Skip to content

Open nowPosted 6 hours ago

Principal Network Engineer

Hasbro121 open roles

Where
Montréal
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Network EngineerHasbro · Montréal
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Hasbro's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Hasbro postings stay open a median of 30 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 6 hours ago

Hasbro median: 30 days open

The posting

We take play seriously. We’re looking for curious adventurers ready to find their party, fueled by imagination and drive to build what’s never been built before. At Hasbro and Wizards of the Coast, you’ll collaborate with passionate teams to reimagine our iconic brands and create experiences that spark joy, connection, and community through the magic of play. This is your chance to shape legendary play that lasts a lifetime.

At Wizards of the Coast, we connect people around the world through play and imagination. From our genre-defining games like Magic: The Gathering® and Dungeons & Dragons® to our growing multiverse, we continue to innovate and build new ways to foster friendship and connection. That’s where you come in!

We seek a Principal Network Engineer to serve as the technical lead for our enterprise network transformation. This is the highest-level individual contributor role on the Network Engineering team. You will design the Zero Trust Network Access framework, manage our Palo Alto Panorama environment, and make key decisions where complexity and security meet. You will work closely with the Senior Manager of Network & Cloud Infrastructure and partner with IAM, Cloud Infrastructure, and Security teams. Together, you will build a network that verifies identity, checks device posture, and enforces least privilege from edge to cloud! You will bring this project to a definitive close.

What You'll Do:

  • Act as the technical expert for the Network 2.0 ZTNA program — own the architecture, lead build reviews, establish engineering standards, and address any critical issues during implementation.
  • Build and validate the full ZTNA architecture across all primary and international sites — defining network zones, segmentation policy, and device posture requirements that eliminate lateral movement risk.
  • Manage Palo Alto Panorama at the platform level — template hierarchy, device group creation, policy distribution oversight, and configuration drift prevention across all on-premises and cloud-connected NGFWs.
  • Develop the AWS and Palo Alto Panorama cloud integration — detailing how cloud-native firewall policy, VPC topology, and on-premises ZTNA fabric combine within a unified enforcement plane.
  • Lead the Palo Alto Cloud Identity Engine (CIE) architecture (Year 2, joint with IAM): construct the identity-to-network enforcement model, compose the network zone taxonomy, and direct the IP-to-identity rule migration that phases out all IP-based user firewall rules.
  • Direct GlobalProtect architecture decisions — agent configuration, split tunneling policy, certificate trust chain, and version compliance standards upheld through Intune.
  • Develop and keep current the network architecture documents, decision records, and runbook library that the broader team relies on to carry out tasks. You establish the standard; the team adheres to it.
  • Lead the global site topology mapping effort by detailing all international sites. Define the tiered support model and produce the hardware refresh sequencing plan linked to the ZTNA rollout waves.
  • Partner with the Automation / Network Reliability Engineer to build self-healing policy frameworks, Panorama API automation patterns, and CI/CD pipeline standards for network configuration changes.
  • Represent Network Engineering in cross-functional architecture reviews alongside IAM, Cloud Infrastructure, Security, and Central Technology — you bring the network angle in conversations where enterprise architecture is decided.

What You'll Bring:

  • 10+ years of enterprise network engineering with demonstrated depth in large-scale architecture building — not just operations.
  • Advanced knowledge of Palo Alto NGFW and Panorama — template hierarchy, device groups, security policy development, NAT, decryption policy, and multi-vsys environments.
  • Proven ZTNA architecture experience — you have built a ZTNA deployment, not just configured one; you understand the segmentation model, the policy logic, and the failure modes.
  • Comprehensive knowledge of GlobalProtect — covering agent architecture, gateway configuration, certificate trust, split tunneling policy, and troubleshooting issues across diverse endpoint types on a large scale.
  • AWS network architecture hands-on — VPC build, Transit Gateway, Direct Connect, AWS Network Firewall, and cloud-native connectivity patterns that integrate with on-premises enforcement.
  • Understanding of identity-to-network enforcement patterns — how identity signals (Okta groups, Entra device compliance, CIE) translate into firewall policy and how that architecture scales.
  • Grasp of SD-WAN concepts and Prisma SD-WAN or equivalent — intelligent path selection, application-aware routing, and WAN optimization in a multi-site enterprise.
  • Experience authoring network architecture documentation, design decision records, and engineering standards that other engineers can build against with confidence.
  • Ability to work independently as a reliable contributor with a senior manager. You build technical expertise so the manager can focus on the program. You operate without needing close supervision and do not cause it.
  • Clear communicator across technical and non-technical audiences. You can explain a zone segmentation model to a CISO and a Panorama template hierarchy to a junior engineer in the same afternoon.

Nice to Have:

  • Hands-on experience with Palo Alto Cloud Identity Engine (CIE) — integrating Okta or Entra group membership into NGFW policy enforcement.
  • Network automation depth — Python, Ansible, or Panorama API scripting for policy automation, compliance checking, or self-healing configurations.
  • Experience in GCP network configuration — VPC Service Controls, Cloud Armor, or hybrid connectivity models connecting GCP and on-premises ZTNA fabric.
  • Experience working in a multi-studio, multi-site entertainment or gaming enterprise with geographically distributed international infrastructure.
  • Active certifications: PCNSE (Palo Alto Certified Network Security Engineer), ZTNA specialist, or AWS Advanced Networking Specialty.

We are an Equal Opportunity / Affirmative Action Employer Hasbro is committed to equality of opportunity in all aspects of employment. We are committed to making all employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, or any other legally protected status.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. If you have a disability and require assistance in this application process and need to request an accommodation, please contact your recruiter or coordinator.

#Wizards

Employees may be eligible for annual and long-term incentives as part of their overall compensation package, depending on role, location, and eligibility. Benefits and programs may include:

  • Health & Wellness
  • Time Off to Recharge
  • Financial Well-being
  • Life & Family Support
  • Volunteer and Community Initiatives
  • Learning & Development
  • Exclusive Perks

Please review our Applicant Privacy Notice to learn how we collect, use, and protect your personal information in connection with the application process.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Hasbro's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Hasbro's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Hasbro's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.