Sr Zscaler Security Engineer
Quick Summary
Lead and support the implementation of Zero Trust security controls, with primary responsibility for Zscaler and its integration with enterprise network, identity, device, application, data,
Lead and support the implementation of Zero Trust security controls, with primary responsibility for Zscaler and its integration with enterprise network, identity, device, application, data,
About the Role
~1 min readEasy Dynamics is seeking an experienced Senior Zscaler Security Engineer to support a high-impact Digital Transformation and Zero Trust implementation program. This is a hands-on engineering role responsible for operating, securing, troubleshooting, and expanding an enterprise Zscaler environment across ZIA, ZPA, ZDX, Zidentity, Client Connector, and capabilities such as OneAPI, Data Loss Prevention, Deception, and Branch Connector
The successful candidate will assess and optimize existing Zscaler policies, plan and implement controlled configuration changes, troubleshoot user and traffic-forwarding issues, and integrate Zscaler with enterprise security, monitoring, identity, and service-management platforms. The engineer will work closely with federal stakeholders, network and security teams, the service desk, DHS headquarters, and technology vendors to align the environment with approved baselines, Zero Trust principles, and federal security requirements.
This position requires strong technical execution as well as the ability to translate complex security topics into clear recommendations, implementation plans, change requests, operating procedures, and leadership briefings.
Responsibilities
~2 min read- →Zero Trust Architecture and Implementation:
- →
- →Lead and support the implementation of Zero Trust security controls, with primary responsibility for Zscaler and its integration with enterprise network, identity, device, application, data, and visibility capabilities.
- →
- →Support network segmentation and Zero Trust access strategies by configuring and integrating ZPA, ZIA, Client Connector, Cloud Firewall, Branch Connector, and related network-security controls.
- →
- →Conduct thorough risk assessments, identify vulnerabilities, and develop proactive strategies to mitigate risks in line with Zero Trust principles across network and data domains.
- →
- →Review proposed architectures, integrations, designs, and change requests for alignment with federal requirements, Zero Trust principles and the approved enterprise security architecture.
- →Zscaler Architecture & Configuration:
- →
- →Administer and optimize ZIA, ZPA, ZDX, Zidentity, Client Connector, Sandbox, SSL Inspection, Cloud Firewall, URL Filtering, and related Zscaler services.
- →
- →Review existing Zscaler configurations against vendor-recommended and DHS/HQ baselines; document deviations, risks, and remediation recommendations.
- →
- →Design and implement Zscaler policies for web access, application access, traffic forwarding, SSL/TLS inspection, sandboxing, threat protection, file handling, and user/device-based controls.
- →
- →Analyze rule order, policy dependencies, bypasses, exclusions, and catch-all behavior to safely integrate new requirements into existing production configurations.
- →
- →Develop and execute phased implementation, testing, rollback, and validation plans for Zscaler changes that may affect user access or production traffic.
- →
- →Troubleshoot Zscaler service issues involving Client Connector, authentication, traffic forwarding, application access, policy enforcement, certificates, SSL inspection, and integrations.
- →
- →Align Zscaler deployments with the CISA Zero Trust Maturity Model and organizational Zero Trust strategies.
- →Integration with Enterprise Tools:
- →
- →Integrate Zscaler with endpoint security, vulnerability management, infrastructure monitoring, identity, SIEM/SOAR, and ITSM platforms, including CrowdStrike, Tripwire, Qualys, ScienceLogic, Splunk, ServiceNow/HEAT, Active Directory, and Microsoft Entra ID, as applicable.
- →
- →Implement Zscaler integration with cloud storage and collaboration platforms to enforce secure data access and sharing.
- →Security Strategy & Consulting:
- →
- →Document and address organization's information security, cybersecurity architecture, and systems security engineering requirements throughout the acquisition life cycle
- →
- →Participate in security reviews, identify gaps in security architecture, and develop a security risk management plan
- →
- →Advise stakeholders on best practices for security modernization, cloud migration, and risk reduction.
- →
- →Conduct gap analysis and develop actionable roadmaps for security capability uplift.
- →
- →Provide architectural guidance and mentor technical teams on Zscaler and integrated security solutions.
Requirements
~2 min read- 10+ years of cybersecurity, network-security, or Zero Trust engineering experience, including experience in federal, public-sector, or similarly regulated environments.
- 3+ years of substantial hands-on experience administering, configuring, and troubleshooting Zscaler capabilities, particularly ZIA and ZPA.
- Demonstrated experience with Zscaler policy design, rule ordering, SSL/TLS Inspection, sandboxing, traffic forwarding, URL filtering, application access, certificates, and Client Connector.
- Experience implementing production changes through documented testing, approvals, rollback planning, validation, and change control.
- Experience with REST APIs and scripting languages such as Python or PowerShell.
- Excellent communication skills to internal and external stakeholders – ability to adjust messaging to a variety of audiences (client leadership, technical staff, team members etc.).
- Consultative mindset and ability to map solutions against client challenges.
- BA/BS degree or equivalent experience.
- Must be a US Citizen and able to obtain a US Government security clearance/public trust.
- Industry certifications: Zscaler Certified Cloud Professional (ZCCP), Zscaler Certified Cloud Administrator (ZCCA), CISSP, CISM, CCSP, Azure Security Specialty.
- Experience in federal government or regulated industry environments.
- Knowledge of secure cloud adoption frameworks and hybrid environment security.
- Experience with GitLab or comparable source-control and CI/CD tooling.
- Familiarity with Jira and Confluence for work tracking, technical documentation, and lifecycle management.
- Experience creating operational dashboards, alerting workflows, runbooks, and security-response procedures.
The annual salary range for this position is $125,000- 140,000
Easy Dynamics is an equal opportunity employer. Applicants are considered for positions without discrimination on the basis of race, color, religion, sex, national origin, age, disability, sexual orientation, gender identity, veteran status or any other consideration made unlawful by applicable federal state or local laws.
Location & Eligibility
Listing Details
- First seen
- October 6, 2026
- Last seen
- October 6, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 66%
- Scored at
- October 6, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.