Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation
Cloud Platform
Cloud Platforms
Cloud Solutions
Consultant
Cybersecurity Tools
Digital Transformation
Identity and Access Management
Information Security
Sase/ztna
Security
Security Automation
Solution Architecture
Splunk
Splunk Enterprise Security
Zero Trust Architecture
Zscaler
Zscaler Digital Experience
Job Description
Role context: Senior Consultant focused on guiding clients through modernizing network security with cloud-delivered zero-trust architectures (ZIA and ZPA) across on‑premises and cloud environments within the Deloitte Cyber practice.
Location
Cincinnati, OH (onsite)
Compensation
USD 105,400 - 207,800 per year
Responsibilities
- Design, deploy, and operate ZIA and ZPA capabilities across enterprise client environments
- Lead zero trust network access transformations, including replacement of legacy VPN infrastructure and modernization of access controls
- Configure and optimize Zscaler security features, including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud‑based traffic inspection
- Implement branch, cloud, and application connector architectures across on‑premises and cloud environments, including AWS, Azure, and GCP
- Develop technical deliverables, solution designs, and client‑facing recommendations aligned to enterprise security, network transformation, and operational requirements
Requirements
- BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience
- Zscaler Digital Transformation Engineer (ZDTE) certification required
- 5+ years of progressively responsible experience in network security engineering
- 5+ years of hands‑on experience designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies in enterprise environments
- 5+ years of hands‑on experience designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust network access architectures replacing legacy VPN infrastructure
- 1+ years of experience designing, deploying, and managing Zscaler Branch Connector, and configuring BGP/static routing configurations and network segmentation, replacing traditional SD‑WAN platforms
- 1+ years of experience designing, deploying, and managing Zscaler Cloud Connector, including deployment within cloud environments (AWS, Azure, and/or GCP), workload‑to‑internet and workload‑to‑workload traffic inspection, and integration with cloud‑native networking constructs (VPCs, VNets, Transit Gateways)
- 3+ years of experience configuring and tuning Zscaler advanced security features, including Cloud Sandboxing, Advanced Threat Protection (ATP), Intrusion Prevention (IPS), Cloud Browser Isolation (CBI), and Data Loss Prevention (DLP) policies
- 3+ years of experience implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling of certificate‑pinned applications
- 1+ years of experience with Zscaler AI-powered capabilities, including AI‑driven policy recommendations, Digital Experience Monitoring (ZDX), and leveraging Zscaler's AI/ML threat intelligence for automated threat response
- 3+ years of experience defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle management, access reviews, and RBAC within the Zscaler Admin Portal
- Experience implementing ZIdentity for centralized identity management
- 3+ years of experience with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors within cloud‑native architectures
- 3+ years of experience deploying Zscaler Cloud Connector
- Experience integrating Zscaler with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response workflows
- Experience with Zscaler APIs and automation tooling (e.g., Terraform, Ansible, Python) for provisioning, policy management, and infrastructure‑as‑code workflows
- Experience designing and presenting Zscaler solution architectures tailored to client requirements, translating technical concepts for executive and non‑technical stakeholders
- Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM‑based authentication within ZIA and ZPA deployments
- Ability to travel up to 50% on average based on client assignments and industry served
- Limited immigration sponsorship may be available
- Ability to work independently and as part of a team, with effective written and verbal communication skills
- Meticulous attention to detail and quality of work, ability to build and sustain professional relationships
- Ability to lead projects or workstreams and manage multiple tasks in a fast‑paced environment
Technologies
- Zscaler Internet Access (ZIA)
- Zscaler Private Access (ZPA)
- Zscaler Branch Connector
- Zscaler Cloud Connector
- AWS, Microsoft Azure, Google Cloud Platform (GCP)
- Zscaler Digital Experience (ZDX)
- Zscaler AI powered capabilities
- Zscaler APIs
- Terraform, Ansible, Python
- Splunk, Microsoft Sentinel, Palo Alto XSOAR
- Okta, Azure AD, Ping Identity
- SAML/SCIM based authentication
- VPCs, VNets, Transit Gateways
- SSL/TLS inspection
- Cloud Sandboxing, ATP, IPS, CBI, DLP
- ZIdentity
The Team
Our Enterprise Security offering weaves security into every phase of digital transformation, protecting a client’s technical backbone while enabling secure innovation. The practice encompasses security architecture, secure development and deployment, end‑to‑end cyber cloud capabilities, application security, and protections for emerging technologies and connected products.