EngineerJobs.io
← Back to all jobs

Job Description

Deloitte is seeking a Cyber Zscaler Network Security Engineer / Senior Consultant to advance enterprise security through Zscaler cloud-delivered zero-trust architectures. This onsite role in Austin, TX focuses on the design, deployment, and optimization of ZIA and ZPA across both on premises and cloud environments. The position offers a salary range of USD 105,400 to 207,800 per year and requires a BA/BS degree in a technical field along with relevant experience.

Responsibilities

  • Design, deploy, and manage Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) across enterprise client environments.
  • Support zero trust network access transformations by replacing legacy VPN infrastructure and modernizing access controls.
  • Configure and optimize Zscaler security features, including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection.
  • Implement branch, cloud, and application connectors across on‑premises and cloud platforms such as AWS, Microsoft Azure, and Google Cloud Platform (GCP).
  • Develop technical deliverables, solution designs, and client-facing recommendations aligned to enterprise security, network modernization, and operational requirements.

Requirements

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience.
  • Zscaler Digital Transformation Engineer (ZDTE) certification is required.
  • 5+ years of progressively responsible experience in network security engineering.
  • 5+ years of hands-on experience designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies in enterprise environments.
  • 5+ years of hands-on experience designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust network access architectures replacing legacy VPNs.
  • 1+ years of experience designing, deploying, and managing Zscaler Branch Connector, with knowledge of BGP/static routing and network segmentation to replace traditional SD-WAN platforms.
  • 1+ years of experience designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, and/or GCP), including workload-to-internet and workload-to-workload traffic inspection and integration with cloud networking constructs.
  • 3+ years of experience configuring and tuning advanced security features such as Cloud Sandboxing, Advanced Threat Protection, Intrusion Prevention, Cloud Browser Isolation, and Data Loss Prevention.
  • 3+ years of experience implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling certificate-pinned applications.
  • 1+ years of experience with Zscaler AI-powered capabilities, including AI-driven policy recommendations and Digital Experience Monitoring (ZDX), plus leveraging AI/ML threat intelligence for automated responses.
  • 3+ years of hands-on experience defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle management, access reviews, and RBAC in the Zscaler Admin Portal.
  • Experience implementing ZIdentity for centralized identity management.
  • 3+ years of experience with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors within cloud-native architectures.
  • 3+ years of experience deploying Zscaler Cloud Connector.
  • Experience integrating Zscaler with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response workflows.
  • Experience with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning, policy management, and configuration-as-code workflows.
  • Experience designing and presenting Zscaler solution architectures tailored to client requirements and translating technical concepts for executive and non-technical stakeholders.
  • Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM-based authentication within ZIA and ZPA deployments.
  • Ability to travel up to 50 percent, depending on client engagement and project requirements.
  • Limited immigration sponsorship may be available.

Technologies

  • Zscaler Internet Access (ZIA)
  • Zscaler Private Access (ZPA)
  • Zscaler Branch Connector
  • Zscaler Cloud Connector
  • Zscaler AI-powered capabilities and ZDX
  • ZIdentity
  • AWS, Microsoft Azure, Google Cloud Platform (GCP)
  • Splunk, Microsoft Sentinel, Palo Alto XSOAR
  • Terraform, Ansible, Python
  • Okta, Azure AD, Ping Identity

Benefits

  • Discretionary annual incentive program eligibility

The Team

Our Enterprise Security offering integrates security across the digital transformation journey, safeguarding a client’s technical backbone while enabling secure modernization. The group encompasses security architecture, secure development and deployment practices, end-to-end cyber cloud capabilities, application security, and protection for emerging technologies and connected products.

Similar Jobs