”

Industry & Context.

Enterprise Security
Problems you'll solve

Troubleshooting; Root cause analysis

What They're Looking For.

Must Have

8+ years network security engineering, Enterprise, cloud, OT/lab environments, Next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, ZTNA, TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI, cloud networking security, AWS, GCP, or Azure, IaC and automation tooling, Terraform, Python, CI/CD pipelines, REST APIs, Network security monitoring, Threat detection, security operations, SIEM, IDS/IPS, Zeek, Suricata, Vulnerability management platforms, NIST 800-53, CSF 2.0, ISO 27001

Nice to Have

Experience in autonomous vehicle environments, Experience in robotics environments, Experience in automotive environments, PCNSE certification, AWS Security Specialty certification, CCNP/CCIE Security certification, CISSP certification, Experimenting with AI/ML security, Deploying AI/ML security, LLM-driven copilots

What You'll Do.

Design secure hybrid/multi-cloud network architectures

Implement secure hybrid/multi-cloud network architectures

Maintain secure hybrid/multi-cloud network architectures

Enforce zero-trust access controls

Enforce network segmentation

Develop related policies

Develop related standards

Develop related architecture diagrams

Maintain related policies

Maintain related standards

Maintain related architecture diagrams

Own next-generation firewall platforms

Operate next-generation firewall platforms

Manage firewall policy architecture

Manage firewall segmentation

Manage firewall URL filtering

Manage firewall SSL/TLS decryption

Manage firewall threat prevention tuning

Architect secure remote access solutions

Operate secure remote access solutions

Own secure remote access solutions

Ensure high availability

Ensure certificate-based authentication

Integrate with identity providers

Drive Infrastructure-as-Code

Manage configurations using IaC

Manage firewall policies using IaC

Manage security using IaC

Integrate LLM-based tools

Streamline operational tasks

Oversee security operations

Perform network security monitoring

Perform traffic analysis

Perform threat detection

Perform vulnerability assessments

Support compliance requirements

Conduct security reviews

Lead 802.1X initiatives

Lead certificate-based NAC initiatives

Lead cross-functional security initiatives

How You'll Work.

Team & Collaboration

Cross-functional security initiatives; Product Security; SRE; IT; Software Engineering

Process & Methodology

Roadmap definition

Full Job Description

## In This Role, You Will... Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN, SD-WAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, GlobalProtect, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Lead 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Define team roadmap, mentor engineers, and lead cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams ## Qualifications Experience: 8+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networki

Free ATS check

Applying for this Senior/Staff Network Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Lever

  • Lever uses a streamlined one-page form — apply in under 5 minutes.
  • LinkedIn import works well; review parsed data before submitting.
  • The cover letter field is optional but visible to reviewers — use it to differentiate.
  • Referral codes from employees can significantly boost visibility of your application.

ANONYMOUS · UNFILTERED

What do employees actually say about Zoox?

Real rants from real employees. Read before you apply.

Read Company Rants →