P

Principal Network Engineer

Progressive Leasing · United States

RemoteWorkplace
TodayPosted · Aug 3
HimalayasSource
Apply now Opens the original posting at Progressive Leasing. PivotHop does not host applications.

Skills in this posting

Extracted from the posting text by the instrument — the demand side, read literally.

The posting

Progressive Leasing is a leading provider of in-store and e-commerce lease-to-own solutions. With more than 20 years in FinTech, we’ve grown from start-up to industry leader by innovating, simplifying, and valuing people.

We are a subsidiary of PROG Holdings (NYSE: PRG), a FinTech holding company with three business segments: Progressive Leasing , Purchasing Power (a leading employee purchase program for consumer products and services using payroll deduction), and Four, a Buy Now Pay Later (BNPL) platform.

We are currently hiring a Principal Network Engineer to take ownership of the network that powers the business across a hybrid environment of AWS cloud and on-premise branch offices.

You’ll work close to the foundations (AWS networking, Palo Alto firewalls, routing and connectivity, automation, and infrastructure as code) and set the direction for how the network is standardized, secured, and operated end to end.

A team of network engineering contractors helps deliver the work; you’ll coordinate and prioritize what they take on while you focus on the larger initiatives. This role is a work‑from‑home position and can be performed remotely anywhere in the continental US.

Employee Value Proposition (EVP): PROG is dedicated to providing people with opportunity — opportunity for inclusive collaboration, opportunity for innovation, and opportunity for development. WE ARE: The Tech team at PROG and we’re cloud-first, security-aware, and heavily invested in automation and IaC-driven workflows.

We treat our infrastructure as a platform: our “customers” are the application, security, and operations teams who should be able to self-serve their own network needs and troubleshoot with the tooling and guardrails we provide. You’ll have ownership from day one and the autonomy to decide how the network platform runs and improves.

YOU ARE: You’ll be the technical owner of our network platform, balancing day-to-day operational excellence with the longer-term work of standardizing and hardening the environment. You’ll focus on platform direction, reliability, and security. YOUR DAY‑TO‑DAY:

Own and operate our hybrid network end to end, spanning AWS cloud networking and the limited but critical on-premise branch and data center footprint, with a focus on standardization, reliability, and security

Lead the technical evaluation and deployment of ZTNA and Secure Web Gateway (SWG) capabilities alongside Enterprise Architecture and Cyber Security, driving the organization’s transition from always-on VPN toward a Zero Trust access model

Own the AWS network platform in a multi-account hub-spoke landing zone, including VPCs, Transit Gateway, IPAM, Route 53, Direct Connect, Gateway Load Balancer inspection paths, NACLs, security groups, and VPC sharing via AWS RAM across our network and workload accounts

Manage the Palo Alto environment, including VM-Series firewalls in AWS and Panorama-based policy management, the current GlobalProtect remote-access VPN (including contractor and third-party access groups and HIP checks), and east-west / ingress / egress inspection design

Drive network infrastructure as code with Terraform as the core tool, building and evolving modular, reusable patterns so network changes are version-controlled, peer-reviewed, and repeatable rather than one-off manual edits (transferable IaC experience from other tools is welcome)

Treat the network as a self-service platform: build the modules, guardrails, documentation, and tooling that let application and operations teams provision and troubleshoot their own connectivity, and make stepping in for one-off work the exception, not the norm

Build observability, alerting, and redundancy into the network by default, instrumenting telemetry, logs, and SNMP into our observability stack (Dynatrace and Observe) so issues are caught early and the platform is resilient across regions and availability zones

Set and enforce network standards across the organization, reduce configuration drift, and partner on the program to detect and alert on manual changes that bypass IaC

Support hybrid connectivity across on-premise branch routing and switching and Direct Connect into AWS

Execute changes through our ServiceNow change-management process, including CAB review for significant changes, and participate in the support and on-call rotation

Treat every one-off build or manual fix as a signal: either a defect in the platform to be fixed or a missing feature to be added, and close that gap so the work becomes self-service next time

Use AI-assisted tools to accelerate troubleshooting, draft and improve runbooks, and reduce repetitive operational overhead, with a practical focus on where AI adds value in network operations

YOU’LL BRING: We need a strong network engineer who is equally comfortable in the cloud and on traditional network gear, can lead a team and delegate effectively, and has the instinct to standardize and automate rather than firefight. Breadth across cloud and network, plus the discipline to build a platform, matter more here than deep specialization in any single tool. Required experience:

Strong, hands-on networking fundamentals across routing, switching, DNS, load balancing, NAT, and segmentation, in both cloud and on-premise contexts

Proven ability to lead a ZTNA and Secure Web Gateway (SWG) evaluation and deployment (e.g., Zscaler, Netskope, Prisma Access, or comparable), owning the technical direction alongside Enterprise Architecture and Cyber Security as the organization moves from always-on VPN to a Zero Trust access model

Hands-on experience managing a Palo Alto environment (NGFW / VM-Series, Panorama, security policy, and traffic inspection)

Strong AWS networking experience in a multi-account environment: VPC design, Transit Gateway, Direct Connect, Route 53, IPAM, NACLs and security groups, and VPC sharing patterns

Practical infrastructure as code experience, with Terraform as the core tool (transferable experience from other IaC tools is acceptable) and a track record of replacing manual changes with version-controlled, peer-reviewed automation

A platform mindset: experience building reusable modules, guardrails, and self-service capabilities so other teams can provision and troubleshoot without one-off engineering help

Comfort coordinating and prioritizing a team’s delivery and keeping work on track while you focus on larger initiatives

A strong instinct for observability, alerting, and redundancy, and experience instrumenting networks for monitoring and resilience

Security-first thinking, including segmentation, least privilege, and secure connectivity patterns across hybrid environments

Comfort operating in production with formal change management (CAB / ServiceNow) and on-call responsibility

Scripting fluency (Python, Bash, or similar) for automation and operational tooling

Strong cross-team communication and a consultative approach to supporting application, security, and operations teams

Comfort using AI tools (Claude, GitHub Copilot, or similar) to ramp on unfamiliar systems, write automation, and diagnose issues

Excerpt from the original listing. The full, current text lives at the source. Read and apply there →

The PivotHop read

Where these skills also reach

Adjacent occupations measured from the same postings — readiness is what a network engineer’s profile already covers.

More network engineer roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves