Staff Network Engineer
IT
Menlo Park, CA, USA
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.
Staff Network Engineer
Location: MPK/Bellevue/Dublin
Snowflake's Enterprise Technology Network Services team is looking for a Senior Network Engineer to lead the design, operation, and optimization of our Zero Trust and secure-access platform. This role is Zscaler-centric — you will own the health, performance, and roadmap of our ZIA/ZPA deployment — while working across a modern, multi-cloud network stack that supports a global workforce of 10,000+ users. You'll be the escalation point for the most complex connectivity issues and a driver of automation and observability across the environment.
What You'll Do
Own and operate the Zscaler platform (ZIA, ZPA, ZDX, ZCC) end-to-end, including policy frameworks, app-segmentation models, PAC/traffic-forwarding standards, App Connector topology, and NSS/log-streaming design.
Troubleshoot secure-access incidents like tunnel flapping, broker/connector health, SSL inspection edge cases, DNS/DTLS failures, and lead root-cause analysis for systemic issues.
Manage Palo Alto firewalls, Panorama and GlobalProtect VPN, while planning migration toward Zscaler solutions.
Support Aruba (Central) Wireless, Ekahau and Cisco Catalyst switches globally.
Design, install, and configure network devices and ISP circuits at new offices.
Build automation and observability: leverage log analytics (we run our network telemetry through Snowflake) to create dashboards, alerting, and proactive detection.
Troubleshoot secure Network constructs in AWS, Azure, and GCP such as NVAs, NSG, VPC, UDR, DirectConnect, ExpressRoute.
Author technical runbooks, escalation procedures, and knowledge-base content.
Participate in on-call rotations for the changes and lead responses to major network incidents.
Be able to travel internationally for short periods of time for site builds.
What You'll Bring
At least 10 years of enterprise network infrastructure experience, including 3+ years of hands-on Zscaler ZIA/ZPA design and deployment at scale.
Recognized depth in Zero Trust / SASE architecture with expertise in ZTNA, proxy/SWG, SSL inspection, and cloud security.
Hands-on Palo Alto (PAN-OS, GlobalProtect, Panorama) and enterprise VPN experience.
Aruba wireless and Cisco LAN/WAN (routing, switching, 802.1x) fundamentals.
Strong TCP/IP, DNS, DHCP, TLS/DTLS, BGP, and QoS troubleshooting skills.
Multi-cloud (AWS/Azure/GCP) networking and site-to-cloud connectivity experience.
Automation mindset: Python scripting, API config, and log observability (SQL/Snowflake a plus).
Strong ITSM management, documentation, and communication skills.
Nice to Have
Certifications: Zscaler (ZCCA-IA/PA, ZDTA), Palo Alto (PCNSE), Aruba (ACMA/ACMP), or Cisco (CCNA/CCNP).
Experience migrating legacy VPNs (GlobalProtect) to ZPA.
Familiarity with SASE and network-as-code/IaC (Terraform).
Experience operating in high-growth SaaS or cloud-native environments.
Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.
How do you want to make your impact?
For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com