Zscaler Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Position Overview
The Zscaler Engineer will support the design, implementation, production deployment, and operational transition of a Zscaler Private Access (ZPA) environment as part of an enterprise identity and secure access modernization initiative. The role will focus on replacing legacy VPN and site-to-site tunnel access with a scalable, Zero Trust–aligned access architecture supporting a large, distributed population of external users and organizations. The initial environment is expected to support approximately 16,600 external users across roughly 1,600 independent agencies, with the architecture designed to accommodate future expansion to the internal workforce.
The engineer will be responsible for translating a validated proof-of-value architecture into a secure production environment, including ZPA tenant configuration, App Connector architecture, application segmentation, access policies, Client Connector and Browser Access strategies, DNS design, identity integration, logging, migration planning, documentation, and knowledge transfer. The position will work closely with cybersecurity, identity, networking, application, helpdesk, and agency stakeholders throughout implementation and rollout.
Job Responsibilities
- Design and implement enterprise Zscaler Private Access (ZPA) architectures, including App Connector placement, redundancy, capacity planning, application segments, access policies, and naming standards.
- Configure and harden the ZPA tenant using least-privilege administrative roles, appropriate administrator authentication requirements, and secure platform configuration standards.
- Develop and implement Zscaler Client Connector configurations that can coexist with third-party agency VPN clients without disrupting access to agency-owned resources.
- Design and support both Client Connector and ZPA Browser Access solutions, selecting the appropriate access method based on user population, application requirements, and endpoint management capabilities.
- Engineer DNS and application access configurations, including internal FQDN design, connector-side DNS resolution, application segmentation, and controls that prevent external agencies from receiving direct access to internal DNS infrastructure.
- Validate end-to-end brokered application connectivity from external endpoints through Zscaler and the enterprise data center to protected applications, including performance, latency, connectivity, and transaction testing.
- Integrate ZPA with enterprise identity services, including SAML federation with Okta and identity/group mappings used to enforce access policies.
- Configure Zscaler Log Streaming Service (LSS) and integrate ZPA activity and security logging with Rapid7 InsightIDR or comparable SIEM/security monitoring platforms.
- Develop repeatable migration procedures for onboarding organizations and applications, including application publishing, identity/group mapping, legacy VPN or tunnel cutover, validation, rollback, and decommissioning activities.
- Produce detailed as-built documentation covering the production ZPA tenant, App Connectors, application segments, policies, security hardening, and supporting configurations.
- Develop operational runbooks and troubleshooting procedures for administrators, helpdesk personnel, technical agency contacts, and other support teams.
- Provide technical guidance and knowledge transfer to internal engineering and security teams, including train-the-trainer sessions and post-deployment hypercare support.
Job Qualifications
- Demonstrated hands-on experience designing, deploying, configuring, and supporting Zscaler Private Access (ZPA) in enterprise environments.
- Strong understanding of Zero Trust Network Access (ZTNA) concepts and replacing traditional VPN or network-level access with application-centric, identity-aware access controls.
- Experience deploying and troubleshooting Zscaler Client Connector, including environments where Client Connector must coexist with other endpoint VPN technologies.
- Experience architecting and administering ZPA App Connectors, App Connector Groups, application segments, segment groups, access policies, and Browser Access.
- Strong knowledge of enterprise networking concepts, including DNS, routing, firewall rules, TCP/IP, application connectivity, proxy technologies, VPNs, and data center connectivity.
- Experience with enterprise identity federation and access management technologies, preferably Okta, SAML, MFA, identity groups, and identity-based access policies.
- Experience integrating Zscaler logging and telemetry with SIEM or security analytics platforms; experience with Zscaler LSS and Rapid7 InsightIDR is highly desirable.
- Ability to perform end-to-end troubleshooting across endpoints, Zscaler services, App Connectors, enterprise networks, identity systems, and protected applications.
- Experience designing highly available and scalable ZPA environments, including connector sizing, redundancy, bandwidth planning, and capacity planning for large user populations.
- Experience developing migration plans and executing phased or wave-based migrations involving multiple independent organizations or business units.
- Strong documentation skills with experience producing solution designs, as-built documentation, administrator runbooks, deployment guides, troubleshooting procedures, and end-user documentation.
- Ability to communicate technical concepts to audiences with varying levels of expertise, including engineers, cybersecurity teams, support personnel, business stakeholders, and nontechnical external administrators.
- Experience conducting technical knowledge-transfer sessions and transitioning newly implemented platforms to operational support teams.
- Ability to coordinate activities across parallel identity, networking, security, application, and third-party vendor workstreams.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at True Zero Technologies
Explore Top Companies in this Space
Trail of Bits
Cybersecurity / Information Security / Blockchain
Huntress
Cybersecurity / Managed Security / Information Technology
Costello Medical
Healthcare / Medical Communications / Health Economics / Consulting
EAT Club
FoodTech / Corporate Services / Ecommerce / Digital Marketplaces
True Zero Technologies
View Company ProfileTrue Zero Technologies (operating at truezerotech.com) is a cybersecurity platform/company engineered for proactive defense. Founded in 2016 by unknown founders and headquartered in Not specified, True Zero Technologies specializes in creating cybersecurity programs and software solutions that enable agency leaders to run a proactive defense, rather than simply reacting to threats. Under the hood, the company leverages its expertise in comprehensive cybersecurity and consulting services to provide a comprehensive data platform in support of the public sector, health care fields, and commercial customers. This allows federal, SLED & commercial organizations to benefit from proactive cybersecurity measures. Not specified.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
