Senior Zscaler Security Engineer

Posted 13hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Zscaler Security Engineer operating and expanding Zscaler Zero Trust environments for federal agencies. Integrating security, identity, monitoring, and service-management platforms.

Responsibilities:

  • Lead and support implementation of Zero Trust security controls, primarily Zscaler and its integration with enterprise network, identity, device, application, data, and visibility capabilities
  • Configure and integrate ZPA, ZIA, Client Connector, Cloud Firewall, Branch Connector, and related network-security controls
  • Conduct risk assessments, identify vulnerabilities, and develop proactive mitigation strategies
  • Review architectures, integrations, designs, and change requests for alignment with federal requirements, Zero Trust principles, and approved enterprise security architecture
  • Administer and optimize ZIA, ZPA, ZDX, Zidentity, Client Connector, Sandbox, SSL Inspection, Cloud Firewall, URL Filtering, and related Zscaler services
  • Review configurations against vendor-recommended and DHS/HQ baselines; document deviations, risks, and remediation recommendations
  • Design and implement policies for web access, application access, traffic forwarding, SSL/TLS inspection, sandboxing, threat protection, file handling, and user/device-based controls
  • Analyze rule order, policy dependencies, bypasses, exclusions, and catch-all behavior
  • Develop and execute phased implementation, testing, rollback, and validation plans for production changes
  • Troubleshoot Client Connector, authentication, traffic forwarding, application access, policy enforcement, certificates, SSL inspection, and integration issues
  • Align Zscaler deployments with the CISA Zero Trust Maturity Model and organizational Zero Trust strategies
  • Integrate Zscaler with endpoint security, vulnerability management, infrastructure monitoring, identity, SIEM/SOAR, and ITSM platforms
  • Integrate Zscaler with cloud storage and collaboration platforms to enforce secure data access and sharing
  • Document and address information security, cybersecurity architecture, and systems security engineering requirements throughout the acquisition life cycle
  • Participate in security reviews, identify architecture gaps, and develop security risk management plans
  • Advise stakeholders on security modernization, cloud migration, and risk reduction
  • Conduct gap analyses and develop actionable roadmaps for security capability uplift
  • Provide architectural guidance and mentor technical teams on Zscaler and integrated security solutions
  • Work with federal stakeholders, network and security teams, service desk, DHS headquarters, and technology vendors

Requirements:

  • 10+ years of cybersecurity, network-security, or Zero Trust engineering experience, including experience in federal, public-sector, or similarly regulated environments
  • 3+ years of substantial hands-on experience administering, configuring, and troubleshooting Zscaler capabilities, particularly ZIA and ZPA
  • Demonstrated experience with Zscaler policy design, rule ordering, SSL/TLS Inspection, sandboxing, traffic forwarding, URL filtering, application access, certificates, and Client Connector
  • Experience implementing production changes through documented testing, approvals, rollback planning, validation, and change control
  • Experience with REST APIs and scripting languages such as Python or PowerShell
  • Excellent communication skills to internal and external stakeholders and ability to adjust messaging to varied audiences
  • Consultative mindset and ability to map solutions against client challenges
  • BA/BS degree or equivalent experience
  • Must be a US Citizen and able to obtain a US Government security clearance/public trust
  • Preferred: Zscaler Certified Cloud Professional (ZCCP), Zscaler Certified Cloud Administrator (ZCCA), CISSP, CISM, CCSP, Azure Security Specialty
  • Preferred: Experience in federal government or regulated industry environments
  • Preferred: Knowledge of secure cloud adoption frameworks and hybrid environment security
  • Preferred: Experience with GitLab or comparable source-control and CI/CD tooling
  • Preferred: Familiarity with Jira and Confluence for work tracking, technical documentation, and lifecycle management
  • Preferred: Experience creating operational dashboards, alerting workflows, runbooks, and security-response procedures