Cyber Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation
Job Description
Join Deloitte's Cyber practice in Cleveland, onsite, to help clients modernize network security through cloud-delivered zero trust architectures. In the Cyber Zscaler Network Security Engineer / Senior Consultant role, you will design, deploy, and optimize Zscaler capabilities across complex enterprise environments, guiding security transformations from strategy through implementation. This onsite position in Cleveland, OH offers a salary range of USD 105,400 to 207,800 per year and requires a technical BA/BS with at least 1 year of relevant experience.
Responsibilities
- Plan, deploy, and operate Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) across enterprise client environments.
- Support zero trust network access transformations by migrating from legacy VPNs and updating access controls.
- Configure and tune Zscaler security features, including policy management, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection.
- Deploy branch, cloud, and application connectors across on‑premises and cloud environments (AWS, Azure, GCP).
- Produce technical deliverables, solution designs, and client-facing recommendations aligned with enterprise security, network transformation, and operational requirements.
Requirements
- Bachelor’s degree in a technical field or equivalent work experience (e.g., Computer Science, Cyber Security, Information Technology).
- Zscaler Digital Transformation Engineer (ZDTE) certification is required.
- Five or more years of progressively responsible experience in network security engineering.
- Five or more years of hands-on experience designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies in enterprise-scale environments.
- Five or more years of hands-on experience designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust network access architectures replacing legacy VPN infrastructure.
- One or more years designing, deploying, and managing Zscaler Branch Connector with BGP/static routing configurations and network segmentation, replacing traditional SD-WAN platforms.
- One or more years designing, deploying, and managing Zscaler Cloud Connector, including deployments within AWS, Azure, or GCP, workload-to-internet and workload-to-workload inspection, and integration with cloud-native networking constructs (VPCs, VNets, Transit Gateways).
- Three or more years configuring and tuning Zscaler advanced security features (Cloud Sandboxing, ATP, IPS, CBI, DLP policies).
- Three or more years implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling certificate-pinned applications.
- One or more years working with Zscaler AI-powered capabilities, including AI-driven policy recommendations, Digital Experience Monitoring (ZDX), and AI/ML-based threat intelligence for automated threat response.
- Three or more years defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle management, access reviews, and RBAC in the Zscaler Admin Portal.
- Experience implementing ZIdentity for centralized identity management.
- Three or more years with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors in cloud-native architectures.
- Three or more years deploying Zscaler Cloud Connector.
- Experience integrating Zscaler with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response workflows.
- Experience with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning, policy management, and configuration-as-code workflows.
- Experience designing and presenting Zscaler solution architectures tailored to client requirements, translating technical concepts for executive and non-technical stakeholders.
- Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM-based authentication within ZIA and ZPA deployments.
- Ability to travel up to 50 percent on average based on client engagements.
- Limited immigration sponsorship may be available.
Technologies
- Zscaler Internet Access (ZIA)
- Zscaler Private Access (ZPA)
- Zscaler Branch Connector
- Zscaler Cloud Connector
- Zscaler AI-powered capabilities
- ZDX
- Cloud Sandboxing
- Advanced Threat Protection (ATP)
- Intrusion Prevention (IPS)
- Cloud Browser Isolation (CBI)
- Data Loss Prevention (DLP)
- SSL/TLS inspection
- Zscaler APIs
- Terraform
- Ansible
- Python
- Splunk
- Microsoft Sentinel
- Palo Alto XSOAR
- Okta
- Azure AD
- Ping Identity
- ZIdentity
- AWS
- GCP
- Azure
- SAML
- SCIM
Benefits
- Discretionary annual incentive program eligibility
Preferred Qualifications
- Advanced cybersecurity certifications such as CISSP, CCIE Security, CCNP Security, or GIAC equivalents (e.g., GPEN, GCSA).
- Ability to conduct SASE vendor competitive analyses and advise clients on solution selection (for example Zscaler vs Palo Alto Prisma vs Netskope).
- Experience conducting Zero Trust Architecture assessments and developing roadmaps aligned to NIST SP 800-207 or the CISA Zero Trust Maturity Model.
- Previous consulting or Big Four experience with a track record delivering enterprise network security or SASE transformation engagements.