Jobgether
Senior Zscaler Engineer (ZIA/ZPA)
engineeringfull-timeCanada
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more
About the role
Accountabilities
- Design, deploy, configure, and optimize Zscaler Internet Access (ZIA) policies, including URL filtering, SSL inspection, DLP, and cloud application controls.
- Build and manage Zscaler Private Access (ZPA) application segments, access policies, App Connector architecture, and Private Service Edge deployments.
- Deploy and maintain App Connectors and Private Service Edges, ensuring appropriate sizing, high availability, and placement across data center and cloud environments.
- Integrate Zscaler with identity platforms such as Okta using SAML and SCIM, while implementing device posture and Device Assurance requirements.
- Collaborate with IT Security, Network, Identity, and Endpoint teams to align Zscaler configurations with enterprise access-control and security models.
- Partner with endpoint teams using Jamf and Intune to package, deploy, and troubleshoot Zscaler Client Connector across Windows and macOS environments.
- Support BYOD and mobile application management decisions where Zscaler solutions intersect with mobile access requirements.
- Troubleshoot user, application, and network connectivity issues using ZIA/ZPA diagnostics, log streaming, packet captures, and other technical analysis tools.
- Lead cutover and migration activities associated with replacing legacy GlobalProtect VPN infrastructure, including pilot deployments, application testing, and rollback planning.
- Identify security and architecture gaps between the current environment and the target Zero Trust model, and implement appropriate remediation strategies.
- Produce configuration standards, technical documentation, and compliance materials, including documentation supporting Cyber Essentials Plus requirements.
- Provide clear technical progress updates, communicate risks and dependencies, and escalate significant blockers to project leadership.
- 5+ years of hands-on experience in enterprise network or security engineering, including at least 2 years deploying and operating Zscaler solutions.
- Deep practical expertise with both Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA), including architecture, policy configuration, connector deployment, and troubleshooting.
- Experience implementing SSL inspection, including certificate distribution and bypass management, as well as DLP policies and Zero Trust access models.
- Strong understanding of enterprise networking fundamentals, including DNS, GRE/IPSec tunneling, routing, proxy behavior, TLS, and client connectivity.
- Experience working with identity providers, preferably Okta, and familiarity with SAML, SCIM provisioning, device posture, and conditional access concepts.
- Experience with endpoint management technologies such as Jamf and Microsoft Intune across Windows and macOS environments.
- Strong analytical and troubleshooting abilities, with the capacity to investigate complex security, application, and connectivity issues through to root cause.
- Excellent technical writing and documentation skills, particularly for compliance-facing standards, configuration decisions, and architecture documentation.
- Ability to collaborate effectively with cross-functional technical teams while taking ownership of hands-on engineering decisions and delivery.
- Zscaler certifications such as ZDTA, ZDTP, or equivalent credentials are preferred.
- Competitive contract compensation of $80.00–$85.16 per hour.
- Full-time contract opportunity with an enterprise-focused security engineering environment.
- Opportunity to work on a major Zero Trust transformation involving ZIA, ZPA, identity, endpoint security, and VPN modernization.
- Exposure to complex cloud, data center, networking, and cybersecurity environments.
- Opportunity to collaborate with multidisciplinary Security, Network, Identity, and Endpoint engineering teams.
- Eligible full-time employees may have access to medical, dental, and vision coverage, subject to applicable eligibility requirements.
- Additional benefits and plan details are provided during the interview and onboarding process.
Requirements
Benefits
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply