Cyber Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation
Job Description
Deloitte is seeking a Cyber Zscaler Network Security Engineer / Senior Consultant to advance enterprise security through Zscaler cloud-delivered zero-trust architectures. This onsite role in Austin, TX focuses on the design, deployment, and optimization of ZIA and ZPA across both on premises and cloud environments. The position offers a salary range of USD 105,400 to 207,800 per year and requires a BA/BS degree in a technical field along with relevant experience.
Responsibilities
- Design, deploy, and manage Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) across enterprise client environments.
- Support zero trust network access transformations by replacing legacy VPN infrastructure and modernizing access controls.
- Configure and optimize Zscaler security features, including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection.
- Implement branch, cloud, and application connectors across on‑premises and cloud platforms such as AWS, Microsoft Azure, and Google Cloud Platform (GCP).
- Develop technical deliverables, solution designs, and client-facing recommendations aligned to enterprise security, network modernization, and operational requirements.
Requirements
- BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience.
- Zscaler Digital Transformation Engineer (ZDTE) certification is required.
- 5+ years of progressively responsible experience in network security engineering.
- 5+ years of hands-on experience designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies in enterprise environments.
- 5+ years of hands-on experience designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust network access architectures replacing legacy VPNs.
- 1+ years of experience designing, deploying, and managing Zscaler Branch Connector, with knowledge of BGP/static routing and network segmentation to replace traditional SD-WAN platforms.
- 1+ years of experience designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, and/or GCP), including workload-to-internet and workload-to-workload traffic inspection and integration with cloud networking constructs.
- 3+ years of experience configuring and tuning advanced security features such as Cloud Sandboxing, Advanced Threat Protection, Intrusion Prevention, Cloud Browser Isolation, and Data Loss Prevention.
- 3+ years of experience implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling certificate-pinned applications.
- 1+ years of experience with Zscaler AI-powered capabilities, including AI-driven policy recommendations and Digital Experience Monitoring (ZDX), plus leveraging AI/ML threat intelligence for automated responses.
- 3+ years of hands-on experience defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle management, access reviews, and RBAC in the Zscaler Admin Portal.
- Experience implementing ZIdentity for centralized identity management.
- 3+ years of experience with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors within cloud-native architectures.
- 3+ years of experience deploying Zscaler Cloud Connector.
- Experience integrating Zscaler with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response workflows.
- Experience with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning, policy management, and configuration-as-code workflows.
- Experience designing and presenting Zscaler solution architectures tailored to client requirements and translating technical concepts for executive and non-technical stakeholders.
- Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM-based authentication within ZIA and ZPA deployments.
- Ability to travel up to 50 percent, depending on client engagement and project requirements.
- Limited immigration sponsorship may be available.
Technologies
- Zscaler Internet Access (ZIA)
- Zscaler Private Access (ZPA)
- Zscaler Branch Connector
- Zscaler Cloud Connector
- Zscaler AI-powered capabilities and ZDX
- ZIdentity
- AWS, Microsoft Azure, Google Cloud Platform (GCP)
- Splunk, Microsoft Sentinel, Palo Alto XSOAR
- Terraform, Ansible, Python
- Okta, Azure AD, Ping Identity
Benefits
- Discretionary annual incentive program eligibility
The Team
Our Enterprise Security offering integrates security across the digital transformation journey, safeguarding a client’s technical backbone while enabling secure modernization. The group encompasses security architecture, secure development and deployment practices, end-to-end cyber cloud capabilities, application security, and protection for emerging technologies and connected products.