We are looking for an experienced Cloud Network Security Engineer with strong expertise in Zscaler, Microsoft Entra, Azure Networking, Zero Trust, and enterprise network security . The ideal candidate will have hands-on experience designing, implementing, and supporting secure cloud and hybrid network environments, with a strong understanding of SASE, SSE, ZTNA, Secure Web Gateway, CASB, and Zero Trust security architectures .
The role will involve working with enterprise-scale security and networking technologies, troubleshooting complex connectivity and security issues, and supporting cloud transformation initiatives.
Key Responsibilities
- Design, implement, configure, and support Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) solutions.
- Implement and manage Microsoft Global Secure Access, Microsoft Entra Internet Access, and Microsoft Entra Private Access .
- Design and support SSE, SASE, ZTNA, SWG, CASB, Cloud Firewall, and Zero Trust Security architectures.
- Integrate security solutions with Microsoft Entra ID , including SAML, SCIM, MFA, and Conditional Access.
- Configure and support integrations with Microsoft Defender for Cloud Apps and Microsoft Defender for Endpoint .
- Implement and troubleshoot SSL/TLS inspection, PAC files, proxy chaining, traffic forwarding, and policy-based access controls .
- Design, configure, and support Azure networking environments , including VNets, VNet Peering, NSGs, Route Tables, Azure Firewall, Private Endpoints, DNS Services, and Virtual WAN.
- Support Azure ExpressRoute deployment, configuration, monitoring, and operations.
- Work with enterprise networking technologies including TCP/IP, DNS, DHCP, routing, switching, VLANs, NAT, VPN, and load balancing .
- Configure and troubleshoot Cisco enterprise routing and switching environments.
- Work with enterprise firewall platforms such as Palo Alto, Fortinet, Check Point, Cisco Firepower , or equivalent technologies.
- Perform network and security troubleshooting using packet captures, traceroute, firewall logs, proxy logs, and security monitoring tools .
- Analyze network traffic, identify security or connectivity issues, and implement appropriate remediation.
- Collaborate with infrastructure, cloud, security, and application teams to implement secure connectivity solutions.
- Participate in large-scale cloud transformation and Zero Trust adoption initiatives .
- Ensure security solutions align with enterprise security policies, architecture standards, and operational requirements.
Requirements
Mandatory Skills
- Strong hands-on experience with Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) .
- Experience with Microsoft Global Secure Access, Microsoft Entra Internet Access, and Microsoft Entra Private Access .
- Strong understanding of SWG, Cloud Firewall, CASB, SSE, SASE, ZTNA, and Zero Trust Security concepts.
- Experience with Microsoft Entra ID, SAML, SCIM, MFA, and Conditional Access .
- Experience integrating and monitoring Microsoft Defender for Cloud Apps and Microsoft Defender for Endpoint .
- Strong knowledge of SSL/TLS Inspection, PAC Files, Proxy Chaining, Traffic Forwarding, and Policy-Based Access Control .
- Strong Azure networking experience with:
- VNets and VNet Peering
- NSGs and Route Tables
- Azure Firewall
- Private Endpoints
- DNS Services
- Azure Virtual WAN
- Hands-on experience with Azure ExpressRoute deployment and operations .
- Strong networking fundamentals covering TCP/IP, DNS, DHCP, Routing, Switching, VLANs, NAT, VPN, and Load Balancing .
- Strong experience with Cisco networking technologies and enterprise Routing/Switching .
- Experience with enterprise firewall platforms such as Palo Alto, Fortinet, Check Point, Cisco Firepower , or equivalent.
- Strong troubleshooting skills using packet capture, log analysis, traceroute, firewall logs, proxy logs, and network monitoring tools .
Preferred Skills & Certifications
- Zscaler Certified Administrator or Professional certification.
- Microsoft security certifications related to Entra, Zero Trust, and Defender technologies .
- CCNP Enterprise or CCNP Security .
- PCNSE or equivalent firewall certification.
- CISSP, CCSP , or equivalent security certification.
- Experience in the Banking / Financial Services domain.
- Experience working on large-scale cloud transformation and security modernization initiatives.
Ideal Candidate Profile
- Strong combination of networking, cloud, and cybersecurity expertise.
- Hands-on experience implementing Zscaler and Microsoft security solutions in enterprise environments.
- Good understanding of Zero Trust and SASE/SSE architecture .
- Strong analytical and troubleshooting skills.
- Ability to work across network, security, cloud, and infrastructure teams.
- Experience handling enterprise-scale environments and complex technical issues.
- Strong communication and stakeholder management skills.