Jobgether
Jobgether

Senior Zscaler Engineer (ZIA/ZPA)

engineeringfull-timeCanada
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities

    • Design, deploy, configure, and optimize Zscaler Internet Access (ZIA) policies, including URL filtering, SSL inspection, DLP, and cloud application controls.
    • Build and manage Zscaler Private Access (ZPA) application segments, access policies, App Connector architecture, and Private Service Edge deployments.
    • Deploy and maintain App Connectors and Private Service Edges, ensuring appropriate sizing, high availability, and placement across data center and cloud environments.
    • Integrate Zscaler with identity platforms such as Okta using SAML and SCIM, while implementing device posture and Device Assurance requirements.
    • Collaborate with IT Security, Network, Identity, and Endpoint teams to align Zscaler configurations with enterprise access-control and security models.
    • Partner with endpoint teams using Jamf and Intune to package, deploy, and troubleshoot Zscaler Client Connector across Windows and macOS environments.
    • Support BYOD and mobile application management decisions where Zscaler solutions intersect with mobile access requirements.
    • Troubleshoot user, application, and network connectivity issues using ZIA/ZPA diagnostics, log streaming, packet captures, and other technical analysis tools.
    • Lead cutover and migration activities associated with replacing legacy GlobalProtect VPN infrastructure, including pilot deployments, application testing, and rollback planning.
    • Identify security and architecture gaps between the current environment and the target Zero Trust model, and implement appropriate remediation strategies.
    • Produce configuration standards, technical documentation, and compliance materials, including documentation supporting Cyber Essentials Plus requirements.
    • Provide clear technical progress updates, communicate risks and dependencies, and escalate significant blockers to project leadership.
    • Requirements

      • 5+ years of hands-on experience in enterprise network or security engineering, including at least 2 years deploying and operating Zscaler solutions.
      • Deep practical expertise with both Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA), including architecture, policy configuration, connector deployment, and troubleshooting.
      • Experience implementing SSL inspection, including certificate distribution and bypass management, as well as DLP policies and Zero Trust access models.
      • Strong understanding of enterprise networking fundamentals, including DNS, GRE/IPSec tunneling, routing, proxy behavior, TLS, and client connectivity.
      • Experience working with identity providers, preferably Okta, and familiarity with SAML, SCIM provisioning, device posture, and conditional access concepts.
      • Experience with endpoint management technologies such as Jamf and Microsoft Intune across Windows and macOS environments.
      • Strong analytical and troubleshooting abilities, with the capacity to investigate complex security, application, and connectivity issues through to root cause.
      • Excellent technical writing and documentation skills, particularly for compliance-facing standards, configuration decisions, and architecture documentation.
      • Ability to collaborate effectively with cross-functional technical teams while taking ownership of hands-on engineering decisions and delivery.
      • Zscaler certifications such as ZDTA, ZDTP, or equivalent credentials are preferred.
      • Benefits

        • Competitive contract compensation of $80.00–$85.16 per hour.
        • Full-time contract opportunity with an enterprise-focused security engineering environment.
        • Opportunity to work on a major Zero Trust transformation involving ZIA, ZPA, identity, endpoint security, and VPN modernization.
        • Exposure to complex cloud, data center, networking, and cybersecurity environments.
        • Opportunity to collaborate with multidisciplinary Security, Network, Identity, and Endpoint engineering teams.
        • Eligible full-time employees may have access to medical, dental, and vision coverage, subject to applicable eligibility requirements.
        • Additional benefits and plan details are provided during the interview and onboarding process.
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Senior Zscaler Engineer (ZIA/ZPA) at Jobgether — Remote