ZScaler SME Network Engineer

Agile Defense
United States
Workplace: HybridFull timeUSD 170,000 - 185,000 annuallyFunction: IT Operations (Systems/Network Admin)Skills: ["Problem-solving","Analytical skills","Cross-functional collaboration"]

Serve as the primary technical authority for enterprise Zscaler Secure Access Service Edge (SASE) deployments, leading the operational architecture across ZIA, ZPA, and ZDX. Build and tune security policies, formulate Zero Trust access controls, and manage Zscaler Client Connector (ZCC) lifecycle across multiple endpoint platforms. Provide Tier-3/Tier-4 escalation for complex proxy and identity-related issues, integrate observability with SIEM tooling (Splunk, Cribl), and coordinate emergency changes when needed.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Agile Defense
Agile Defense
2 days ago

ZScaler SME Network Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Serve as the primary technical authority for enterprise Zscaler Secure Access Service Edge (SASE) deployments, leading the operational architecture across ZIA, ZPA, and ZDX. Build and tune security policies, formulate Zero Trust access controls, and manage Zscaler Client Connector (ZCC) lifecycle across multiple endpoint platforms. Provide Tier-3/Tier-4 escalation for complex proxy and identity-related issues, integrate observability with SIEM tooling (Splunk, Cribl), and coordinate emergency changes when needed.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: IT Operations (Systems/Network Admin)
Seniority: Mid level

Key Responsibilities

  • •Lead architecture and engineering for enterprise Zscaler deployments across multi-cloud and hybrid environments (ZIA, ZPA, ZDX, ZCC).
  • •Create and tune security policies (URL filtering, Cloud Application Control, SSL/TLS deep packet inspection, DLP, sandbox).
  • •Configure Zero Trust access policies in ZPA to enable least-privilege access without traditional VPN overhead.
  • •Provide Tier-3/Tier-4 troubleshooting and incident support for proxy routing, PAC debugging, identity/authentication issues, and application latency.
  • •Manage ZCC lifecycle (distribution, health checks, profile tuning, version upgrades) and integrate observability/analytics with ZDX and SIEM logs (Splunk, Cribl).
Travel: Medium travel

Pay and Benefits

Salary: USD 170,000 - 185,000 annually

Key Requirements

  • •Design, implement, and maintain enterprise Zscaler deployments (ZIA, ZPA, ZDX, and Zscaler Client Connector) across multi-cloud and hybrid corporate environments.
  • •Create, audit, and tune security policies, including URL filtering, Cloud Application Control, SSL/TLS deep packet inspection, DLP, and sandbox policies.
  • •Formulate and execute least-privilege access policies within ZPA for internal application access across AWS, Azure, GCP, and on-premises data centers.
  • •Provide Tier-3/Tier-4 escalation for complex proxy routing and troubleshooting (PAC file debugging, identity integration, authentication drops, application latency).
  • •Manage enterprise Zscaler Client Connector (ZCC) distribution, health checks, profile tuning, and version upgrades across macOS, Windows, iOS, and Android.
Experience:Zero TrustSASE
Skills:Problem-solvingAnalytical skillsCross-functional collaboration
Tech Stack:ZscalerZIAZPAZDXZscaler Client ConnectorZCCAWSAzureGCPSSL/TLS deep packet inspectionDLPPACSIEMSplunkCriblSAMLSCIMOktaMicrosoft Entra IDPing Identity

Company Brief

Agile Defense
Provides cybersecurity services including managed detection and response, incident response, vulnerability assessments, and security operations to help organizations detect, respond to, and remediate cyber threats while meeting regulatory and compliance requirements.
Industry: Cybersecurity
Website