CybersecurityJobs.io
← Back to all jobs

Job Description

This role supports clients in modernizing network security through cloud delivered zero trust architectures. You will design, implement, and optimize Zscaler capabilities across on premises and cloud environments to strengthen security posture, improve user access experiences, and enable secure transformation.

Responsibilities

  • Architect, deploy, and administer Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) across large enterprise environments.
  • Lead zero trust network access transformations, replacing legacy VPNs and updating access control models.
  • Tune and manage Zscaler security functions, including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud based traffic inspection.
  • Design branch, cloud, and application connectors for hybrid deployments spanning on premises and major cloud platforms such as AWS, Azure, and GCP.
  • Produce technical deliverables, solution designs, and client facing recommendations aligned with enterprise security, network modernization, and operational needs.

Requirements

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience.
  • Zscaler Digital Transformation Engineer (ZDTE) certification is required.
  • Five or more years of progressively responsible experience in network security engineering.
  • Five or more years designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies in large-scale environments.
  • Five or more years designing, deploying, and managing ZPA, including application segment configuration, access policies, connectors, and zero trust architectures replacing legacy VPNs.
  • One or more years of experience with Zscaler Branch Connector, including BGP or static routing, network segmentation, and replacing traditional SD-WAN platforms.
  • One or more years designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, and/or GCP) with workload to internet and workload to workload traffic inspection, integrated with cloud networking constructs.
  • Three or more years configuring and tuning advanced Zscaler security features such as Cloud Sandboxing, ATP, IPS, CBI, and DLP policies.
  • Three or more years implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling certificate pinned applications.
  • One or more years of experience leveraging Zscaler AI powered capabilities, including AI driven policy recommendations, Digital Experience Monitoring (ZDX), and AI/ML based threat intelligence for automated responses.
  • Three or more years defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle, access reviews, and RBAC within the Admin Portal.
  • Experience implementing ZIdentity for centralized identity management.
  • Three or more years with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors in cloud native architectures.
  • Three or more years deploying Zscaler Cloud Connector.
  • Experience integrating Zscaler with SIEM or SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response.
  • Experience with Zscaler APIs and automation tools (Terraform, Ansible, Python) for provisioning, policy management, and infrastructure as code workflows.
  • Experience designing and presenting Zscaler solution architectures tailored to client requirements for executive and non-technical stakeholders.
  • Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM based authentication in ZIA and ZPA deployments.
  • Ability to travel up to 50 percent on average based on client engagements.
  • Limited immigration sponsorship may be available.

Technologies

  • Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA)
  • ZTNA, SSL/TLS inspection, Advanced Threat Protection (ATP)
  • Cloud Sandboxing, Cloud Browser Isolation (CBI), Data Loss Prevention (DLP)
  • Zscaler AI powered capabilities, Digital Experience Monitoring (ZDX), ZIdentity
  • Zscaler Cloud Connector, Zscaler Branch Connector, Zscaler Admin Portal
  • Zscaler APIs, Terraform, Ansible, Python
  • AWS, Microsoft Azure, Google Cloud Platform (GCP)
  • Okta, Azure AD, Ping Identity
  • Splunk, Microsoft Sentinel, Palo Alto XSOAR
  • SAML/SCIM, VPCs, VNets, Transit Gateways
  • BGP and static routing

Benefits

  • Discretionary annual incentive program

The Team

Within our Enterprise Security practice, the team integrates security across digital transformation initiatives. The offering encompasses security architecture, secure development and deployment, end-to-end cloud security capabilities, application security, and security for emerging technologies and connected products.

Similar Jobs