EngineerJobs.io
← Back to all jobs

Job Description

Role context: Senior Consultant focused on guiding clients through modernizing network security with cloud-delivered zero-trust architectures (ZIA and ZPA) across on‑premises and cloud environments within the Deloitte Cyber practice.

Location

Cincinnati, OH (onsite)

Compensation

USD 105,400 - 207,800 per year

Responsibilities

  • Design, deploy, and operate ZIA and ZPA capabilities across enterprise client environments
  • Lead zero trust network access transformations, including replacement of legacy VPN infrastructure and modernization of access controls
  • Configure and optimize Zscaler security features, including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud‑based traffic inspection
  • Implement branch, cloud, and application connector architectures across on‑premises and cloud environments, including AWS, Azure, and GCP
  • Develop technical deliverables, solution designs, and client‑facing recommendations aligned to enterprise security, network transformation, and operational requirements

Requirements

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience
  • Zscaler Digital Transformation Engineer (ZDTE) certification required
  • 5+ years of progressively responsible experience in network security engineering
  • 5+ years of hands‑on experience designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies in enterprise environments
  • 5+ years of hands‑on experience designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust network access architectures replacing legacy VPN infrastructure
  • 1+ years of experience designing, deploying, and managing Zscaler Branch Connector, and configuring BGP/static routing configurations and network segmentation, replacing traditional SD‑WAN platforms
  • 1+ years of experience designing, deploying, and managing Zscaler Cloud Connector, including deployment within cloud environments (AWS, Azure, and/or GCP), workload‑to‑internet and workload‑to‑workload traffic inspection, and integration with cloud‑native networking constructs (VPCs, VNets, Transit Gateways)
  • 3+ years of experience configuring and tuning Zscaler advanced security features, including Cloud Sandboxing, Advanced Threat Protection (ATP), Intrusion Prevention (IPS), Cloud Browser Isolation (CBI), and Data Loss Prevention (DLP) policies
  • 3+ years of experience implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling of certificate‑pinned applications
  • 1+ years of experience with Zscaler AI-powered capabilities, including AI‑driven policy recommendations, Digital Experience Monitoring (ZDX), and leveraging Zscaler's AI/ML threat intelligence for automated threat response
  • 3+ years of experience defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle management, access reviews, and RBAC within the Zscaler Admin Portal
  • Experience implementing ZIdentity for centralized identity management
  • 3+ years of experience with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors within cloud‑native architectures
  • 3+ years of experience deploying Zscaler Cloud Connector
  • Experience integrating Zscaler with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response workflows
  • Experience with Zscaler APIs and automation tooling (e.g., Terraform, Ansible, Python) for provisioning, policy management, and infrastructure‑as‑code workflows
  • Experience designing and presenting Zscaler solution architectures tailored to client requirements, translating technical concepts for executive and non‑technical stakeholders
  • Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM‑based authentication within ZIA and ZPA deployments
  • Ability to travel up to 50% on average based on client assignments and industry served
  • Limited immigration sponsorship may be available
  • Ability to work independently and as part of a team, with effective written and verbal communication skills
  • Meticulous attention to detail and quality of work, ability to build and sustain professional relationships
  • Ability to lead projects or workstreams and manage multiple tasks in a fast‑paced environment

Technologies

  • Zscaler Internet Access (ZIA)
  • Zscaler Private Access (ZPA)
  • Zscaler Branch Connector
  • Zscaler Cloud Connector
  • AWS, Microsoft Azure, Google Cloud Platform (GCP)
  • Zscaler Digital Experience (ZDX)
  • Zscaler AI powered capabilities
  • Zscaler APIs
  • Terraform, Ansible, Python
  • Splunk, Microsoft Sentinel, Palo Alto XSOAR
  • Okta, Azure AD, Ping Identity
  • SAML/SCIM based authentication
  • VPCs, VNets, Transit Gateways
  • SSL/TLS inspection
  • Cloud Sandboxing, ATP, IPS, CBI, DLP
  • ZIdentity

The Team

Our Enterprise Security offering weaves security into every phase of digital transformation, protecting a client’s technical backbone while enabling secure innovation. The practice encompasses security architecture, secure development and deployment, end‑to‑end cyber cloud capabilities, application security, and protections for emerging technologies and connected products.

Similar Jobs