Senior Network Security Engineer - Zscaler Private Access Specialist

Ernst & Young LLP ( EY India )

Bengaluru

On-site

INR 1,800,000 - 2,400,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Ernst & Young in India seeks a Senior Associate – Network Security Engineer to implement Zscaler Private Access at scale. The role focuses on ZPA deployment, app connectors, Private Service Edges, and least-privilege access across cloud and data centers.

You will collaborate with security, cloud, and infrastructure teams to deliver secure private app access and robust diagnostics. The ideal candidate will have hands-on ZPA experience, strong knowledge of DNS/TLS, and integration with identity

Qualifications

  • 1–4 years of hands-on experience in network/security, plus 3–5 years of practical Zscaler experience.
  • Strong knowledge of ZPA components: application segments, groups, policies, App Connectors, and Private Service Edges.
  • Ability to troubleshoot live ZPA issues using logs, diagnostics, DNS checks, and TLS/certificate checks.
  • Experience integrating ZPA with Microsoft Entra ID or equivalent identity providers using SAML/SCIM.
  • Knowledge of Azure networking and hybrid connectivity (VNets, Private Link, ExpressRoute) and VMware/Azure deployments.

Responsibilities

  • Explain ZPA connection flow and design private app segments and access policies.
  • Configure and troubleshoot ZPA constructs: segments, groups, App Connectors, and Private Service Edges.
  • Validate end-to-end traffic flows from Client Connector to target application.
  • Deploy and support App Connectors and Private Service Edges across Azure and on-premises.
  • Assist with automation and continuous improvement of deployment and operational processes.

Skills

ZPA engineering
Zero Trust
App Connectors
DNS troubleshooting
Azure Networking

Education

Azure Network Engineer Associate
Azure Security Engineer
CISSP
CCSP
Zscaler certifications

Tools

Terraform
Python
PowerShell
APIs
ZPA

Job description

Zscaler Network Security Engineer At EY

Zscaler Network Security Engineer At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Security Technology Services – Network Security Technology Senior Associate – Network Security Engineer | India EY Technology

Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organizaƟon the size of ours working efficiently and securely. We have more than 400,000 people in over 150 countries, all of whom rely on secure technology to perform their jobs every day. Everything we use as a firm depends on our security-first mindset. Our users, applicaƟons, cloudplaƞorms, data centers, AI services, and business-criƟcal systems all rely on modern security technologies to enable secure access, protect sensiƟve informaƟon, and reduce cyber risk. Within Security Technology Services, our mission is to deliver world-class security engineeringcapabiliƟes that enable Zero Trust, cloud transformaƟion, aƩack surface reducƟon, and secure digital experiences. If you are passionate about building and engineering security soluƟons at global scale, we want to hear from you.

The Opportunity

We are looking for a Senior Associate – Network Security Engineer to join Security Technology Services as a hands‑on engineering specialist focused on Zscaler Private Access, Zero Trust Network Access,private applicaƟion onboarding, App Connectors, Private Service Edges, Client Connector integraƟon, and least-privilege user-to-applicaƟon access. This role will report to the Assistant Director and will be responsible for detailed engineering, deployment, configuraƟon, tesƟng, troubleshooƟng, opƟmizaƟon and operaƟonal transiƟon of ZPAservices used to securely connect users, devices and applicaƟons without exposing private applicaƟons to the internet. The successful candidate must be able to explain and demonstrate hands‑on experience across ZPA applicaƟon segments, segment groups, server groups, App Connector groups, Private Service Edge deployments, authenƟcaƟon and idenƟty integraƟons, DNS, rouƟng, TLS, SAML, SCIM, device posture, Client Connector behavior, live logs, diagnosƟcs, and end‑to‑end traffic flow troubleshooƟng. This role will support engineering iniƟaƟves focused on: Zscaler Private Access engineering for secure private applicaƟon accessDesign and implementaƟon of granular ZPA applicaƟon segments, segment groups and access policies Deployment and support of App Connectors, Private Service Edges and connector groups across cloud and data center environments Least‑privilege user‑to‑applicaƟon access and migraƟon from VPN‑style network access to applicaƟon‑level access ZPA diagnosƟcs, policy validaƟon, operaƟonal readiness and producƟon troubleshooƟng. The role will work closely with Network Security Technology, Cloud Engineering, IdenƟty, Endpoint, Infrastructure, ApplicaƟon and Architecture teams to deploy scalable ZPA capabiliƟes across global enterprise environments.

Your Key ResponsibiliƟes

The Senior Associate – Network Security Engineer, Zscaler/ZPA will work under the direcƟon of the Assistant Director and provide hands‑on engineering support for ZPA deployment, integraƟon,opƟmizaƟon, troubleshooƟng and conƟnuous improvement. Zscaler Private Access Engineering Build, configure and troubleshoot ZPA constructs including applicaƟon segments, segment groups, server groups, servers, access policies, connector groups, App Connectors and Private Service Edges. Translate applicaƟon details such as FQDNs, IPs, TCP/UDP ports, protocols, users, groups and source condiƟons into secure ZPA applicaƟon access policies. Validate end‑to‑end traffic flows from Client Connector to ZPA Service Edge or Private Service Edge, App Connector, server group and target applicaƟon. Support onboarding of internal applicaƟons, administrator services, developer plaƟorms, privileged access services and business workloads into ZPA. Validate DNS, rouƟng, TLS, IdP, SAML, SCIM, device posture, Client Connector and authenƟcaƟon integraƟons required for successful ZPA deployments. Produce low‑level implementaƟon steps, test evidence, troubleshooƟng notes, rollbackconsideraƟons and operaƟonal handover material. App Connector and Private Service Edge Deployment Deploy and support App Connectors and Private Service Edges across Azure, VMware and datacenter environments. Design connector placement, connector groups, resiliency, capacity, plaƟorm sizing andoutbound connecƟvity requirements. Troubleshoot connector health, registraƟion, provisioning keys, soŌware updates, service edgeconnecƟvity and tunnel establishment issues. Validate required outbound connecƟvity, DNS resoluƟon, cerƟficate handling, NTP, firewall allowlists and rouƟng paths for ZPA components. Work with infrastructure teams to ensure high availability, service resilience and operaƟ supportability for producƟion ZPA deployments. Least‑Privilege Access and ApplicaƟon SegmentaƟon Create granular applicaƟon segments and access policies aligned to least‑privilege principles for employees, administrators, vendors, service accounts and support groups. Use ZPA applicaƟon discovery, policy insights, access logs and diagnosƟcs to validate user‑ toapplicaƟon access paƩerns. Review exisƟng access models, idenƟfy over‑permissive access and support migraƟon from VPN or network‑level access to ZPA applicaƟon‑level access. Partner with applicaƟion, idenƟty and infrastructure teams to confirm business access requirements before policy enforcement. ConƟnuously improve policy quality using logs, dashboards, diagnosƟcs, access review outputs and producƟion support findings. ZPA TroubleshooƟng, DiagnosƟcs and OperaƟons Troubleshoot ZPA issues using a structured approach across endpoint, Client Connector, idenƟty provider, ZPA policy, Service Edge, App Connector, DNS, rouƟng, firewall and target applicaƟon layers. Use ZPA live logs, user acƟvity diagnosƟcs, user status diagnosƟcs, applicaƟon diagnosƟcs, connector status, Private Service Edge status, service edge health and audit logs to idenƟfy root cause. Diagnose common scenarios including policy mismatch, unauthenƟcated users, failed SAML claims, missing SCIM groups, connector offline state, DNS resoluƟon failure, cerƟficate errors, port mismatch, asymmetric rouƟng and applicaƟon unavailability. Develop structured test plans for applicaƟon onboarding, policy changes, connector changes, Private Service Edge rollout and producƟion migraƟon waves. Document known issues, operaƟonal procedures, support steps, log locaƟons, escalaƟon evidence and rollback consideraƟons for producƟion deployments. Drive conƟnuous plaƟorm improvement through problem management, automaƟonopportuniƟes and implementaƟon lessons learned. Engineering AutomaƟon and PlaƟorm OpƟmizaƟon Build and maintain automaƟon soluƟons to improve security engineering efficiency. Automate deployment, configuraƟon validaƟon and policy management acƟviƟes. UƟlize Terraform, Python, PowerShell, APIs and Infrastructure-as-Code approaches. Improve plaƟorm scalability, consistency and operaƟonal effecƟveness through automaƟon. Contribute engineering inputs, deployment feedback and technical validaƟon to future‑state security engineering plans. Engineering ExecuƟon and CollaboraƟon Work under the direcƟon of the Assistant Director to implement approved ZPA engineering paƩerns and deployment standards. Act as a hands‑on escalaƟon point for Zscaler, ZPA, DNS, TLS, rouƟng, Client Connector andauthenƟcaƟon issues. Collaborate with cloud, data center, idenƟty, applicaƟon and infrastructure teams during designvalidaƟon, pilot and producƟon rollout. Provide technical guidance to engineers and support teams involved in onboarding applicaƟonsand workloads. Communicate implementaƟon risks, dependencies and progress clearly to the Assistant Director and project stakeholders.

Technical Interview Focus Areas

Explain the ZPA connecƟon flow from user device and Client Connector to Service Edge or Private Service Edge, App Connector and target private applicaƟon. Design an applicaƟon segment for a private web applicaƟon, SSH service, RDP service or administrator portal using FQDNs, ports, server groups, connector groups and access policyrules. Troubleshoot a user who is authenƟcated but unable to access one ZPA applicaƟon while other applicaƟons work successfully. Troubleshoot an App Connector or Private Service Edge that is registered but unhealthy,disconnected or unable to reach the target applicaƟon. Explain how SAML aƩributes, SCIM groups, idenƟty provider claims, device posture andcondiƟonal access inputs influence ZPA access policy decisions. Describe DNS resoluƟon requirements for ZPA, including internal DNS dependencies, splithorizon DNS paƩerns and Browser Access consideraƟons. Explain connector placement and resiliency strategy for Azure, VMware and data center environments. Interpret ZPA logs and diagnosƟcs to idenƟfy whether a failure is caused by policy, idenƟty, connector, rouƟng, DNS, TLS, endpoint or target applicaƟon issues. Explain how to migrate an applicaƟon from VPN‑based network access to ZPA applicaƟon‑level access with tesƟng, rollback and operaƟonal readiness steps. Discuss automaƟon opportuniƟes using APIs, Terraform, Python or PowerShell for repeatable ZPA configuraƟion, validaƟon and reporƟng.

Skills and Attributes for Success

We are interested in candidates who bring deep hands‑on ZPA engineering experience from large global enterprise environments and can combine technical execuƟon with strong implementaƟon discipline. As a successful candidate, you will demonstrate: Strong hands‑on engineering experƟse in Zscaler Private Access and Zero Trust Network Access. Deep troubleshooƟng capability across DNS, rouƟng, TLS, SAML, SCIM, device posture, Client Connector, App Connectors and Private Service Edges. Ability to deploy and validate ZPA soliƟons at enterprise scale in partnership with plaƟormarchitecture and operaƟons teams. Strong understanding of Azure and data center networking paƩerns relevant to ZPA deployment. Experience working across global teams and mulƟple technology disciplines. Strong technical communicaƟon skills with the ability to explain implementaƟion risks, dependencies and engineering decisions clearly. Passion for automaƟon, repeatable engineering standards and conƟnuous improvement. Ability to operate effecƟvely in fast‑paced and highly complex enterprise environments.

To Qualify for the Role, You Must Have

1‑4 years of hands‑on experience in network security, cloud security, infrastructure security or security engineering, 3‑5 years of practiƟcal Zscaler experience, including hands‑on ZPA deployment, configuraƟon,troubleshooƟng or operaƟons. Strong working knowledge of ZPA applicaƟion segments, segment groups, server groups, accesspolicies, App Connectors, connector groups, provisioning keys and Private Service Edges. Ability to troubleshoot live ZPA issues using logs, diagnosƟcs, packet‑level reasoning, DNS checks,rouƟng validaƟon, TLS/cerƟficate checks and endpoint‑side observaƟons. Experience integraƟng ZPA with MicrosoŌ Entra ID or equivalent idenƟty providers using SAML,SCIM, user groups, device posture and condiƟonal access signals. Working knowledge of Azure networking and hybrid connecƟvity, including VNets, subnets,rouƟng, Private Link, Private Endpoint, ExpressRoute, Azure Firewall and ApplicaƟion Gateway. Experience deploying or supporƟng ZPA components in VMware‑based data centerenvironments and Azure cloud environments. Strong understanding of TCP/IP, DNS, TLS, PKI, rouƟng, proxy concepts, idenƟty federaƟon,firewall policy and enterprise networking fundamentals. Experience with automaƟon or scripƟng using Python, PowerShell, Terraform, APIs or similartools is preferred. Strong English communicaƟon skills with the ability to explain troubleshooƟng logic, root causeand implementaƟon decisions clearly. Ideally, You’ll Also Have Hands‑on experience with ZPA autonomous user‑to-app segmentaƟon, policy insights, applicaƟon discovery workflows or AI‑generated policy recommendaƟons. Experience with ZPA Private Service Edge reference architectures and deployments for onpremises and cloud‑hosted private applicaƟons. Experience migraƟng users and applicaƟons from VPN or legacy remote access to ZPA‑basedapplicaƟon access. Experience securing Azure‑hosted private applicaƟons, administrator interfaces, developerservices and internal plaƟorms through ZPA. Experience integraƟng ZPA with MicrosoŌ Entra ID, CondiƟonal Access, SCIM, SAML and endpoint posture signals. Strong understanding of SASE, SSE, ZTNA, Zero Trust segmentaƟon and private applicaƟon protecƟon paƩerns. Zscaler cerƟficaƟons focused on ZPA, Client Connector, Private Service Edge or equivalent hands‑on credenƟals. Azure Network Engineer Associate or Azure Security Engineer cerƟficaƟon. CISSP, CCSP, CCNP Security or equivalent cerƟficaƟons.

What We Look For

We are looking for a highly technical, hands‑on Zscaler/ZPA engineer who can execute complex private access deployments, solve implementaƟon issues and support reliable producƟion adopƟon of ZPA across global enterprise environments. The ideal candidate has successfully deployed ZPA least‑privilege access, applicaƟon segments, App Connectors, Private Service Edges, Client Connector integraƟons and idenƟty‑based access controls across Azure, enterprise data centers and VMware‑based infrastructure.

What working at EY offers

At EY, we offer a compeƟƟve remuneraƟon package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working, career development and benefits that support your personal and professional prioriƟes. Plus, we offer: Support, coaching and feedback from engaging colleagues. OpportuniƟes to develop new skills and progress your career. Exposure to large‑scale global technology and cybersecurity transformaƟion programs. The freedom and flexibility to handle your role in a way that’s right for you. EY | Building a better working world EY exists to build a better working world, helping to create long‑term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Network Security Engineer and Associate Director
Principal Network Security Engineer and Associate Director

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 4,500,000 - 7,500,000
Zscaler Network Security-Principal engineer- Associate director
Zscaler Network Security-Principal engineer- Associate director

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 4,200,000 - 7,000,000
Zscaler Network Security Engineer
Zscaler Network Security Engineer

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 3,000,000 - 5,400,000
Senior Infrastructure Security Consultant
Senior Infrastructure Security Consultant

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Coaching and feedback
Career development
Flexible work options
Senior Cyber Security Architect - Network & Cloud Security
Senior Cyber Security Architect - Network & Cloud Security

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 3,500,000 - 7,000,000
GMS-Senior-Zscaler and Check Point
GMS-Senior-Zscaler and Check Point

EY • Hyderabad

On-site
INR 1,500,000 - 2,100,000
GMS-Senior-Zscaler and Check Point
GMS-Senior-Zscaler and Check Point

Ernst & Young Advisory Services Sdn Bhd • Dadri

On-site
INR 1,500,000 - 2,500,000
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior

Ernst & Young Advisory Services Sdn Bhd • Dadri

Hybrid
INR 3,500,000 - 6,000,000
Senior Zscaler Security Consultant
Senior Zscaler Security Consultant

EY • Dadri

On-site
INR 4,000,000 - 7,000,000
TC-CS-Cyber Architecture-OT and Engineering-Zscaler SASE-Senior
TC-CS-Cyber Architecture-OT and Engineering-Zscaler SASE-Senior

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 2,600,000 - 5,200,000