
Senior Zscaler Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Oversee and assist in the deployment of Zero Trust security measures, focusing on Zscaler and its integration with enterprise networks, identities, devices, applications, data, and visibility features.
• Set up and integrate ZPA, ZIA, Client Connector, Cloud Firewall, Branch Connector, and associated network-security measures.
• Perform risk assessments, pinpoint vulnerabilities, and create proactive mitigation strategies.
• Evaluate architectures, integrations, designs, and change requests to ensure compliance with federal standards, Zero Trust principles, and established enterprise security architecture.
• Manage and enhance ZIA, ZPA, ZDX, Zidentity, Client Connector, Sandbox, SSL Inspection, Cloud Firewall, URL Filtering, and other related Zscaler services.
• Inspect configurations against vendor-recommended guidelines and DHS/HQ baselines; document any deviations, risks, and suggested remediation steps.
• Craft and enforce policies related to web access, application access, traffic forwarding, SSL/TLS inspection, sandboxing, threat protection, file handling, and user/device-based controls.
• Examine rule order, policy interdependencies, bypasses, exclusions, and overall catch-all behavior.
• Formulate and implement phased plans for deployment, testing, rollback, and validation of production changes.
• Diagnose issues related to Client Connector, authentication, traffic forwarding, application access, policy enforcement, certificates, SSL inspection, and integration.
• Align Zscaler implementations with the CISA Zero Trust Maturity Model and the organization’s Zero Trust strategies.
• Integrate Zscaler with endpoint security, vulnerability management, infrastructure monitoring, identity, SIEM/SOAR, and ITSM platforms.
• Connect Zscaler with cloud storage and collaboration platforms to ensure secure data access and sharing.
• Record and address information security, cybersecurity architecture, and systems security engineering requirements throughout the acquisition lifecycle.
• Engage in security reviews, identify architectural deficiencies, and formulate security risk management plans.
• Provide guidance to stakeholders on security modernization, cloud migration, and risk mitigation.
• Conduct gap analyses and create actionable roadmaps for enhancing security capabilities.
• Offer architectural direction and mentor technical teams on Zscaler and integrated security solutions.
• Collaborate with federal stakeholders, network and security teams, service desk, DHS headquarters, and technology vendors.
• Over 10 years of experience in cybersecurity, network security, or Zero Trust engineering, particularly in federal, public-sector, or similarly regulated environments.
• At least 3 years of significant hands-on experience in administering, configuring, and troubleshooting Zscaler capabilities, especially ZIA and ZPA.
• Proven experience in Zscaler policy design, rule ordering, SSL/TLS Inspection, sandboxing, traffic forwarding, URL filtering, application access, certificates, and Client Connector.
• Experience in implementing production changes through structured testing, approvals, rollback planning, validation, and change control processes.
• Proficiency with REST APIs and scripting languages such as Python or PowerShell.
• Exceptional communication skills to engage with internal and external stakeholders, with the ability to tailor messages for diverse audiences.
• Consultative approach and capability to align solutions with client challenges.
• Bachelor’s degree or equivalent experience required.
• Must be a US Citizen and eligible to obtain a US Government security clearance/public trust.
• Preferred: Zscaler Certified Cloud Professional (ZCCP), Zscaler Certified Cloud Administrator (ZCCA), CISSP, CISM, CCSP, Azure Security Specialty.
• Preferred: Experience in federal government or regulated industry environments.
• Preferred: Familiarity with secure cloud adoption frameworks and hybrid environment security.
• Preferred: Experience with GitLab or similar source control and CI/CD tools.
• Preferred: Knowledge of Jira and Confluence for task tracking, technical documentation, and lifecycle management.
• Preferred: Experience in creating operational dashboards, alerting workflows, runbooks, and security response procedures.
• Comprehensive health, dental, and vision insurance options.
• Retirement savings plan with employer matching contributions.
• Opportunities for professional development and ongoing training.
• Flexible work arrangements and a supportive work environment.
• Generous paid time off and holiday schedule.
OpenLoop
Funcional Health Tech
Salesforce
CNO Financial Group
Get handpicked remote jobs straight to your inbox weekly.