Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation
Job Description
Senior Consultant in Deloitte's Cyber Enterprise Security group focused on modernizing network security with cloud-delivered zero trust architectures using Zscaler across on premise and cloud environments.
RESPONSIBILITIES
- Design, deploy, and manage ZIA and ZPA capabilities across enterprise client environments
- Support zero trust network access transformations, replacing legacy VPNs and updating access controls
- Configure and optimize Zscaler security features including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection
- Implement branch, cloud, and application connectors across on‑premises and cloud setups (AWS, Azure, GCP)
- Develop technical deliverables, solution designs, and client-facing recommendations aligned to security, network transformation, and operations requirements
REQUIREMENTS
- BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience
- Zscaler Digital Transformation Engineer (ZDTE) certification is required
- 5+ years of progressively responsible experience in network security engineering
- 5+ years designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and ATP/DLP policies in enterprise-scale environments
- 5+ years designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust architectures replacing legacy VPNs
- 1+ years designing, deploying, and managing Zscaler Branch Connector with BGP/static routing and network segmentation to replace traditional SD-WAN platforms
- 1+ years designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, GCP) with workload-to-internet and workload-to-workload inspection and integration with VPCs, VNets, and Transit Gateways
- 3+ years configuring and tuning advanced Zscaler security features including Cloud Sandboxing, Advanced Threat Protection, IPS, Cloud Browser Isolation, and DLP policies
- 3+ years implementing and troubleshooting SSL/TLS inspection within ZIA, covering certificate management, decryption policy design, bypass rules, and handling certificate-pinned applications
- 1+ years working with Zscaler AI capabilities, including AI-driven policy recommendations, Digital Experience Monitoring (ZDX), and AI/ML threat intelligence for automated responses
- 3+ years defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle, access reviews, and RBAC in the Admin Portal
- Experience implementing ZIdentity for centralized identity management
- 3+ years with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors in cloud-native architectures
- 3+ years deploying Zscaler Cloud Connector
- Experience integrating Zscaler with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and response workflows
- Experience with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning, policy management, and infrastructure-as-code workflows
- Experience designing and presenting Zscaler architectures tailored to client requirements and communicating concepts to executives and non-technical stakeholders
- Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM-based authentication in ZIA and ZPA
- Ability to travel up to 50 percent, depending on client engagement
- Limited immigration sponsorship may be available
TECHNOLOGIES
- Zscaler Internet Access (ZIA)
- Zscaler Private Access (ZPA)
- Zscaler Branch Connector
- Zscaler Cloud Connector
- ZDX
- AWS, Microsoft Azure, Google Cloud Platform (GCP)
- Terraform, Ansible, Python
- Splunk, Microsoft Sentinel, Palo Alto XSOAR
- Okta, Azure AD, Ping Identity
- ZIdentity
BENEFITS
- Discretionary annual incentive program
THE TEAM
Our Enterprise Security offering integrates security across digital transformation, safeguarding a client’s technical backbone while enabling secure, accelerated modernization. The practice spans security architecture, secure development and deployment, cloud security, application security, and security for emerging technologies and connected products.
PREFERRED QUALIFICATIONS
- Advanced cybersecurity certifications such as CISSP, CCIE Security, CCNP Security, or GIAC equivalents (e.g., GPEN, GCSA)
- Ability to conduct SASE vendor competitive analyses and advise clients on solution choices based on use cases (for example Zscaler vs. Palo Alto Prisma vs. Netskope)
- Capability to perform Zero Trust Architecture assessments and develop roadmaps aligning Zscaler capabilities with NIST SP 800-207 or CISA Zero Trust Maturity Model frameworks
- Previous consulting or Big 4 experience with a track record delivering enterprise network security or SASE transformation engagements