Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus

New York (NY)

On-site

USD 150,000 - 300,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
Life insurance

Job summary

A leading technology firm is seeking a Principal Consultant to lead the design and implementation of Zero Trust architectures focusing on Zscaler (ZIA/ZPA). This role involves hands-on leadership in transitioning clients from legacy networks to modern secure access models, ensuring compliance with regulatory requirements. Candidates should have extensive experience in network security and Zero Trust architecture, with a compensation range of $150,000–$300,000 alongside full benefits including health and retirement plans.

Qualifications

  • Must have 8–12+ years in network security or Zero Trust architecture.
  • Deep expertise in Zscaler (ZIA & ZPA) and policy design.
  • Solid understanding of identity providers like Entra ID and Okta.

Responsibilities

  • Design and deliver end-to-end Zero Trust architectures.
  • Lead full lifecycle Zscaler implementations.
  • Lead transition from VPN and MPLS.

Skills

Zero Trust architecture expertise
Zscaler (ZIA/ZPA) knowledge
Networking fundamentals
Strong troubleshooting skills
Excellent communication skills

Education

8–12+ years of experience in network security

Tools

Terraform
SD-WAN platforms

Job description

Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture – Overview

We are seeking a Principal Consultant to lead the design and implementation of modern Zero Trust architectures, focusing on Zscaler (ZIA/ZPA) and secure access transformation. This is a hands‑on technical leader role translating strategy into scalable, real‑world solutions, driving DIA‑first architectures, eliminating legacy network assumptions, and delivering identity‑driven access for enterprise clients in regulated environments.

Responsibilities
  • Design and deliver end‑to‑end Zero Trust architectures leveraging ZTNA (ZPA), ZIA, and SSE/SASE frameworks.
  • Architect DIA‑first strategies that eliminate centralized egress and legacy network dependencies.
  • Ensure all access decisions are based on identity, device posture, and context, not network location.
  • Lead the transition away from VPN and MPLS to modern secure access models.
  • Lead full lifecycle Zscaler implementations across enterprise environments.
  • Configure and optimize ZIA traffic forwarding and ZPA segmentation.
  • Design, implement, and continuously refine ZIA policies (URL filtering, SSL inspection, CASB, DLP).
  • Troubleshoot complex issues across TLS, DNS, proxy, and application layers.
  • Optimize for performance, security, and operational scalability.
  • Integrate Zscaler with leading SD‑WAN platforms and implement DIA‑based traffic steering using GRE/IPsec tunnels.
  • Serve as a hands‑on technical leader across design and delivery.
  • Establish reusable architecture patterns, standards, and best practices.
  • Mentor engineers and elevate client technical capabilities.
  • Act as a trusted advisor on Zero Trust transformation and secure access strategy.
  • Lead technical discovery, solution validation, and stakeholder alignment.
  • Clearly communicate architectural shifts and business impact.
  • Align solutions with NIST, NERC‑CIP, ISO frameworks.
  • Ensure designs are audit‑ready, secure, and compliant with regulatory requirements.
Qualifications
  • Must be legally authorized to work in the United States without employer sponsorship.
  • Must be a resident of the continental United States.
  • 8–12+ years of experience in network security, Zero Trust, or secure access architecture.
  • Deep expertise in Zscaler (ZIA & ZPA), including policy design, optimization, and troubleshooting.
  • Strong experience designing and implementing ZTNA and SSE/SASE architectures.
  • Proven experience building DIA‑first architectures and eliminating VPN/MPLS‑based designs.
  • Strong knowledge of networking fundamentals: DNS, TLS, proxy architectures, traffic flow design.
  • Experience integrating Zscaler with SD‑WAN platforms and implementing GRE/IPsec tunnels.
  • Solid understanding of identity providers (Entra ID, Okta) and conditional access, device posture.
  • Experience with security policy frameworks: URL filtering, SSL inspection, CASB, DLP.
  • Familiarity with automation using APIs, Terraform, or similar tooling is a plus.
  • Experience working in regulated industries (energy, utilities, finance, healthcare) preferred.
  • Strong troubleshooting skills across network and application layers.
  • Excellent communication skills with experience engaging both technical teams and business stakeholders.
  • Demonstrated ability to operate as a hands‑on builder across architecture and implementation.
Nice to Haves
  • Experience with Entra ID (Azure AD) or Okta in Zero Trust architectures.
  • Familiarity with endpoint management and device posture enforcement (Intune, CrowdStrike).
  • Experience with automation using Terraform, APIs, or code for Zscaler deployments.
  • Exposure to enterprise compliance frameworks (NIST, NERC‑CIP, ISO) and collaboration with SOC/SIEM teams.
  • Knowledge of SIEM platforms (QRadar, Splunk) and integrating Zscaler logs.
  • Experience integrating third‑party security tools into SSE/SASE ecosystems.
  • Familiarity with cloud security architectures across Azure, AWS, GCP.
  • Exposure to performance monitoring and user experience optimization in secure access environments.
  • Experience supporting large‑scale enterprise transformations from legacy network models to Zero Trust.
Compensation

W2 Employment: $150,000–$300,000 annually with full benefits, including 401(k) with employer matching 6%, health, dental, and vision insurance, paid time off, and life insurance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Chicago (IL)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health insurance
Dental and vision insurance
+2
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Boston (MA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Dallas (TX)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Denver (CO)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Paid time off
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Seattle (WA)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Richmond (VA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental and vision insurance
+2
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Phoenix (AZ)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Atlanta (GA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • San Francisco (CA)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Philadelphia

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1