1

Sase Architect Jobs (NOW HIRING)

Solution Architect

New York, NY · On-site

$120K - $160K/yr

Architect comprehensive solutions across cybersecurity (Next-Gen Firewall, SASE, ZTA, endpoint, SIEM/SOC), enterprise networking, SD-WAN, cloud connectivity, and compute infrastructure. * Produce ...

SASE Operations and Support Engineer

Alexandria, VA · On-site

$74K - $100K/yr

Support the creation and maintenance of SASE network flow diagrams, architecture diagrams, IP assignments, Azure Publisher connectivity, and end-to-end flow documentation. * Create Netskope packaging ...

Zscaler Security Architect (Remote)

Cincinnati, OH · Remote

$66.50 - $86/hr

... Trust, SASE, secure web gateway, cloud firewall, CASB, DLP, and traffic inspection concepts. · Proven experience designing Zscaler architecture for large enterprise and global transformation ...

Network Architect

Brandon, FL · On-site

$57.50 - $77/hr

Support modernization initiatives including Cisco Secure Access, Zero Trust, and Secure Access Service Edge (SASE) strategies * As a Network Architect, you will develop network design documentation ...

Architect comprehensive solutions across cybersecurity (Next-Gen Firewall, SASE, ZTA, endpoint, SIEM/SOC), enterprise networking, SD-WAN, cloud connectivity, and compute infrastructure. * Produce ...

Architect comprehensive solutions across cybersecurity (Next-Gen Firewall, SASE, ZTA, endpoint, SIEM/SOC), enterprise networking, SD-WAN, cloud connectivity, and compute infrastructure. * Produce ...

Network Security Engineer - SASE

Atlanta, GA · On-site

$103K - $141K/yr

Job Purpose and Impact The Network Engineer - SASE will implement, operate, automate, and ... The engineer will work within established architecture and collaborate with senior engineers and ...

Showing results 21-40

Sase Architect information

See salary details

$46.5K

$128.8K

$201.5K

How much do sase architect jobs pay per year?

As of Sep 12, 2026, the average yearly pay for sase architect in the United States is $128,756.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,000.00 and $166,000.00 per year, depending on experience, location, and employer.

What is the difference between Sase Architect vs Network Security Engineer?

AspectSase ArchitectNetwork Security Engineer
CredentialsCertifications like CCNP, CCIE, CISSP, CCSPCertifications like CISSP, CEH, CCNP Security
Work EnvironmentDesigning and implementing secure SD-WAN and SASE solutions for organizationsMonitoring, configuring, and maintaining network security infrastructure
Industry UsagePrimarily in cloud security, SD-WAN, and SASE deploymentsAcross various industries focusing on network security and threat mitigation

The Sase Architect focuses on designing and implementing SASE solutions, integrating cloud security and SD-WAN technologies. In contrast, the Network Security Engineer manages and maintains security infrastructure to protect networks. Both roles require similar certifications and work in overlapping environments, but their core responsibilities differ in scope and focus.

What are popular job titles related to Sase Architect jobs?

For Sase Architect jobs, the most frequently searched job titles are:

Infographic showing various Sase Architect job openings in the United States as of September 2026, with employment types broken down into 95% Full Time, 1% Part Time, and 4% Contract. Highlights an 76% Physical, 6% Hybrid, and 18% Remote job distribution, with an average salary of $128,756 per year, or $61.9 per hour.

Zero Trust Network Access Architect/Engineer

Quantico, VA • Hybrid

Full-time

Posted 12 days ago


ASRC Federal rating

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz


Job description

Position Description:

ASRC Federal is actively hiring a Senior Zero Trust Network Architect / Principal Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico, VA.

We are seeking an industry-leading cybersecurity expert with a deep specialization in Zero Trust Network Architecture (ZTNA) and Secure Access Service Edge (SASE). The successful candidate will serve as the chief technical authority for the design, orchestration, implementation, and long-term governance of our enterprise security boundaries.

In this role, you will lead the strategic modernization of DCSA's hybrid workforce infrastructure. You will leverage Palo Alto Networks (Panorama, GlobalProtect) and Versa Networks SASE platforms to establish a highly resilient, identity-aware, and context-driven security posture.

This is primarily a Telework position with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base VA. Additional onsite time may be required during initial onboarding and program integration.

Minimum Requirements: 

  • Experience:
    • Minimum of 10 years of progressive experience in network security engineering, enterprise architecture, and infrastructure security.
    • At least 3–4 years of direct experience architecting and implementing Zero Trust frameworks (NIST SP 800-207) and SASE solutions in enterprise or federal environments.
  • Technical Mastery:
    • Advanced architecture-level knowledge of Palo Alto Networks enterprise solutions, including deep management expertise via Panorama and secure access deployments using GlobalProtect.
    • Deep technical proficiency in designing and deploying Versa Networks SASE (SD-WAN, Secure Web Gateway, Cloud Access Security Broker, and Firewall-as-a-Service).
  • Security Clearance: Active Secret Clearance REQUIRED, must be eligible to be upgraded to TS/SCI.
  • Compliance: Must meet 8140 certification requirements (e.g. CISM, CISSP-ISSAP, CISSP-ISSEP, GCIA, GDSA, GICSP)
  • Education: Bachelor’s Degree in Cybersecurity, Computer Engineering, Information Systems Management, or a related field. A Master's degree or an equivalent combination of military service and 12+ years of highly relevant experience is accepted.
  • Desired Vendor Certifications:
    • Palo Alto Networks Certified Network Security Engineer (PCNSE)
    • Palo Alto Networks Certified Zero Trust Network Security Engineer (PCZTNSE)
    • Versa Certified SASE Professional (VCSP) or Versa Certified SASE Specialist (VCSS)

 

Responsibilities:

Strategic Architecture & Engineering

  • Serve as the Principal Architect for the DCSA Zero Trust journey, establishing the technical roadmap, reference architectures, and engineering guidelines aligned with NIST SP 800-207 standards.
  • Lead the end-to-end design, implementation, and optimization of Palo Alto GlobalProtect and Versa Networks SASE to secure cloud, hybrid on-premises, and mobile endpoints.
  • Define and govern global security policy templates within Palo Alto Panorama to enforce micro-segmentation, application-level security, and threat prevention.

Policy, Governance & Optimization

  • Architect advanced data loss prevention (DLP), SSL/TLS decryption, and threat prevention strategies across all egress and ingress points.
  • Conduct regular architectural reviews of the SASE and ZTNA configurations to identify performance bottlenecks, configuration drifts, or security gaps, providing advanced mitigation strategies.

Identity & Ecosystem Integration

  • Collaborate with Identity and Access Management (IAM) teams to integrate ZTNA/SASE policies with identity providers (e.g., Okta, Azure AD), ensuring device posture, user context, and continuous authentication are evaluated in real time.
  • Guide the integration of Versa SASE and Palo Alto platforms with existing Security Operations Center (SOC) environments, including SIEM, SOAR, and endpoint detection (EDR/XDR) tools.

Technical Leadership & Mentorship

  • Provide technical leadership and guidance to the cybersecurity engineering team, serving as the tier-4 escalations point for complex architectural, routing, and access control challenges.
  • Author enterprise-level high-level designs (HLD), low-level designs (LLD), system security plans (SSP), and change-management policies for executive-level and government stakeholders.

Vendor & Capability Evaluation

  • Stay abreast of the latest Palo Alto PAN-OS and Versa Networks feature sets, performing proof-of-concepts (PoC) to evaluate and deploy next-generation capabilities.
  • Champion security-as-code and automation initiatives, using APIs and orchestration tools to automate secure connectivity and zero-touch deployments.

 Work Environment and Physical Demands: 

  • This is primarily a Telework position with a requirement to be onsite at least two (2) days a week or as needed at Quantico Marine Corps Base VA. Additional onsite time may be required during initial onboarding and program integration.
  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection
  • Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom