Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation
Job Description
Deloitte's on-site opportunity in San Diego, CA invites senior security professionals to guide enterprise clients through modernizing their network defenses with cloud-delivered zero trust using Zscaler (ZIA and ZPA) across on‑premises and cloud environments. The role sits within Deloitte’s security practice, offering a competitive salary range of USD 105,400 to 207,800 per year and a discretionary annual incentive program.
Benefits
- Discretionary annual incentive program
The Team
Our Enterprise Security offering integrates security across the full spectrum of digital transformation. The practice secures a client’s technical backbone while enabling secure innovation, covering security architecture, secure development and deployment, end-to-end cloud security capabilities, application security, and protection for emerging technologies and connected products.
Responsibilities
- Design, deploy, and operate Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) across large enterprise environments
- Support zero trust network access transformations, including replacing legacy VPNs and modernizing access controls
- Configure and optimize Zscaler security features such as policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud-based traffic inspection
- Implement branch, cloud, and application connectors across on-premises and cloud platforms including AWS, Microsoft Azure, and Google Cloud Platform
- Develop technical deliverables, solution designs, and client-facing recommendations aligned to enterprise security, network transformation, and operational requirements
Requirements
- Ability to work independently and as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Capability to manage and prioritize multiple tasks in a fast-paced environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines and provide clear guidance to others
- BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology, or equivalent experience)
- Zscaler Digital Transformation Engineer (ZDTE) certification required
- 5+ years of progressively responsible experience in network security engineering
- 5+ years hands-on experience designing, deploying, and managing ZIA including web filtering, DNS security, cloud firewall, bandwidth controls, and ATP policies
- 5+ years hands-on experience designing, deploying, and managing ZPA including application segment configuration, access policies, connector deployment, and ZTNA architectures replacing legacy VPNs
- 1+ years experience designing, deploying, and managing Zscaler Branch Connector with BGP/static routing and network segmentation, replacing traditional SD-WAN
- 1+ years experience designing, deploying, and managing Zscaler Cloud Connector in cloud environments (AWS, Azure, and/or GCP) with workload-to-internet and workload-to-workload inspection, integrated with cloud-native networking constructs
- 3+ years configuring and tuning advanced security features such as Cloud Sandboxing, ATP, IPS, CBI, and DLP policies
- 3+ years implementing SSL/TLS inspection within ZIA, including certificate management and decryption policy design
- 1+ years experience with Zscaler AI-powered capabilities, including AI-driven policy recommendations and ZDX
- 3+ years defining, managing, and reviewing Zscaler security policies, including rule base optimization and RBAC in the Admin Portal
- Experience implementing ZIdentity for centralized identity management
- 3+ years with one or more major cloud providers (AWS, GCP, Azure) to deploy ZPA App Connectors within cloud-native architectures
- 3+ years deploying Zscaler Cloud Connector
- Experience integrating Zscaler with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog
- Experience with Zscaler APIs and automation tooling (Terraform, Ansible, Python) for provisioning and policy management
- Experience designing and presenting Zscaler solution architectures tailored to client requirements and communicating with executive and non-technical stakeholders
- Familiarity with identity providers (Okta, Azure AD, Ping Identity) for SAML/SCIM authentication in ZIA and ZPA deployments
- Ability to travel up to 50% as duties and client needs require
- Limited immigration sponsorship may be available
Technologies
- Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), ZTNA
- SSL/TLS inspection, Advanced Threat Protection (ATP), Cloud Sandboxing
- Intrusion Prevention (IPS), Cloud Browser Isolation (CBI), Data Loss Prevention (DLP)
- Zscaler Branch Connector, Zscaler Cloud Connector
- AI powered capabilities, Digital Experience Monitoring (ZDX)
- ZIdentity, Terraform, Ansible, Python
- SIEM/SOAR integrations (Splunk, Microsoft Sentinel, Palo Alto XSOAR)
- Okta, Azure Active Directory, Ping Identity
- AWS, Azure, Google Cloud Platform