Cyber Zscaler Network Security Engineering Manager / Manager, Strategy, Growth, and Transformation

PowerToFly

California (MO)

On-site

USD 135,000 - 265,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Deloitte Cyber is seeking a Manager to drive network security modernization using Zscaler across large enterprises. You will design, deploy, and optimize ZIA and ZPA, lead zero trust transformations, and guide policy, SSL/TLS inspection, and cloud connectivity efforts across AWS, Azure, and GCP.

Expectations include strong leadership and client-facing collaboration. You will oversee delivery teams, ensure high-quality architectures, and align security with overall digital transformation

Qualifications

  • BA/BS in a technical field (e.g., Computer Science, Cyber Security, IT).
  • ZDTE certification required.
  • 7+ years of progressively responsible experience in network security engineering.

Responsibilities

  • Lead end-to-end design, deployment, and ops management of ZIA and ZPA across enterprise environments.
  • Manage ZTNA transformation workstreams and VPN modernization.
  • Provide tech leadership for Zscaler policy administration, SSL/TLS inspection, and DLP policies.
  • Oversee branch, cloud, and app connector architectures across on-prem and cloud (AWS/AZURE/GCP).
  • Direct development and QA of solution architectures and client-facing recommendations.
  • Lead client and delivery teams with workplans, risks, dependencies, and issue resolution.

Skills

ZIA expertise
ZPA expertise
ZTNA transformation
Cloud security architecture
Policy management
SSL/TLS inspection
Cloud connectors
VPN modernization
Leadership
Project management
Communication
Threat protection
Cloud providers (AWS/Azure/GCP)

Education

BA/BS in a technical field
ZDTE certification
7+ years network security engineering

Tools

Zscaler ZIA
Zscaler ZPA
Zscaler Branch Connector
Zscaler Cloud Connector
ZIA policy management

Job description

Zscaler Network Security Engineering Manager / Manager, Strategy, Growth, and Transformation

Deloitte's Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative approach. We collaborate with teams from across our organization in order to bring the full breadth of Deloitte, its commercial and public sector expertise, to best support our clients.

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

As a Manager, you will help clients modernize network security through cloud-delivered zero trust architectures. This role leads the design, deployment, and optimization of Zscaler capabilities across complex enterprise environments, helping organizations strengthen security posture, improve user access experiences, and enable secure transformation across on-premises and cloud ecosystems.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Manager on the Cyber Enterprise Security team, you will be responsible for...

  • Lead the end‑to‑end design, deployment, and operational management of Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) solutions across complex enterprise environments.
  • Manage zero trust network access (ZTNA) transformation workstreams, including the replacement of legacy virtual private network (VPN) infrastructure and modernization of enterprise access controls.
  • Provide technical leadership for the configuration and optimization of Zscaler capabilities, including policy administration, SSL/TLS inspection, advanced threat protection, data loss prevention, and cloud‑based traffic inspection.
  • Oversee the implementation of branch, cloud, and application connector architectures across on‑premises and public cloud environments, including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP).
  • Direct the development and quality assurance of technical deliverables, solution architectures, and client‑facing recommendations aligned with enterprise security, network transformation, and operational objectives.
  • Lead client and delivery teams through execution, managing workplans, risks, dependencies, stakeholder communications, and issue resolution to ensure high‑quality outcomes.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast‑paced and dynamic environment
  • Strong interpersonal skills and professional demeanorAbility to meet deadlines
  • Ability to mentor and provide clear guidance to others
The team

Our Enterprise Security offering embeds security in all aspects of digital transformation by securing a client's technical backbone while enabling secure digital transformation. Includes security architecture, secure development and deployment, end‑to‑end cyber cloud capabilities, application security, and security for emerging technologies and connected products.

Qualifications
Required Qualifications
  • BA/BS degree in a technical field (e.g., Computer Science, Cyber Security, Information Technology)
  • Zscaler Digital Transformation Engineer (ZDTE) certification required
  • 7+ years of progressively responsible experience in network security engineering
  • 7+ years of hands‑on experience designing, deploying, and managing Zscaler Internet Access (ZIA), including web filtering, DNS security, cloud firewall, bandwidth controls, and advanced threat protection policies in enterprise‑scale environments
  • 7+ years of hands‑on experience designing, deploying, and managing Zscaler Private Access (ZPA), including application segment configuration, access policies, connector deployment, and zero trust network access (ZTNA) architectures replacing legacy VPN infrastructure
  • 3+ years of experience designing, deploying, and managing Zscaler Branch Connector, and configuring BGP/static routing configurations and network segmentation, replacing traditional SD‑WAN platforms (e.g., Cisco, VMware, Aruba)
  • 3+ years of experience designing, deploying, and managing Zscaler Cloud Connector, including deployment within cloud environments (AWS, Azure, and/or GCP), workload‑to‑internet and workload‑to‑workload traffic inspection, and integration with cloud‑native networking constructs (e.g., VPCs, VNets, Transit Gateways)
  • 5+ years of experience configuring and tuning Zscaler advanced security features, including Cloud Sandboxing, Advanced Threat Protection (ATP), Intrusion Prevention (IPS), Cloud Browser Isolation (CBI), and Data Loss Prevention (DLP) policies
  • 5+ years of experience implementing and troubleshooting SSL/TLS inspection within ZIA, including certificate management, decryption policy design, bypass rules, and handling of certificate‑pinned applications
  • 2+ years of experience with Zscaler AI‑powered capabilities, including AI‑driven policy recommendations, Digital Experience Monitoring (ZDX), and leveraging Zscaler AI/ML‑based threat intelligence for automated threat response
  • 3+ years of hands‑on experience defining, managing, and reviewing Zscaler security policies, including rule base optimization, policy lifecycle management, access reviews, and role‑based access controls within the Zscaler Admin Portal
  • Experience implementing ZIdentity for centralize identity management.
  • 4+ years of experience with one or more major cloud service providers (AWS, GCP, Azure) to deploy ZPA App Connectors within cloud‑native architectures.
  • 4+ years of experience deploying Zscaler Cloud Connector.
  • Ability to travel up to 50%, on average, based on the work you perform and the clients and industries/sectors you serve
  • Limited immigration sponsorship may be available
Preferred Qualifications
  • Advanced cybersecurity certifications such as CISSP, CCIE Security, CCNP Security, or GIAC equivalents (e.g., GPEN, GCSA)
  • Ability to conduct SASE vendor competitive analysis and advise clients on solution selection based on specific use cases and requirements (e.g., Zscaler vs. Palo Alto Prisma vs. Netskope)
  • Ability to conduct Zero Trust Architecture assessments and develop roadmaps aligning Zscaler capabilities to NIST SP 800-207 or CISA Zero Trust Maturity Model frameworks
  • Experience integrating Zscaler with SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Palo Alto XSOAR) via log streaming, API connectors, or syslog for threat detection and incident response workflows
  • Experience with Zscaler APIs and automation tooling (e.g., Terraform, Ansible, Python) for provisioning, policy management, and configuration‑as‑code workflows
  • Experience designing and presenting Zscaler solution architectures tailored to client requirements, translating technical concepts for executive and non‑technical stakeholders
  • Familiarity with identity provider integrations (e.g., Okta, Azure AD, Ping Identity) for SAML/SCIM‑based authentication within ZIA and ZPA deployments
  • Previous consulting or "Big 4" experience, with a track record of delivering enterprise network security or SASE transformation engagements

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation
Cyber Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation

Deloitte France • Washington

On-site
USD 105,000 - 208,000
Travel up to 50%
Discretionary annual incentive
Cyber Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation
Cyber Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and Transformation

Deloitte France • San Francisco (CA)

On-site
USD 105,000 - 208,000
Cyber Zscaler Network Security Engineering Manager / Manager, Strategy, Growth, and Transformation
Cyber Zscaler Network Security Engineering Manager / Manager, Strategy, Growth, and Transformation

Deloitte France • San Francisco (CA)

On-site
USD 135,000 - 265,000
Cyber Senior Manager - Strategy, Growth, and Transformation
Cyber Senior Manager - Strategy, Growth, and Transformation

Deloitte France • Los Angeles (CA)

On-site
USD 163,000 - 322,000
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Philadelphia

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • San Francisco (CA)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

Medium • Austin (TX)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Raleigh (NC)

On-site
USD 150,000 - 300,000
Health insurance
401(k) with employer matching
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • New York (NY)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Atlanta (GA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3