EngineerJobs.io
← Back to all jobs

Job Description

Deloitte is hiring in Detroit on site for a Cyber Zscaler Network Security Engineer / Senior Consultant who will help clients modernize network security with cloud-delivered zero-trust architectures. You will design, deploy, and optimize Zscaler capabilities across both on-premises and cloud environments, strengthening security posture, improving user access experiences, and enabling secure transformation. This role offers a competitive salary range of USD 105,400 to 207,800 per year and a discretionary annual incentive program.

Benefits

  • Discretionary annual incentive program

Responsibilities

  • Design, deploy, and operate Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) across enterprise environments
  • Support zero trust network access transformations by replacing legacy VPNs and modernizing access controls
  • Configure and optimize Zscaler security features, including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection
  • Implement branch, cloud, and application connectors across on‑premises and cloud, including AWS, Azure, and GCP
  • Develop technical deliverables, solution designs, and client-facing recommendations aligned to security, network transformation, and operational requirements

Requirements

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience
  • Zscaler Digital Transformation Engineer (ZDTE) certification required
  • 5+ years of progressively responsible experience in network security engineering
  • 5+ years designing, deploying, and managing ZIA with web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies at enterprise scale
  • 5+ years designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust architectures replacing legacy VPNs
  • 1+ years designing, deploying, and managing Zscaler Branch Connector with BGP/static routing and network segmentation to replace traditional SD-WAN
  • 1+ years designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, and/or GCP) with workload-to-internet and workload-to-workload inspection
  • 3+ years configuring and tuning Zscaler advanced security features (Cloud Sandboxing, ATP, IPS, CBI, DLP)
  • 3+ years implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling certificate-pinned apps
  • 1+ years working with Zscaler AI-powered capabilities, including AI-driven policy recommendations, ZDX, and AI/ML threat intelligence for automated threat response
  • 3+ years defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle, access reviews, and RBAC within the Zscaler Admin Portal
  • Experience implementing ZIdentity for centralized identity management
  • 3+ years of experience with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors within cloud-native architectures
  • 3+ years deploying Zscaler Cloud Connector
  • Experience integrating Zscaler with SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog
  • Experience with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning, policy management, and configuration-as-code workflows
  • Experience designing and presenting Zscaler solution architectures tailored to client requirements for executive and non-technical stakeholders
  • Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM-based authentication in ZIA and ZPA
  • Ability to travel up to 50% on average
  • Limited immigration sponsorship may be available

Technologies

  • Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), ZTNA
  • SSL/TLS inspection, Advanced Threat Protection (ATP), Cloud Sandboxing, Cloud Browser Isolation (CBI), Data Loss Prevention (DLP)
  • Zscaler AI capabilities, Digital Experience Monitoring (ZDX), ZIdentity
  • Zscaler Cloud Connector, Zscaler Branch Connector, Zscaler Admin Portal
  • Zscaler APIs, Terraform, Ansible, Python
  • AWS, Azure, Google Cloud Platform (GCP)
  • Okta, Azure AD, Ping Identity, Splunk, Microsoft Sentinel, Palo Alto XSOAR
  • SAML/SCIM, VPCs, VNets, Transit Gateways, BGP/static routing

The team

Our Enterprise Security offering embeds security across digital transformation initiatives, securing the technical backbone while enabling secure growth. The practice encompasses security architecture, secure development and deployment, end-to-end cloud security capabilities, application security, and security considerations for emerging technologies and connected products.

Similar Jobs