Cyber Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation
Job Description
Deloitte offers a collaborative, client‑driven environment where security professionals modernize network protection through cloud delivered zero trust architectures. This onsite role in Atlanta focuses on designing, deploying, and optimizing Zscaler capabilities across both on‑premises and cloud environments. You will deliver technical designs, client‑facing recommendations, and enable secure transformation to strengthen security posture while improving user access experiences. Compensation ranges from USD 105,400 to 207,800 per year, plus a discretionary annual incentive program. This position is based on site in Atlanta, GA.
Benefits
- Discretionary annual incentive program
Responsibilities
- Design, deploy, and manage Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) across enterprise client environments
- Support zero trust network access transformations, replacing legacy VPNs and modernizing access controls
- Configure and optimize Zscaler security features including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection
- Implement branch, cloud, and application connector architectures across on‑premises and cloud environments such as AWS, Azure, and Google Cloud Platform
- Develop technical deliverables, solution designs, and client‑facing recommendations aligned to enterprise security, network transformation, and operational requirements
Requirements
- BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology, or equivalent work experience)
- Zscaler Digital Transformation Engineer (ZDTE) certification required
- 5+ years of progressively responsible experience in network security engineering
- 5+ years of hands-on experience designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies in enterprise environments
- 5+ years of hands-on experience designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust network access architectures replacing legacy VPN infrastructure
- 1+ years of experience designing, deploying, and managing Zscaler Branch Connector, including BGP/static routing configurations and network segmentation to replace traditional SD-WAN platforms
- 1+ years of experience designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, and/or GCP), including workload to internet and workload to workload traffic inspection
- 3+ years of experience configuring and tuning Zscaler advanced security features such as Cloud Sandboxing, Advanced Threat Protection, Intrusion Prevention, Cloud Browser Isolation, and Data Loss Prevention
- 3+ years of experience implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management and decryption policy design
- 1+ years of experience with Zscaler AI powered capabilities including AI driven policy recommendations and Digital Experience Monitoring (ZDX)
- 3+ years of hands-on experience defining, managing, and reviewing Zscaler security policies including policy lifecycle and RBAC in the Zscaler Admin Portal
- Experience implementing ZIdentity for centralized identity management
- 3+ years of experience with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors
- 3+ years of experience deploying Zscaler Cloud Connector
- Experience integrating Zscaler with SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog
- Experience with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning and configuration as code
- Experience designing and presenting Zscaler solution architectures tailored to client requirements and communicating effectively to executives
- Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM authentication within ZIA and ZPA
- Ability to travel up to 50 percent
- Limited immigration sponsorship may be available
- Ability to work independently and as part of a team, with strong written and verbal communication skills
- Meticulous attention to detail, professional demeanor, and the ability to manage multiple tasks in a dynamic environment
Technologies
- Zscaler Internet Access (ZIA)
- Zscaler Private Access (ZPA)
- Zscaler Branch Connector
- Zscaler Cloud Connector
- SSL/TLS inspection
- AWS, Azure, GCP
- BGP, VPCs, VNets, Transit Gateways
- Cloud Sandboxing
- Advanced Threat Protection (ATP)
- Intrusion Prevention (IPS)
- Cloud Browser Isolation (CBI)
- Data Loss Prevention (DLP)
- ZDX (Digital Experience Monitoring)
- Zscaler AI powered capabilities
- ZIdentity
- Okta, Azure AD, Ping Identity
- Terraform, Ansible, Python
- Splunk, Microsoft Sentinel, Palo Alto XSOAR
- Zscaler APIs
The Team
Our Enterprise Security practice weaves security into every facet of digital transformation. The team covers security architecture, secure development and deployment, end to end cyber cloud capabilities, application security, and security for emerging technologies and connected products. You will join a culture that values collaboration, rigorous delivery, and a focus on protecting client assets while enabling secure innovation.