Search Jobs

Search by job, company or skills

Zscaler Network Security Engineer

Zscaler Network Security Engineer

EY
Early Applicant
  • Posted 11 days ago
  • Be among the first 30 applicants

Job Description

At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Security Technology Services – Network Security Technology

Senior Associate – Network Security Engineer | India

EY Technology

Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organizaon the size of ours working eciently and securely. We have more than 400,000 people in over 150 countries, all of whom rely on secure technology to perform their jobs every day.

Everything we use as a rm depends on our security-rst mindset. Our users, applicaons, cloud plaorms, data centers, AI services, and business-crical systems all rely on modern security technologies to enable secure access, protect sensive informaon, and reduce cyber risk.

Within Security Technology Services, our mission is to deliver world-class security engineering capabilies that enable Zero Trust, cloud transformaon, aack surface reducon, and secure digital experiences. If you are passionate about building and engineering security soluons at global scale, we want to hear from you.

The Opportunity

We are looking for a Senior Associate – Network Security Engineer to join Security Technology Services as a hands-on engineering specialist focused on Zscaler Private Access, Zero Trust Network Access, private applicaon onboarding, App Connectors, Private Service Edges, Client Connector integraon, and least-privilege user-to-applicaon access.

This role will report to the Assistant Director and will be responsible for detailed engineering, deployment, conguraon, tesng, troubleshoong, opmizaon and operaonal transion of ZPA services used to securely connect users, devices and applicaons without exposing private applicaons to the internet.

The successful candidate must be able to explain and demonstrate hands-on experience across ZPA applicaon segments, segment groups, server groups, App Connector groups, Private Service Edge deployments, authencaon and identy integraons, DNS, roung, TLS, SAML, SCIM, device posture, Client Connector behavior, live logs, diagnoscs, and end-to-end trac ow troubleshoong.

This role will support engineering iniaves focused on:

  • Zscaler Private Access engineering for secure private applicaon access Design and implementaon of granular ZPA applicaon segments, segment groups and access policies
  • Deployment and support of App Connectors, Private Service Edges and connector groups across cloud and data center environments
  • Least-privilege user-to-applicaon access and migraon from VPN-style network access to applicaon-level access
  • ZPA diagnoscs, policy validaon, operaonal readiness and producon troubleshoong

The role will work closely with Network Security Technology, Cloud Engineering, Identy, Endpoint, Infrastructure, Applicaon and Architecture teams to deploy scalable ZPA capabilies across global enterprise environments.

Your Key Responsibilies

The Senior Associate – Network Security Engineer, Zscaler/ZPA will work under the direcon of the Assistant Director and provide hands-on engineering support for ZPA deployment, integraon, opmizaon, troubleshoong and connuous improvement.

Zscaler Private Access Engineering

  • Build, congure and troubleshoot ZPA constructs including applicaon segments, segment groups, server groups, servers, access policies, connector groups, App Connectors and Private Service Edges.
  • Translate applicaon details such as FQDNs, IPs, TCP/UDP ports, protocols, users, groups and source condions into secure ZPA applicaon access policies.
  • Validate end-to-end trac ows from Client Connector to ZPA Service Edge or Private Service Edge, App Connector, server group and target applicaon.
  • Support onboarding of internal applicaons, administrator services, developer plaorms, privileged access services and business workloads into ZPA.
  • Validate DNS, roung, TLS, IdP, SAML, SCIM, device posture, Client Connector and authencaon integraons required for successful ZPA deployments.
  • Produce low-level implementaon steps, test evidence, troubleshoong notes, rollback consideraons and operaonal handover material.

App Connector and Private Service Edge Deployment

  • Deploy and support App Connectors and Private Service Edges across Azure, VMware and data center environments.
  • Design connector placement, connector groups, resiliency, capacity, plaorm sizing and outbound connecvity requirements.
  • Troubleshoot connector health, registraon, provisioning keys, soware updates, service edge connecvity and tunnel establishment issues.
  • Validate required outbound connecvity, DNS resoluon, cercate handling, NTP, rewall allowlists and roung paths for ZPA components.
  • Work with infrastructure teams to ensure high availability, service resilience and opera supportability for producon ZPA deploymentsonal

Least-Privilege Access and Applicaon Segmentaon

  • Create granular applicaon segments and access policies aligned to least-privilege principles for employees, administrators, vendors, service accounts and support groups.
  • Use ZPA applicaon discovery, policy insights, access logs and diagnoscs to validate user- toapplicaon access paerns.
  • Review exisng access models, idenfy over-permissive access and support migraon from VPN or network-level access to ZPA applicaon-level access.
  • Partner with applicaon, identy and infrastructure teams to conrm business access requirements before policy enforcement.
  • Connuously improve policy quality using logs, dashboards, diagnoscs, access review outputs and producon support ndings.

ZPA Troubleshoong, Diagnoscs and Operaons

  • Troubleshoot ZPA issues using a structured approach across endpoint, Client Connector, identy provider, ZPA policy, Service Edge, App Connector, DNS, roung, rewall and target applicaon layers.
  • Use ZPA live logs, user acvity diagnoscs, user status diagnoscs, applicaon diagnoscs, connector status, Private Service Edge status, service edge health and audit logs to idenfy root cause.
  • Diagnose common scenarios including policy mismatch, unauthencated users, failed SAML claims, missing SCIM groups, connector oine state, DNS resoluon failure, cercate errors, port mismatch, asymmetric roung and applicaon unavailability.
  • Develop structured test plans for applicaon onboarding, policy changes, connector changes, Private Service Edge rollout and producon migraon waves.
  • Document known issues, operaonal procedures, support steps, log locaons, escalaon evidence and rollback consideraons for producon deployments.
  • Drive connuous plaorm improvement through problem management, automaon opportunies and implementaon lessons learned.

Engineering Automaon and Plaorm Opmizaon

  • Build and maintain automaon soluons to improve security engineering eciency.
  • Automate deployment, conguraon validaon and policy management acvies.
  • Ulize Terraform, Python, PowerShell, APIs and Infrastructure-as-Code approaches.
  • Improve plaorm scalability, consistency and operaonal eecveness through automaon.
  • Contribute engineering inputs, deployment feedback and technical validaon to future-state security engineering plans.

Engineering Execuon and Collaboraon

  • Work under the direcon of the Assistant Director to implement approved ZPA engineering paerns and deployment standards.
  • Act as a hands-on escalaon point for Zscaler, ZPA, DNS, TLS, roung, Client Connector and authencaon issues.
  • Collaborate with cloud, data center, identy, applicaon and infrastructure teams during design validaon, pilot and producon rollout.
  • Provide technical guidance to engineers and support teams involved in onboarding applicaons and workloads.
  • Communicate implementaon risks, dependencies and progress clearly to the Assistant Director and project stakeholders.

Technical Interview Focus Areas

Candidates should be prepared to discuss real implementa troubleshoong on examples and demonstrate praccal depth in the following areas:

  • Explain the ZPA connecon ow from user device and Client Connector to Service Edge or Private Service Edge, App Connector and target private applicaon.
  • Design an applicaon segment for a private web applicaon, SSH service, RDP service or administrator portal using FQDNs, ports, server groups, connector groups and access policy rules.
  • Troubleshoot a user who is authencated but unable to access one ZPA applicaon while other applicaons work successfully.
  • Troubleshoot an App Connector or Private Service Edge that is registered but unhealthy, disconnected or unable to reach the target applicaon.
  • Explain how SAML aributes, SCIM groups, identy provider claims, device posture and condional access inputs inuence ZPA access policy decisions.
  • Describe DNS resoluon requirements for ZPA, including internal DNS dependencies, splithorizon DNS paerns and Browser Access consideraons.
  • Explain connector placement and resiliency strategy for Azure, VMware and data center environments.
  • Interpret ZPA logs and diagnoscs to idenfy whether a failure is caused by policy, identy, connector, roung, DNS, TLS, endpoint or target applicaon issues.
  • Explain how to migrate an applicaon from VPN-based network access to ZPA applicaon-level access with tesng, rollback and operaonal readiness steps.
  • Discuss automaon opportunies using APIs, Terraform, Python or PowerShell for repeatable
  • ZPA conguraon, validaon and reporng.

Skills and Aributes for Success

We are interested in candidates who bring deep hands-on ZPA engineering experience from large global enterprise environments and can combine technical execuon with strong implementaon discipline.

As a successful candidate, you will demonstrate:

  • Strong hands-on engineering experse in Zscaler Private Access and Zero Trust Network Access. Deep troubleshoong capability across DNS, roung, TLS, SAML, SCIM, device posture, Client Connector, App Connectors and Private Service Edges.
  • Ability to deploy and validate ZPA soluons at enterprise scale in partnership with plaorm architecture and operaons teams.
  • Strong understanding of Azure and data center networking paerns relevant to ZPA deployment.
  • Experience working across global teams and mulple technology disciplines.
  • Strong technical communicaon skills with the ability to explain implementaon risks, dependencies and engineering decisions clearly.
  • Passion for automaon, repeatable engineering standards and connuous improvement. Ability to operate eecvely in fast-paced and highly complex enterprise environments.

To Qualify for the Role, You Must Have

  • Bachelor's degree in Computer Science, Informaon Technology, Engineering or equivalent experience.
  • 4-7 years of hands-on experience in network security, cloud security, infrastructure security or security engineering.
  • 3-5 years of praccal Zscaler experience, including hands-on ZPA deployment, conguraon, troubleshoong or operaons.
  • Strong working knowledge of ZPA applicaon segments, segment groups, server groups, access policies, App Connectors, connector groups, provisioning keys and Private Service Edges.
  • Ability to troubleshoot live ZPA issues using logs, diagnoscs, packet-level reasoning, DNS checks, roung validaon, TLS/cercate checks and endpoint-side observaons.
  • Experience integrang ZPA with Microso Entra ID or equivalent identy providers using SAML, SCIM, user groups, device posture and condional access signals.
  • Working knowledge of Azure networking and hybrid connecvity, including VNets, subnets, roung, Private Link, Private Endpoint, ExpressRoute, Azure Firewall and Applicaon Gateway.
  • Experience deploying or supporng ZPA components in VMware-based data center environments and Azure cloud environments.
  • Strong understanding of TCP/IP, DNS, TLS, PKI, roung, proxy concepts, identy federaon, rewall policy and enterprise networking fundamentals.
  • Experience with automaon or scripng using Python, PowerShell, Terraform, APIs or similar tools is preferred.
  • Strong English communicaon skills with the ability to explain troubleshoong logic, root cause and implementaon decisions clearly.

Ideally, You'll Also Have

  • Hands-on experience with ZPA autonomous user-to-app segmentaon, policy insights, applicaon discovery workows or AI-generated policy recommendaons.
  • Experience with ZPA Private Service Edge reference architectures and deployments for onpremises and cloud-hosted private applicaons.
  • Experience migrang users and applicaons from VPN or legacy remote access to ZPA-based applicaon access.
  • Experience securing Azure-hosted private applicaons, administrator interfaces, developer services and internal plaorms through ZPA.
  • Experience integrang ZPA with Microso Entra ID, Condional Access, SCIM, SAML and endpoint posture signals.
  • Strong understanding of SASE, SSE, ZTNA, Zero Trust segmentaon and private applicaon protecon paerns.
  • Zscaler cercaons focused on ZPA, Client Connector, Private Service Edge or equivalent hands-on credenals.
  • Azure Network Engineer Associate or Azure Security Engineer cercaon.
  • CISSP, CCSP, CCNP Security or equivalent cercaons.

What We Look For

  • We are looking for a highly technical, hands-on Zscaler/ZPA engineer who can execute complex private access deployments, solve implementaon issues and support reliable producon adopon of ZPA across global enterprise environments.
  • The ideal candidate has successfully deployed ZPA least-privilege access, applicaon segments, App Connectors, Private Service Edges, Client Connector integraons and identy-based access controls across Azure, enterprise data centers and VMware-based infrastructure.

What Working At EY Oers

At EY, we oer a compeve remuneraon package where you'll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for exible working, career development and benets that support your personal and professional priories.

Plus, we oer:

  • Support, coaching and feedback from engaging colleagues.
  • Opportunies to develop new skills and progress your career.
  • Exposure to large-scale global technology and cybersecurity transformaon programs. The freedom and exibility to handle your role in a way that's right for you.

EY | Building a better working world

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

App Connectors

Private Service Edges

Infrastructure-as-Code

Client Connector

Zero Trust Network Access

device posture

Zscaler Private Access

SCIM

About Company