Zscaler Network Security Engineer

EY

Bengaluru Urban

Hybrid

INR 1,400,000 - 2,100,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

EY seeks a Senior Associate – Network Security Engineer to join EY Technology in India, focusing on Zscaler Private Access and Zero Trust, with hands-on engineering for deployment, configuration, testing, and operational transition of ZPA components across cloud and data center environments.

The role collaborates with multiple teams to design granular access, App Connectors, Private Service Edges, and identity integrations, requiring 4-7 years of security engineering experience and strong

Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, Engineering or equivalent experience.
  • 4-7 years of hands-on experience in network security, cloud security, infrastructure security or security engineering.
  • 3-5 years of practical Zscaler experience, including hands-on ZPA deployment, configuration, troubleshooting or operations.
  • Experience integrating ZPA with Microsoft Entra ID or equivalent identity providers using SAML, SCIM, user groups, device posture and conditional access signals.
  • Strong English communication skills.

Responsibilities

  • Build, configure and troubleshoot ZPA constructs including application segments, segment groups, server groups, servers, access policies, connector groups, App Connectors and Private Service Edges.
  • Translate application details into secure ZPA application access policies.
  • Validate end-to-end traffic flows from Client Connector to ZPA components and target application.
  • Deploy and support App Connectors, Private Service Edges across Azure, VMware and data centers.
  • Troubleshoot ZPA issues across endpoint, identity provider, policy and routing layers.
  • Document known issues, operational procedures and rollback considerations.

Skills

ZPA engineering
Zscaler Private Access
Zero Trust
App Connectors
Private Service Edge
DNS troubleshooting
TLS/SAML/SCIM
Azure networking
Networking fundamentals
Automation (Python/PowerShell)

Education

Bachelor’s degree in Computer Science or equivalent

Tools

Terraform
Python
PowerShell
APIs
VMware
Azure

Job description

Job Description:

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Security Technology Services – Network Security Technology
Senior Associate – Network Security Engineer | India
EY Technology

Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organizaƟon the size of ours working efficiently and securely. We have more than 400,000 people in over 150 countries, all of whom rely on secure technology to perform their jobs every day.

Everything we use as a firm depends on our security-first mindset. Our users, applicaƟons, cloudplaƞorms, data centers, AI services, and business-criƟcal systems all rely on modern security technologies to enable secure access, protect sensiƟve informaƟon, and reduce cyber risk.

Within Security Technology Services, our mission is to deliver world-class security engineeringcapabilities that enable Zero Trust, cloud transformaƟon, aƩack surface reducƟon, and secure digital experiences. If you are passionate about building and engineering security soluƟons at global scale, we want to hear from you.

The Opportunity

We are looking for a Senior Associate – Network Security Engineer to join Security Technology Services as a hands‑on engineering specialist focused on Zscaler Private Access, Zero Trust Network Access,private applicaƟon onboarding, App Connectors, Private Service Edges, Client Connector integraƟon, and least‑privilege user‑to‑applicaƟon access.

This role will report to the Assistant Director and will be responsible for detailed engineering, deployment, configuration, tesƟng, troubleshooƟng, opƟmizaƟion and operaƟonal transiƟn of ZPAservices used to securely connect users, devices and applicaƟons without exposing private applicaƟons to the internet.

The successful candidate must be able to explain and demonstrate hands‑on experience across ZPA applicaƟion segments, segment groups, server groups, App Connector groups, Private Service Edge deployments, authenƟcaƟon and idenƟty integraƟons, DNS, rouƟng, TLS, SAML, SCIM, device posture, Client Connector behavior, live logs, diagnosƟcs, and end‑to‑end traffic flow troubleshooƟng.

This role will support engineering initiatives focused on:

  • Zscaler Private Access engineering for secure private applicaƟon accessDesign and implementation of granular ZPA applicaƟon segments, segment groups and access policies
  • Deployment and support of App Connectors, Private Service Edges and connector groups across cloud and data center environments
  • Least‑privilege user‑to‑applicaƟon access and migration from VPN‑style network access to applicaƟon‑level access
  • ZPA diagnosƟcs, policy validaƟon, operational readiness and production troubleshooƟng

The role will work closely with Network Security Technology, Cloud Engineering, IdenƟty, Endpoint, Infrastructure, ApplicaƟon and Architecture teams to deploy scalable ZPA capabilities across global enterprise environments.

Your Key Responsibilities

The Senior Associate – Network Security Engineer, Zscaler/ZPA will work under the direction of the Assistant Director and provide hands‑on engineering support for ZPA deployment, integration, optimization, troubleshooting and continuous improvement.

Zscaler Private Access Engineering
  • Build, configure and troubleshoot ZPA constructs including applicaƟon segments, segment groups, server groups, servers, access policies, connector groups, App Connectors and Private Service Edges.
  • Translate applicaƟion details such as FQDNs, IPs, TCP/UDP ports, protocols, users, groups and source conditions into secure ZPA applicaƟon access policies.
  • Validate end‑to‑end traffic flows from Client Connector to ZPA Service Edge or Private Service Edge, App Connector, server group and target applicaƟon.
  • Support onboarding of internal applicaƟons, administrator services, developer platforms, privileged access services and business workloads into ZPA.
  • Validate DNS, routing, TLS, IdP, SAML, SCIM, device posture, Client Connector and authentication integrations required for successful ZPA deployments.
  • Produce low‑level implementation steps, test evidence, troubleshooting notes, rollback considerations and operational handover material.
App Connector and Private Service Edge Deployment
  • Deploy and support App Connectors and Private Service Edges across Azure, VMware and datacenter environments.
  • Design connector placement, connector groups, resiliency, capacity, platform sizing and outbound connectivity requirements.
  • Troubleshoot connector health, registration, provisioning keys, software updates, service edge connectivity and tunnel establishment issues.
  • Validate required outbound connectivity, DNS resolution, certificate handling, NTP, firewall allowlists and routing paths for ZPA components.
  • Work with infrastructure teams to ensure high availability, service resilience and operational supportability for production ZPA deployments.
Least‑Privilege Access and Application Segmentation
  • Create granular application segments and access policies aligned to least‑privilege principles for employees, administrators, vendors, service accounts, and support groups.
  • Use ZPA application discovery, policy insights, access logs and diagnostics to validate user‑to‑application access patterns.
  • Review existing access models, identify over‑permissive access and support migration from VPN or network‑level access to ZPA application‑level access.
  • Partner with application, identity and infrastructure teams to confirm business access requirements before policy enforcement.
  • Continuously improve policy quality using logs, dashboards, diagnostics, access review outputs and production support findings.
ZPA Troubleshooting, Diagnostics and Operations
  • Troubleshoot ZPA issues using a structured approach across endpoint, Client Connector, identity provider, ZPA policy, Service Edge, App Connector, DNS, routing, firewall and target application layers.
  • Use ZPA live logs, user activity diagnostics, user status diagnostics, application diagnostics, connector status, Private Service Edge status, service edge health and audit logs to identify root cause.
  • Diagnose common scenarios including policy mismatch, unauthenticated users, failed SAML claims, missing SCIM groups, connector offline state, DNS resolution failure, certificate errors, port mismatch, asymmetric routing and application unavailability.
  • Develop structured test plans for application onboarding, policy changes, connector changes, Private Service Edge rollout and production migration waves.
  • Document known issues, operational procedures, support steps, log locations, escalation evidence and rollback considerations for production deployments.
  • Drive continuous platform improvement through problem management, automation opportunities and implementation lessons learned.
Engineering Automation and Platform Optimization
  • Build and maintain automation solutions to improve security engineering efficiency.
  • Automate deployment, configuration validation and policy management activities.
  • Utilize Terraform, Python, PowerShell, APIs and Infrastructure‑as‑Code approaches.
  • Improve platform scalability, consistency and operational effectiveness through automation.
  • Contribute engineering inputs, deployment feedback and technical validation to future‑state security engineering plans.
Engineering Execution and Collaboration
  • Work under the direction of the Assistant Director to implement approved ZPA engineering plans and deployment standards.
  • Act as a hands‑on escalation point for Zscaler, ZPA, DNS, TLS, routing, Client Connector and authentication issues.
  • Collaborate with cloud, data center, identity, application and infrastructure teams during design validation, pilot and production rollout.
  • Provide technical guidance to engineers and support teams involved in onboarding applications and workloads.
  • Communicate implementation risks, dependencies and progress clearly to the Assistant Director and project stakeholders.
Technical Interview Focus Areas

Candidates should be prepared to discuss real implementation troubleshooting on examples and demonstrate practical depth in the following areas:

  • Explain the ZPA connection flow from user device and Client Connector to Service Edge or Private Service Edge, App Connector and target private application.
  • Design an application segment for a private web application, SSH service, RDP service or administrator portal using FQDNs, ports, server groups, connector groups and access policy rules.
  • Troubleshoot a user who is authenticated but unable to access one ZPA application while other applications work successfully.
  • Troubleshoot an App Connector or Private Service Edge that is registered but unhealthy, disconnected or unable to reach the target application.
  • Explain how SAML attributes, SCIM groups, identity provider claims, device posture and conditional access inputs influence ZPA access policy decisions.
  • Describe DNS resolution requirements for ZPA, including internal DNS dependencies, split‑horizon DNS patterns and Browser Access considerations.
  • Explain connector placement and resiliency strategy for Azure, VMware and data center environments.
  • Interpret ZPA logs and diagnostics to identify whether a failure is caused by policy, identity, connector, routing, DNS, TLS, endpoint or target application issues.
  • Explain how to migrate an application from VPN‑based network access to ZPA application‑level access with testing, rollback and operational readiness steps.
  • Discuss automation opportunities using APIs, Terraform, Python or PowerShell for repeatable ZPA configuration, validation and reporting.
Skills and Attributes for Success

We are interested in candidates who bring deep hands‑on ZPA engineering experience from large global enterprise environments and can combine technical execution with strong implementation discipline.

As a successful candidate, you will demonstrate:

  • Strong hands‑on engineering experience in Zscaler Private Access and Zero Trust Network Access. Deep troubleshooting capability across DNS, routing, TLS, SAML, SCIM, device posture, Client Connector, App Connectors and Private Service Edges.
  • Ability to deploy and validate ZPA solutions at enterprise scale in partnership with platform architecture and operations teams.
  • Strong understanding of Azure and data center networking practices relevant to ZPA deployment.
  • Experience working across global teams and multiple technology disciplines.
  • Strong technical communication skills with the ability to explain implementation risks, dependencies and engineering decisions clearly.
  • Passion for automation, repeatable engineering standards and continuous improvement. Ability to operate effectively in fast‑paced and highly complex enterprise environments.
To Qualify for the Role, You Must Have
  • Bachelor’s degree in Computer Science, Information Technology, Engineering or equivalent experience.
  • 4-7 years of hands‑on experience in network security, cloud security, infrastructure security or security engineering.
  • 3-5 years of practical Zscaler experience, including hands‑on ZPA deployment, configuration, troubleshooting or operations.
  • Strong working knowledge of ZPA application segments, segment groups, server groups, access policies, App Connectors, connector groups, provisioning keys and Private Service Edges.
  • Ability to troubleshoot live ZPA issues using logs, diagnostics, packet‑level reasoning, DNS checks, routing validation, TLS/certificate checks and endpoint‑side observations.
  • Experience integrating ZPA with Microsoft Entra ID or equivalent identity providers using SAML, SCIM, user groups, device posture and conditional access signals.
  • Working knowledge of Azure networking and hybrid connectivity, including VNets, subnets, routing, Private Link, Private Endpoint, ExpressRoute, Azure Firewall and Application Gateway.
  • Experience deploying or supporting ZPA components in VMware‑based data center environments and Azure cloud environments.
  • Strong understanding of TCP/IP, DNS, TLS, PKI, routing, proxy concepts, identity federation, firewall policy and enterprise networking fundamentals.
  • Experience with automation or scripting using Python, PowerShell, Terraform, APIs or similar tools is preferred.
  • Strong English communication skills with the ability to explain troubleshooting logic, root cause and implementation decisions clearly.
Ideally, You’ll Also Have
  • Hands‑on experience with ZPA autonomous user‑to‑application segmentation, policy insights, application discovery workflows or AI‑generated policy recommendations.
  • Experience with ZPA Private Service Edge reference architectures and deployments for on‑premises and cloud‑hosted private applications.
  • Experience migrating users and applications from VPN or legacy remote access to ZPA‑based application access.
  • Experience securing Azure‑hosted private applications, administrator interfaces, developer services and internal platform through ZPA.
  • Experience integrating ZPA with Microsoft Entra ID, Conditional Access, SCIM, SAML and endpoint posture signals.
  • Strong understanding of SASE, SSE, ZTNA, Zero Trust segmentation and private application protection patterns.
  • Zscaler certifications focused on ZPA, Client Connector, Private Service Edge or equivalent hands‑on credentials.
  • Azure Network Engineer Associate or Azure Security Engineer certification.
  • CISSP, CCSP, CCNP Security or equivalent certifications.
What We Look For
  • We are looking for a highly technical, hands‑on Zscaler/ZPA engineer who can execute complex private access deployments, solve implementation issues and support reliable production adoption of ZPA across global enterprise environments.
  • The ideal candidate has successfully deployed ZPA least‑privilege access, application segments, App Connectors, Private Service Edges, Client Connector integrations and identity‑based access controls across Azure, enterprise data centers and VMware‑based infrastructure.
What working at EY offers

At EY, we offer a competitive remuneration package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working, career development and benefits that support your personal and professional priorities.

Plus, we offer:

  • Support, coaching and feedback from engaging colleagues.
  • Opportunities to develop new skills and progress your career.
  • Exposure to large‑scale global technology and cybersecurity transformation programs. The freedom and flexibility to handle your role in a way that’s right for you.

EY | Building a better working world

EY exists to build a better working world, helping to create long‑term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Zscaler Network Security-Principal engineer- Associate director
Zscaler Network Security-Principal engineer- Associate director

EY • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Flexible working arrangements
Total rewards package
Career development opportunities
+1
Zscaler Network Security-Principal Engineer- Associate Director
Zscaler Network Security-Principal Engineer- Associate Director

EY • Bengaluru Urban

On-site
INR 6,000,000 - 9,000,000
Zscaler Network Security-Principal engineer- Associate director
Zscaler Network Security-Principal engineer- Associate director

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 4,200,000 - 7,000,000
Zscaler Network Security Engineer
Zscaler Network Security Engineer

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 3,000,000 - 5,400,000
Network Security Operations Assistant Director
Network Security Operations Assistant Director

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 4,000,000 - 7,000,000
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior

EY • Dadri

On-site
INR 1,500,000 - 2,300,000
TC-CS-Cyber Architecture-OT and Engineering-Zscaler SASE-Senior
TC-CS-Cyber Architecture-OT and Engineering-Zscaler SASE-Senior

EY • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Senior Zscaler Security Consultant
Senior Zscaler Security Consultant

EY • Dadri

On-site
INR 4,000,000 - 7,000,000
GMS-Senior-Zscaler and Check Point
GMS-Senior-Zscaler and Check Point

EY • Bengaluru

On-site
INR 1,500,000 - 2,200,000
GMS-Senior-Zscaler and Check Point
GMS-Senior-Zscaler and Check Point

EY • Dadri

On-site
INR 1,800,000 - 3,000,000