GMS-Senior-Zscaler and Check Point

Ernst & Young Advisory Services Sdn Bhd

Dadri

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Ernst & Young Advisory Services Sdn Bhd is seeking an Infra Security Senior to manage Zscaler Internet Access, Zscaler Private Access and Check Point firewalls in enterprise environments. You will handle policy management, secure access enablement, incident troubleshooting, and compliance across on-prem and cloud connectivity.

Preferred candidates have 4+ years in infrastructure security and hands-on experience with ZIA/ZPA and Check Point tools, with strong problem-solving and cross-team

Qualifications

  • Bachelor’s degree in Engineering/Computer Science or equivalent experience.
  • 4+ years in infrastructure security, network security or cloud security.
  • Solid hands-on with ZIA policy administration and troubleshooting.

Responsibilities

  • Administer and support ZIA features including URL filtering, web security and SSL inspection.
  • Manage ZPA access enforcement and publish troubleshooting steps.
  • Configure GRE/IPsec, PAC files, and Zscaler Client Connector for traffic forwarding.
  • Troubleshoot authentication failures, policy mismatches and SSL inspection issues.
  • Integrate with SIEM and perform policy reviews and least privilege reviews.
  • Manage Check Point gateways: NAT, Access Control, IPS, VPN and HA/VSX as applicable.
  • Troubleshoot VPNs, monitor performance and perform packet captures and analysis.

Skills

ZIA policy administration
ZPA troubleshooting
Check Point firewall
FW monitoring
SIEM integration
Troubleshooting / incident response

Education

Bachelor’s degree in Engineering/Computer Science

Tools

SmartConsole
SmartView/Logs
tcpdump
cpinfo
fw monitor

Job description

Infra Security – Zscaler, Check Point_Senior

We are looking for Infra Sec specialist who will be responsible for day-to-day operations, administration, troubleshooting, and optimization of Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Check Point firewalls in a production enterprise environment. The role includes policy management, secure access enablement, incident troubleshooting, performance tuning, upgrades, change execution, and compliance support across on-prem and cloud connectivity.

Key Responsibilities:

Administer and support Zscaler Internet Access (ZIA) features:

  • URL Filtering, Web Security, SSL inspection, Malware protection, Advanced Threat features (as licensed)
  • Cloud firewall policies, bandwidth control, DLP policy support (if applicable)

Administer and support Zscaler Private Access (ZPA):

  • Identity-based access enforcement, posture checks (if enabled), user access troubleshooting

Configure and maintain traffic forwarding methods:

  • GRE/IPsec tunnels, PAC files, Zscaler Client Connector, proxy chaining (as applicable)

Troubleshoot Zscaler access issues:

  • Authentication failures, policy mismatch, SSL inspection problems, application latency and connectivity issues
  • Analyze Zscaler logs (web insights, audit logs, connector logs) and coordinate with ISP/Network teams

Integrate with enterprise identity/security tooling:

  • Log streaming to SIEM (e.g., Sentinel/Splunk/QRadar) and alert tuning
  • Perform policy reviews, rulebase cleanup, and implement least privilege access patterns.

Manage Check Point Security Gateways and Management:

  • Policy creation/maintenance (NAT, Access Control, Application Control, IPS, Anti-Bot/AV as licensed)
  • Object management, service groups, VPN communities, route-based vs domain-based VPN

Administer Check Point VPNs:

  • Site-to-site IPsec VPN, remote access VPN (if used), certificate-based authentication

Perform troubleshooting and performance analysis:

  • VPN tunnel instability, packet drops, asymmetric routing, NAT issues, throughput constraints
  • Use tools: SmartConsole, SmartView/Logs, tcpdump, fw monitor, cpinfo, debugs

Handle firewall lifecycle activities:

  • Backup/restore, upgrades/patching, hotfix installation, cluster management (HA/VSX if applicable)

Implement security best practices:

  • Rulebase optimization, threat prevention tuning, logging strategy, segmentation and zone design
Preferred Requirements:
  • Over 4 years of experience in Infrastructure Security, Network Security, or Cloud Security.
  • Solid hands-on with ZIA policy administration and troubleshooting
  • Working knowledge of ZPA application access design and troubleshooting
  • Experience with Zscaler Client Connector, PAC files, GRE/IPsec forwarding
  • Hands-on policy management using Check Point SmartConsole
  • Strong understanding of NAT, VPN, routing, clustering/HA basics
  • Strong troubleshooting using fw monitor, logs, packet captures, debug utilities
  • Knowledge of threat prevention blades (IPS/AV/Anti-Bot) is a plus
  • Hands-on knowledge on Cisco ASA firewall is also preferred.
Qualifications:
  • Bachelor’s degree in Engineering/Computer Science or equivalent experience
Industry certifications (preferred):
  • Check Point CCSA/CCSE – preferred
  • Network fundamentals: CCNA (nice to have), CCNP Security
  • Strong communication skills with ability to explain issues to stakeholders and coordinate across teams
  • Willingness to work in 24x7 shift

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GMS-Senior-Zscaler And Check Point
GMS-Senior-Zscaler And Check Point

EY • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Senior Zscaler & Check Point Consultant
Senior Zscaler & Check Point Consultant

EY • Dadri

On-site
INR 1,200,000 - 1,800,000
TC-CS-Cyber Architecture-OT and Engineering-Zscaler SASE-Senior
TC-CS-Cyber Architecture-OT and Engineering-Zscaler SASE-Senior

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 2,600,000 - 5,200,000
Zscaler Network Security Engineer
Zscaler Network Security Engineer

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 3,000,000 - 5,400,000
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior

Ernst & Young Advisory Services Sdn Bhd • Dadri

Hybrid
INR 3,500,000 - 6,000,000
Senior Zscaler SASE Consultant
Senior Zscaler SASE Consultant

EY • Bengaluru

On-site
INR 2,500,000 - 4,000,000
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior

EY • Dadri

On-site
INR 1,500,000 - 2,300,000
Senior Zscaler Security Consultant
Senior Zscaler Security Consultant

EY • Dadri

On-site
INR 4,000,000 - 7,000,000
Senior Network Security Engineer - Zscaler Private Access Specialist
Senior Network Security Engineer - Zscaler Private Access Specialist

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Zscaler Network Security-Principal engineer- Associate director
Zscaler Network Security-Principal engineer- Associate director

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 4,200,000 - 7,000,000