EngineerJobs.io
← Back to all jobs

Job Description

Role context: Deloitte seeks a Cyber Zscaler Network Security Engineer / Senior Consultant to modernize enterprise network security with Zscaler across on premise and cloud environments, delivering zero trust architectures and secure transformations. This onsite role is based in Minneapolis, MN, with a salary range of USD 105,400 to 207,800 per year. Candidates should hold a BA/BS in a technical field and have at least 1 year of relevant experience.

Responsibilities

  • Design, deploy, and operate Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) across large client environments.
  • Support zero trust network access transformations, including migrating from legacy VPNs and modernizing access controls.
  • Configure and optimize Zscaler security features such as policy management, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection.
  • Implement branch, cloud, and application connectors across on prem and cloud ecosystems, including AWS, Azure, and GCP.
  • Create technical deliverables, solution designs, and client-facing recommendations aligned to enterprise security, network transformation, and operational needs.

Requirements

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience.
  • Zscaler Digital Transformation Engineer (ZDTE) certification is required.
  • 5+ years of progressively responsible experience in network security engineering.
  • 5+ years of hands-on experience designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies in enterprise-scale environments.
  • 5+ years of hands-on experience designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust architectures replacing legacy VPN infrastructure.
  • 1+ years of experience with Zscaler Branch Connector, including BGP or static routing configurations and network segmentation to replace traditional SD-WAN platforms.
  • 1+ years of experience designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, and/or GCP), including traffic inspection and integration with cloud networking constructs (VPCs, VNets, Transit Gateways).
  • 3+ years of experience configuring and tuning advanced Zscaler security features such as Cloud Sandboxing, Advanced Threat Protection, Intrusion Prevention, Cloud Browser Isolation, and Data Loss Prevention.
  • 3+ years of experience implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling certificate-pinned applications.
  • 1+ years of experience with Zscaler AI-powered capabilities including AI-driven policy recommendations and Digital Experience Monitoring (ZDX), plus leveraging AI/ML threat intelligence for automated responses.
  • 3+ years of hands-on experience defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle management, access reviews, and RBAC within the Zscaler Admin Portal.
  • Experience implementing ZIdentity for centralized identity management.
  • 3+ years of experience with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors in cloud-native architectures.
  • 3+ years of experience deploying Zscaler Cloud Connector.
  • Experience integrating Zscaler with SIEM or SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response.
  • Experience with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning, policy management, and infrastructure-as-code workflows.
  • Experience designing and presenting Zscaler solution architectures tailored to client requirements and translating technical concepts for executive and non-technical stakeholders.
  • Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM based authentication within ZIA and ZPA deployments.
  • Ability to travel up to 50 percent, depending on client engagements.
  • Limited immigration sponsorship may be available.

Technologies

  • Zscaler: ZIA, ZPA, Branch Connector, Cloud Connector
  • Cloud platforms: AWS, Azure, GCP
  • Networking constructs: VPCs, VNets, Transit Gateways
  • Automation and scripting: Terraform, Ansible, Python
  • Security and monitoring: Splunk, Microsoft Sentinel, Palo Alto XSOAR, Zscaler Digital Experience Monitoring (ZDX)
  • Zscaler AI capabilities and ZIdentity
  • Identity providers: Okta, Azure AD, Ping Identity
  • Zscaler APIs and Admin Portal

The Team

Our Enterprise Security offering embeds security across digital transformation efforts by strengthening the technical backbone while enabling secure innovation. The team covers security architecture, secure development and deployment, comprehensive cyber cloud capabilities, application security, and protection for emerging technologies and connected products.

Preferred Qualifications

  • Advanced cybersecurity certifications such as CISSP, CCIE Security, CCNP Security, or GIAC equivalents (e.g., GPEN, GCSA).
  • Ability to perform SASE vendor competitive analyses and advise clients on solution choices based on specific use cases (for example Zscaler versus Palo Alto Prisma or Netskope).
  • Capacity to conduct Zero Trust Architecture assessments and develop roadmaps aligning Zscaler capabilities with NIST SP 800-207 or the CISA Zero Trust Maturity Model.
  • Previous consulting experience or Big Four background with a track record of delivering enterprise network security or SASE transformation engagements.

Similar Jobs