--- title: 'Principal Support Engineer - Network at Reach Security' canonical: 'https://feeny.ai/job/principal-support-engineer-network-reach-security-remote-7j6bxdn30rw5' type: 'job' last_seen: '2026-09-10' --- # Principal Support Engineer - Network at Reach Security - **Company:** Reach Security - **Location:** Remote - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-08-25 - **Last confirmed live:** 2026-09-10 - **Apply:** https://jobs.ashbyhq.com/reach/1716cd90-84d2-4803-a845-c18007f95634 ## Job description Principal Support Engineer — Network ## DOMAIN SUBJECT-MATTER EXPERT · ESCALATION & ENABLEMENT ## About the role Reach Security tells organizations what their existing security tools should be doing with the products they already own — and proves it. As a Principal Support Engineer, Network, you are Reach's senior domain authority on everything network. This is not a firewall-administration or network break/fix role. You won't spend your days writing rule-bases, managing devices, or running a customer's network operations. You've already done that work — for years — and that is exactly what qualifies you. Those years in the trenches are what let you look at a customer's network rules, their controls, and Reach's findings and say, with authority, what matters, what doesn't, and why. In this role you put that hard-won judgment to work: advising the field, guiding customers through their hardest problems, sharpening Reach's recommendations, and troubleshooting how Reach integrates with the network-security products already in a customer's environment. It is a high-agency individual-contributor role for a proven expert who is energized by unfamiliar problems rather than thrown by them. What this role really does You'll serve three audiences at once, and the strongest people in this seat move fluidly between them: - Enable the field (Sales Engineering & POVs). Help SEs build the strongest possible POV from Reach's network findings — turning a rule-base analysis or exposure finding into “here's the risk this creates, here's why it's urgent, here's what to change first.” Coach the field to defend those findings against a skeptical network team, and tell Engineering and Research what would make the next network POV even more compelling. - Empower Customer Success. Be the deep technical resolver behind CS. When a customer hits a hard network or firewall-integration problem, you investigate to root cause, propose the fix, and hand Engineering a clean, reproducible diagnosis — so engineers validate and ship rather than doing front-line discovery. - Harden the product. Own your share of the escalation queue and close the loop: solve, reproduce, test, document, and enable — so each issue makes Reach more robust and each runbook makes the whole team faster. ## How you'll spend your time - Serve as the network subject-matter expert for the support team — review customer firewall rule-bases, network policies, segmentation, and controls, and make sage, prioritized recommendations grounded in real-world best practice (overly permissive, shadowed, redundant, or risky rules; exposure; segmentation gaps). - Critique Reach's network findings so customers are presented only with what truly matters — separating signal from noise and articulating why a finding is urgent, or why it isn't. - Troubleshoot integrations between Reach and third-party network-security products (NGFW, IDS/IPS/NDR, proxy/SWG, SASE/ZTNA, and similar) — using your deep knowledge of how those platforms actually behave to pinpoint where an integration breaks and propose the fix. This is where your hands-on background is exercised most directly. - Diagnose deep, engineering-level customer issues end to end — reasoning from packet captures, flow data, device logs, and protocol behavior to reach true root cause, then packaging a clear diagnosis and proposed fix that Engineering can act on quickly. - Uplevel the Sales Engineering team — teach the technical field team to read and explain network findings, defend recommendations to customer network and security teams, and translate product output into what actually matters to the customer. - Partner with Engineering and QA to report defects, validate fixes, confirm workarounds, and drive root-cause analysis. - Author and maintain runbooks, audit playbooks, and internal documentation that turn your field experience into repeatable team knowledge. - Maintain enough of a lab or test capability across representative network platforms to validate hypotheses about behavior and integration edge cases. The experience that qualifies you The experience below is the foundation we're hiring for. You've done this work hands-on, at depth, earlier in your career — and in this role you'll leverage that judgment as a subject-matter expert rather than performing it day to day. We're screening for the expertise that experience produced, not for a desire to keep administering networks. - 6+ years of deep, hands-on experience with enterprise network security — firewalls, segmentation, and network traffic analysis — enough to have developed genuine expertise, not passing familiarity. - Time in a senior individual-contributor role such as L3 Network Support Engineer, Network Security Engineer, Firewall Engineer, or Security Support Engineer. - Platform-level expertise with one or more enterprise firewall ecosystems — Palo Alto (PAN-OS), Fortinet FortiGate, Cisco (ASA/Firepower), Check Point, or Juniper — including rule-base design, review, and optimization, and the judgment to know what “good” looks like. - Strong command of TCP/IP and network protocol internals, with the ability to reason from packet captures (Wireshark/tcpdump), flow/telemetry data, and device logs to root cause. - Depth in network segmentation and micro-segmentation, NAT, routing (BGP/OSPF), VPN (IPsec/SSL), and TLS/SSL inspection. - Experience with IDS/IPS/NDR, secure web gateways/proxies, DNS security, and modern SASE/ZTNA architectures. - Cloud network security experience — AWS security groups/NACLs, Azure NSGs, GCP firewall rules, VPCs, and connectivity/peering constructs. - A track record resolving interoperability issues between network-security tools and the broader stack. - Working knowledge of Linux system administration, sufficient to reason about the services that collect from and integrate with network devices. - Experience with enterprise-scale, multi-site environments and large, heterogeneous network estates. - The advisory instinct that defines this role: the ability to look at a rule-base or a set of findings and tell a customer, clearly, which few things matter and why. - Strong written and verbal communication — you can make a complex network issue clear to a customer, an SE, and an engineer, each in their own language. - Strong time management and a real sense of urgency in customer-impacting situations. - BS or MS in Computer Science, Engineering, Networking, or a related technical discipline — or equivalent practical experience. Cross-domain fluency we value Reach spans the whole security stack, and the best domain experts are curious well past their specialty. You don't need to be an expert in all of these, but comfort in several will make you far stronger here: identity and IDP troubleshooting (SSO, SAML/OIDC, and layered/conditional access as it intersects network controls); a working grasp of threats and vulnerabilities and how they map to exposure at the network layer; and familiarity with email security controls. We'll gladly help you deepen the areas you're newer to. ## Nice to have - Relevant certifications (e.g., PCNSE, NSE, CCNP/CCIE Security, CISSP) — valued as evidence of depth, not required. - Experience with WAF, load balancers, and application-layer security. - Familiarity with network detection/analytics, SIEM, or SOAR platforms from a support or troubleshooting perspective. - Scripting/automation for network validation and troubleshooting (Python, or platform APIs). - Exposure to hybrid and multi-cloud connectivity (transit gateways, SD-WAN, cloud firewalls). Who you'll thrive as You're the person peers escalate to — and still the first to say “that's a strange packet, let me chase it down.” You think in systems, you're relentless about root cause, and you're generous with what you learn. You're as comfortable teaching an SE how to defend a rule-base finding as you are staring at a capture until the anomaly gives itself up. Curiosity, adaptability, and low ego matter to us as much as depth: the security stack keeps changing, and we're looking for someone who's genuinely excited by that. Working at Reach Security: - Competitive salary, and equity package - Comprehensive benefits package including: - Medical, dental, and vision insurance, including plan options with company-paid employee coverage - FSA, HSA, and 401(k) plans - Company paid life insurance and disability coverage, along with buy up options - Voluntary benefits including pet insurance, identify theft coverage, and legal services - Unlimited PTO and sick time ## About Reach Security ## Company Overview - **One-liner**: Reach Security provides an AI-native platform that integrates with an organization's existing security stack to continuously identify, prioritize, and automatically remediate configuration gaps, misconfigurations, and underutilized defenses. - **Entity Type**: Private (Series A) - **Headquarters**: San Francisco, California, USA - **Founded**: 2021 - **Founders**: Garrett Hamilton (CEO) and Colt Blackmore (CTO) ## Core Business - **Primary industry/industries**: Cybersecurity (Computer and Network Security) - **Target customers**: Enterprise security teams (B2B) - **Mission or purpose statement**: To help organizations find and fix the hidden risks their existing tools miss, transforming exposure insight into action and empowering a more resilient, proactive approach to cybersecurity. ## Products & Services - **Reach Platform (AI-Native Security Controls Operating System)**: A unified platform that integrates with identity, endpoint, email, and network security tools to analyze billions of configuration and security data points. It identifies blind spots, prioritizes fixes, and automatically remediates misconfigurations and configuration drift. The platform encompasses Threat Exposure Management, Security Posture Management, and Configuration Management. ## Market Standing - **Valuation/Market Cap**: Not publicly available - **Key Metric**: Total Funding: $30M USD - **Notable Investors/Partners**: Ballistic Ventures (led Series A), M12 - Microsoft's Venture Fund (led subsequent Series A), Silver Buckshot Ventures. Backed by industry luminaries including Barmak Meftah (General Partner, Ballistic Ventures), Mark McLaughlin (Ex-CEO/Chairman, Palo Alto Networks), Godfrey Sullivan (Ex-CEO, Splunk), and Nicole Perlroth (Author & Cybersecurity Journalist). - **Growth Signals**: Named "Best CTEM Solution 2026," recognized as a "Market Disruptor in Configuration Risk Intelligence," and a "Representative Provider of ASCA in 2026." The company has grown to approximately 70 employees. It has been recognized in a Gartner® Emerging Tech Report on Domain-Specific Language Models for SecOps. ## Competitive Advantages - **Domain-Specific AI**: The platform uses a purpose-built cybersecurity AI that understands security controls and attacker techniques, enabling it to identify misconfigurations and underutilized defenses that generic AI and manual reviews miss. - **Action-Oriented Platform**: Unlike traditional approaches that only surface issues, Reach drives prioritized, guided remediation and can automatically execute validated fixes across the security ecosystem. - **Continuous Monitoring**: The platform continuously detects and remediates configuration drift, helping organizations stay aligned to policy and prevent regressions. - **Rapid Time-to-Value**: The company claims results can be achieved in less than 5 days from account creation. ## Strategic Focus - **Hardening Existing Investments**: The core strategy is to help organizations make better use of the security tools they already have, closing gaps without adding operational burden or new complexity. - **AI-Powered Defense**: The company is focused on leveraging domain-specific AI models to harden security controls at a scale humans alone cannot achieve, specifically to counter AI-powered attacks. - **Proactive Security**: Shifting organizations from reactive security to a proactive, continuous posture management model. ## Why Work Here - **Culture**: The company fosters a collaborative and innovative work culture where every team member is encouraged to contribute ideas, take ownership of projects, and grow within their role. Values include creativity, transparency, and a passion for solving complex security challenges. - **Impactful Work**: Employees work on a high-impact mission to proactively defend organizations from cyber threats at a machine-speed scale. - **Team**: The team is composed of experts from leading security companies (Palo Alto Networks, Proofpoint, Cylance, Splunk, Sysdig), innovative startups, and FAANG, many with hands-on security practitioner experience. - **Remote/Hybrid/Office**: The company is headquartered in San Francisco and has an office presence, but offers remote flexibility for some roles (e.g., Senior Software Engineer roles are listed as remote). The typical time on-site is described as "None" for some roles, while the company also has an "OnSite Workspace." - **Engineering Culture**: Engineering is a large department (36% of staff). The leadership includes a Senior VP of Engineering with experience scaling teams at Lacework and Sysdig, and a VP of Engineering. The tech stack and specific engineering practices are not publicly detailed, but the focus on AI and data platform engineering suggests a modern, data-intensive environment. ## Sources 1. [reach.security](https://www.reach.security/) 2. [reach.security/company](https://www.reach.security/company) 3. [linkedin.com/company/reach-security](https://www.linkedin.com/company/reach-security) 4. [builtin.com/company/reach-security](https://builtin.com/company/reach-security) ## Other roles at Reach Security - [Principal Support Engineer - Endpoint](https://feeny.ai/job/principal-support-engineer-endpoint-reach-security-remote-88qp8nfpnd7s) - [Senior Staff Security Researcher](https://feeny.ai/job/senior-staff-security-researcher-reach-security-san-francisco-s6qhnt1bywzs) — San Francisco, CA - [Senior Staff Software Engineer (Integrations)](https://feeny.ai/job/senior-staff-software-engineer-integrations-reach-security-san-francisco-vb4xg03wszpb) — San Francisco, CA - [Senior Staff Software Engineer (Data Platform)](https://feeny.ai/job/senior-staff-software-engineer-data-platform-reach-security-san-francisco-jbcac296dnsp) — San Francisco, CA - [Staff Software Engineer (Backend)](https://feeny.ai/job/staff-software-engineer-backend-reach-security-san-francisco-1gvwjjsth9ef) — San Francisco, CA