ZScaler Engineer - part-time (R-00232)
- Remote
- All software engineering jobs
- Telework
- Part-Time
- Engineering & Architecture
About the role
Position Overview
The Zscaler Engineer will support the design, implementation, production deployment, and operational transition of a Zscaler Private Access (ZPA) environment as part of an enterprise identity and secure access modernization initiative. The role will focus on replacing legacy VPN and site-to-site tunnel access with a scalable, Zero Trust–aligned access architecture supporting a large, distributed population of external users and organizations. The initial environment is expected to support approximately 16,600 external users across roughly 1,600 independent agencies, with the architecture designed to accommodate future expansion to the internal workforce.
The engineer will be responsible for translating a validated proof-of-value architecture into a secure production environment, including ZPA tenant configuration, App Connector architecture, application segmentation, access policies, Client Connector and Browser Access strategies, DNS design, identity integration, logging, migration planning, documentation, and knowledge transfer. The position will work closely with cybersecurity, identity, networking, application, helpdesk, and agency stakeholders throughout implementation and rollout.
Job Responsibilities
- Design and implement enterprise Zscaler Private Access (ZPA) architectures, including App Connector placement, redundancy, capacity planning, application segments, access policies, and naming standards.
- Configure and harden the ZPA tenant using least-privilege administrative roles, appropriate administrator authentication requirements, and secure platform configuration standards.
- Develop and implement Zscaler Client Connector configurations that can coexist with third-party agency VPN clients without disrupting access to agency-owned resources.
- Design and support both Client Connector and ZPA Browser Access solutions, selecting the appropriate access method based on user population, application requirements, and endpoint management capabilities.
- Engineer DNS and application access configurations, including internal FQDN design, connector-side DNS resolution, application segmentation, and controls that prevent external agencies from receiving direct access to internal DNS infrastructure.
- Validate end-to-end brokered application connectivity from external endpoints through Zscaler and the enterprise data center to protected applications, including performance, latency, connectivity, and transaction testing.
- Integrate ZPA with enterprise identity services, including SAML federation with Okta and identity/group mappings used to enforce access policies.
- Configure Zscaler Log Streaming Service (LSS) and integrate ZPA activity and security logging with Rapid7 InsightIDR or comparable SIEM/security monitoring platforms.
- Develop repeatable migration procedures for onboarding organizations and applications, including application publishing, identity/group mapping, legacy VPN or tunnel cutover, validation, rollback, and decommissioning activities.
- Produce detailed as-built documentation covering the production ZPA tenant, App Connectors, application segments, policies, security hardening, and supporting configurations.
- Develop operational runbooks and troubleshooting procedures for administrators, helpdesk personnel, technical agency contacts, and other support teams.
- Provide technical guidance and knowledge transfer to internal engineering and security teams, including train-the-trainer sessions and post-deployment hypercare support.
Job Qualifications
- Demonstrated hands-on experience designing, deploying, configuring, and supporting Zscaler Private Access (ZPA) in enterprise environments.
- Strong understanding of Zero Trust Network Access (ZTNA) concepts and replacing traditional VPN or network-level access with application-centric, identity-aware access controls.
- Experience deploying and troubleshooting Zscaler Client Connector, including environments where Client Connector must coexist with other endpoint VPN technologies.
- Experience architecting and administering ZPA App Connectors, App Connector Groups, application segments, segment groups, access policies, and Browser Access.
- Strong knowledge of enterprise networking concepts, including DNS, routing, firewall rules, TCP/IP, application connectivity, proxy technologies, VPNs, and data center connectivity.
- Experience with enterprise identity federation and access management technologies, preferably Okta, SAML, MFA, identity groups, and identity-based access policies.
- Experience integrating Zscaler logging and telemetry with SIEM or security analytics platforms; experience with Zscaler LSS and Rapid7 InsightIDR is highly desirable.
- Ability to perform end-to-end troubleshooting across endpoints, Zscaler services, App Connectors, enterprise networks, identity systems, and protected applications.
- Experience designing highly available and scalable ZPA environments, including connector sizing, redundancy, bandwidth planning, and capacity planning for large user populations. The source specifically requires the architecture to accommodate the initial external population as well as subsequent workforce growth.
- Experience developing migration plans and executing phased or wave-based migrations involving multiple independent organizations or business units.
- Strong documentation skills with experience producing solution designs, as-built documentation, administrator runbooks, deployment guides, troubleshooting procedures, and end-user documentation.
- Ability to communicate technical concepts to audiences with varying levels of expertise, including engineers, cybersecurity teams, support personnel, business stakeholders, and nontechnical external administrators.
- Experience conducting technical knowledge-transfer sessions and transitioning newly implemented platforms to operational support teams.
- Ability to coordinate activities across parallel identity, networking, security, application, and third-party vendor workstreams. Preferred Qualifications:
- Zscaler certifications such as Zscaler Certified Engineer/Administrator in ZPA or Zero Trust Access
- Applicable networking or cybersecurity certifications, and prior experience implementing Zscaler within government, public safety, criminal justice, or other highly regulated environments would be beneficial.
Description as published by True Zero Technologies.