Cyber Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation
Job Description
Based in Atlanta, this onsite role offers a path to modernize enterprise security through cloud-delivered zero trust. The position carries a salary range of USD 105,400 to 207,800 per year and is located in the Atlanta, GA area. You will design, deploy, and optimize Zscaler capabilities to strengthen security posture while improving user access experiences.
Our Enterprise Security offering embeds security across digital transformation by protecting a client’s technical backbone while enabling secure evolution. It spans security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and protection for emerging technologies and connected products.
Responsibilities
- Design, deploy, and manage ZIA and ZPA across enterprise client environments.
- Support zero trust network access transformations, replacing legacy VPNs and modernizing access controls.
- Configure and optimize Zscaler security features, including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection.
- Implement branch, cloud, and application connector architectures across on‑premises and cloud environments (AWS, Azure, GCP).
- Develop technical deliverables, solution designs, and client-facing recommendations aligned to enterprise security, network transformation, and operational requirements.
Requirements
- BA/BS degree in a technical field or equivalent work experience.
- Zscaler Digital Transformation Engineer (ZDTE) certification is required.
- 5+ years of progressively responsible experience in network security engineering.
- 5+ years of hands-on experience designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and ATP/DLP policies in enterprise-scale environments.
- 5+ years of hands-on experience designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and ZTNA architectures replacing legacy VPNs.
- 1+ years designing, deploying, and managing Zscaler Branch Connector, including BGP/static routing configurations and network segmentation to replace traditional SD-WAN platforms.
- 1+ years designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, GCP), including workload-to-internet and workload-to-workload traffic inspection and integration with cloud networking constructs (VPCs, VNets, Transit Gateways).
- 3+ years configuring and tuning Zscaler advanced security features such as Cloud Sandboxing, ATP, IPS, CBI, and DLP policies.
- 3+ years implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling certificate-pinned applications.
- 1+ years experience with Zscaler AI-powered capabilities, including AI-driven policy recommendations, ZDX, and AI/ML-based threat intelligence for automated responses.
- 3+ years defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle, access reviews, and RBAC in the Zscaler Admin Portal.
- Experience implementing ZIdentity for centralized identity management.
- 3+ years with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors in cloud-native architectures.
- 3+ years deploying Zscaler Cloud Connector.
- Experience integrating Zscaler with SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response.
- Experience working with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning and configuration-as-code workflows.
- Experience designing and presenting Zscaler solution architectures tailored to client requirements for executive and non-technical stakeholders.
- Familiarity with identity providers (Okta, Azure AD, Ping Identity) for SAML/SCIM-based authentication within ZIA and ZPA.
- Ability to travel up to 50 percent, on average, based on client assignments.
- Limited immigration sponsorship may be available.
- Ability to work independently and as part of a team, with strong written and verbal communication skills.
- Meticulous attention to detail, relationship-building, and the ability to lead projects or workstreams.
- Ability to manage multiple priorities in a fast-paced environment and meet deadlines.
- Professional demeanor with strong interpersonal skills and the ability to provide clear guidance to others.
Technologies
- Zscaler products: ZIA, ZPA, Zscaler Branch Connector, Zscaler Cloud Connector
- Security features: SSL/TLS inspection, Cloud Sandbox, ATP, IPS, CBI, DLP, ZDX
- Cloud platforms: AWS, Azure, GCP; networking: VPCs, VNets, Transit Gateways
- Identity and access: ZIdentity, Okta, Azure AD, Ping Identity
- Automation and IaC: Terraform, Ansible, Python
- SIEM/SOAR integrations: Splunk, Microsoft Sentinel, Palo Alto XSOAR
- APIs and tooling for policy management and provisioning
- Cloud-native networking constructs and integration with cloud services
The Team
Our Enterprise Security offering embeds security across digital transformation by protecting a client’s technical backbone while enabling secure evolution. It spans security architecture, secure development and deployment, end-to-end cyber cloud capabilities, application security, and protection for emerging technologies and connected products.
Salary and Location
Location: Atlanta, GA onsite
Salary: USD 105,400 - 207,800 per year