EngineerJobs.io
← Back to all jobs

Job Description

Senior Consultant in Deloitte's Cyber Enterprise Security group focused on modernizing network security with cloud-delivered zero trust architectures using Zscaler across on premise and cloud environments.

RESPONSIBILITIES

  • Design, deploy, and manage ZIA and ZPA capabilities across enterprise client environments
  • Support zero trust network access transformations, replacing legacy VPNs and updating access controls
  • Configure and optimize Zscaler security features including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection
  • Implement branch, cloud, and application connectors across on‑premises and cloud setups (AWS, Azure, GCP)
  • Develop technical deliverables, solution designs, and client-facing recommendations aligned to security, network transformation, and operations requirements

REQUIREMENTS

  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology) or equivalent work experience
  • Zscaler Digital Transformation Engineer (ZDTE) certification is required
  • 5+ years of progressively responsible experience in network security engineering
  • 5+ years designing, deploying, and managing ZIA, including web filtering, DNS security, cloud firewall, bandwidth controls, and ATP/DLP policies in enterprise-scale environments
  • 5+ years designing, deploying, and managing ZPA, including application segment configuration, access policies, connector deployment, and zero trust architectures replacing legacy VPNs
  • 1+ years designing, deploying, and managing Zscaler Branch Connector with BGP/static routing and network segmentation to replace traditional SD-WAN platforms
  • 1+ years designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, GCP) with workload-to-internet and workload-to-workload inspection and integration with VPCs, VNets, and Transit Gateways
  • 3+ years configuring and tuning advanced Zscaler security features including Cloud Sandboxing, Advanced Threat Protection, IPS, Cloud Browser Isolation, and DLP policies
  • 3+ years implementing and troubleshooting SSL/TLS inspection within ZIA, covering certificate management, decryption policy design, bypass rules, and handling certificate-pinned applications
  • 1+ years working with Zscaler AI capabilities, including AI-driven policy recommendations, Digital Experience Monitoring (ZDX), and AI/ML threat intelligence for automated responses
  • 3+ years defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle, access reviews, and RBAC in the Admin Portal
  • Experience implementing ZIdentity for centralized identity management
  • 3+ years with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors in cloud-native architectures
  • 3+ years deploying Zscaler Cloud Connector
  • Experience integrating Zscaler with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and response workflows
  • Experience with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning, policy management, and infrastructure-as-code workflows
  • Experience designing and presenting Zscaler architectures tailored to client requirements and communicating concepts to executives and non-technical stakeholders
  • Familiarity with identity provider integrations (Okta, Azure AD, Ping Identity) for SAML/SCIM-based authentication in ZIA and ZPA
  • Ability to travel up to 50 percent, depending on client engagement
  • Limited immigration sponsorship may be available

TECHNOLOGIES

  • Zscaler Internet Access (ZIA)
  • Zscaler Private Access (ZPA)
  • Zscaler Branch Connector
  • Zscaler Cloud Connector
  • ZDX
  • AWS, Microsoft Azure, Google Cloud Platform (GCP)
  • Terraform, Ansible, Python
  • Splunk, Microsoft Sentinel, Palo Alto XSOAR
  • Okta, Azure AD, Ping Identity
  • ZIdentity

BENEFITS

  • Discretionary annual incentive program

THE TEAM

Our Enterprise Security offering integrates security across digital transformation, safeguarding a client’s technical backbone while enabling secure, accelerated modernization. The practice spans security architecture, secure development and deployment, cloud security, application security, and security for emerging technologies and connected products.

PREFERRED QUALIFICATIONS

  • Advanced cybersecurity certifications such as CISSP, CCIE Security, CCNP Security, or GIAC equivalents (e.g., GPEN, GCSA)
  • Ability to conduct SASE vendor competitive analyses and advise clients on solution choices based on use cases (for example Zscaler vs. Palo Alto Prisma vs. Netskope)
  • Capability to perform Zero Trust Architecture assessments and develop roadmaps aligning Zscaler capabilities with NIST SP 800-207 or CISA Zero Trust Maturity Model frameworks
  • Previous consulting or Big 4 experience with a track record delivering enterprise network security or SASE transformation engagements

Similar Jobs