
ZScaler Engineer β part-time
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
β’ Design and create enterprise Zscaler Private Access (ZPA) architectures, encompassing App Connector placement, redundancy, capacity planning, application segments, access policies, and naming conventions.
β’ Configure and secure the ZPA tenant utilizing least-privilege administrative roles, suitable administrator authentication protocols, and secure platform configuration standards.
β’ Develop and implement Zscaler Client Connector settings that work alongside third-party agency VPN clients.
β’ Design and maintain Client Connector and ZPA Browser Access solutions.
β’ Engineer DNS and application access setups, including internal FQDN design, connector-side DNS resolution, application segmentation, and controls to prevent external agencies from directly accessing internal DNS infrastructure.
β’ Validate end-to-end brokered application connectivity through Zscaler and the enterprise data center to secure applications.
β’ Integrate ZPA with enterprise identity services, including SAML federation with Okta and identity/group mappings.
β’ Configure Zscaler Log Streaming Service (LSS) and integrate ZPA activity and security logging with Rapid7 InsightIDR or similar SIEM platforms.
β’ Develop repeatable migration processes for onboarding organizations and applications, covering publishing, identity/group mapping, VPN or tunnel cutover, validation, rollback, and decommissioning.
β’ Produce comprehensive as-built documentation detailing the production ZPA tenant, App Connectors, application segments, policies, security hardening, and supporting configurations.
β’ Create operational runbooks and troubleshooting procedures.
β’ Provide technical guidance, knowledge transfer, train-the-trainer sessions, and post-deployment hypercare support to internal engineering and security teams.
β’ Proven hands-on experience in designing, deploying, configuring, and supporting Zscaler Private Access (ZPA) in enterprise settings.
β’ Solid understanding of Zero Trust Network Access (ZTNA) principles and the transition from traditional VPN or network-level access to application-centric, identity-aware access controls.
β’ Experience in deploying and troubleshooting Zscaler Client Connector, especially in environments where it must coexist with other endpoint VPN technologies.
β’ Experience in architecting and managing ZPA App Connectors, App Connector Groups, application segments, segment groups, access policies, and Browser Access.
β’ Strong knowledge of enterprise networking concepts, including DNS, routing, firewall rules, TCP/IP, application connectivity, proxy technologies, VPNs, and data center connectivity.
β’ Experience with enterprise identity federation and access management technologies, preferably Okta, SAML, MFA, identity groups, and identity-based access policies.
β’ Experience integrating Zscaler logging and telemetry with SIEM or security analytics platforms; familiarity with Zscaler LSS and Rapid7 InsightIDR is highly desirable.
β’ Ability to perform end-to-end troubleshooting across endpoints, Zscaler services, App Connectors, enterprise networks, identity systems, and protected applications.
β’ Experience in designing highly available and scalable ZPA environments, including connector sizing, redundancy, bandwidth planning, and capacity planning for large user populations.
β’ Experience in developing migration plans and executing phased or wave-based migrations involving multiple independent organizations or business units.
β’ Excellent documentation skills with experience creating solution designs, as-built documentation, administrator runbooks, deployment guides, troubleshooting procedures, and end-user documentation.
β’ Ability to communicate technical concepts effectively to audiences with varying levels of expertise.
β’ Experience in conducting technical knowledge-transfer sessions and transitioning newly implemented platforms to operational support teams.
β’ Ability to coordinate activities across parallel identity, networking, security, application, and third-party vendor workstreams.
β’ Preferred: Zscaler certifications such as Zscaler Certified Engineer/Administrator in ZPA or Zero Trust Access.
β’ Relevant networking or cybersecurity certifications and prior experience in government, public safety, criminal justice, or other highly regulated environments would be advantageous.
β’ Competitive salary, paid bi-monthly.
β’ Exceptional medical coverage.
β’ 100% of medical premiums covered by True Zero.
β’ Company-wide new business incentive programs.
β’ Contribution Incentives (e.g., white papers, blog posts, internal webinars, etc.).
β’ 3 weeks of PTO plus 11 Paid Holidays Annually.
β’ 401k Program with a 100% company match on the first 4%.
β’ Monthly reimbursement for Cell Phone and Home Internet expenses.
β’ Paternity/Maternity Leave.
β’ Investment in training and certifications to enhance and expand your technical skills.
Mercor
RTX
Expel
Qualus
Get handpicked remote jobs straight to your inbox weekly.