Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus

Seattle (WA)

On-site

USD 150,000 - 300,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
Life insurance

Job summary

A leading technology consulting firm is seeking a Principal Consultant in Seattle to lead Zero Trust architecture design and implementation focusing on Zscaler. This hands-on role requires deep expertise in Zscaler, network security architectures, and proven experience in migrating organizations to DIA-first strategies while ensuring compliance and security across enterprise environments. The compensation ranges from $150,000 to $300,000 annually, with full benefits including health insurance, 401(k) matching, and paid time off.

Qualifications

  • 8–12+ years of experience in network security, Zero Trust, or secure access architecture.
  • Deep expertise in Zscaler including policy design, optimization, and troubleshooting.
  • Strong knowledge of networking fundamentals: DNS, TLS, proxy architectures, traffic flow design.

Responsibilities

  • Design and deliver end-to-end Zero Trust architectures leveraging ZTNA, ZIA, and SSE/SASE frameworks.
  • Lead full lifecycle Zscaler implementations across enterprise environments.
  • Optimize ZIA traffic forwarding and ZPA segmentation.

Skills

Zscaler (ZIA & ZPA)
Zero Trust Architecture
Networking Fundamentals
ZTNA and SSE/SASE
Troubleshooting Skills
Communication Skills

Tools

Terraform
SD-WAN Integration

Job description

Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture – Overview

We are seeking a Principal Consultant to lead the design and implementation of modern Zero Trust architectures, focusing on Zscaler (ZIA/ZPA) and secure access transformation. This is a hands‑on technical leader role translating strategy into scalable, real‑world solutions, driving DIA‑first architectures, eliminating legacy network assumptions, and delivering identity‑driven access for enterprise clients in regulated environments.

Responsibilities
  • Design and deliver end‑to‑end Zero Trust architectures leveraging ZTNA (ZPA), ZIA, and SSE/SASE frameworks.
  • Architect DIA‑first strategies that eliminate centralized egress and legacy network dependencies.
  • Ensure all access decisions are based on identity, device posture, and context, not network location.
  • Lead the transition away from VPN and MPLS to modern secure access models.
  • Lead full lifecycle Zscaler implementations across enterprise environments.
  • Configure and optimize ZIA traffic forwarding and ZPA segmentation.
  • Design, implement, and continuously refine ZIA policies (URL filtering, SSL inspection, CASB, DLP).
  • Troubleshoot complex issues across TLS, DNS, proxy, and application layers.
  • Optimize for performance, security, and operational scalability.
  • Integrate Zscaler with leading SD‑WAN platforms and implement DIA‑based traffic steering using GRE/IPsec tunnels.
  • Serve as a hands‑on technical leader across design and delivery.
  • Establish reusable architecture patterns, standards, and best practices.
  • Mentor engineers and elevate client technical capabilities.
  • Act as a trusted advisor on Zero Trust transformation and secure access strategy.
  • Lead technical discovery, solution validation, and stakeholder alignment.
  • Clearly communicate architectural shifts and business impact.
  • Align solutions with NIST, NERC‑CIP, ISO frameworks.
  • Ensure designs are audit‑ready, secure, and compliant with regulatory requirements.
Qualifications
  • Must be legally authorized to work in the United States without employer sponsorship.
  • Must be a resident of the continental United States.
  • 8–12+ years of experience in network security, Zero Trust, or secure access architecture.
  • Deep expertise in Zscaler (ZIA & ZPA), including policy design, optimization, and troubleshooting.
  • Strong experience designing and implementing ZTNA and SSE/SASE architectures.
  • Proven experience building DIA‑first architectures and eliminating VPN/MPLS‑based designs.
  • Strong knowledge of networking fundamentals: DNS, TLS, proxy architectures, traffic flow design.
  • Experience integrating Zscaler with SD‑WAN platforms and implementing GRE/IPsec tunnels.
  • Solid understanding of identity providers (Entra ID, Okta) and conditional access, device posture.
  • Experience with security policy frameworks: URL filtering, SSL inspection, CASB, DLP.
  • Familiarity with automation using APIs, Terraform, or similar tooling is a plus.
  • Experience working in regulated industries (energy, utilities, finance, healthcare) preferred.
  • Strong troubleshooting skills across network and application layers.
  • Excellent communication skills with experience engaging both technical teams and business stakeholders.
  • Demonstrated ability to operate as a hands‑on builder across architecture and implementation.
Nice to Haves
  • Experience with Entra ID (Azure AD) or Okta in Zero Trust architectures.
  • Familiarity with endpoint management and device posture enforcement (Intune, CrowdStrike).
  • Experience with automation using Terraform, APIs, or code for Zscaler deployments.
  • Exposure to enterprise compliance frameworks (NIST, NERC‑CIP, ISO) and collaboration with SOC/SIEM teams.
  • Knowledge of SIEM platforms (QRadar, Splunk) and integrating Zscaler logs.
  • Experience integrating third‑party security tools into SSE/SASE ecosystems.
  • Familiarity with cloud security architectures across Azure, AWS, GCP.
  • Exposure to performance monitoring and user experience optimization in secure access environments.
  • Experience supporting large‑scale enterprise transformations from legacy network models to Zero Trust.
Compensation

W2 Employment: $150,000–$300,000 annually with full benefits, including 401(k) with employer matching 6%, health, dental, and vision insurance, paid time off, and life insurance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Philadelphia

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • San Francisco (CA)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Atlanta (GA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

Medium • Austin (TX)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Phoenix (AZ)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Richmond (VA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental and vision insurance
+2
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Dallas (TX)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Boston (MA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • New York (NY)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Chicago (IL)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health insurance
Dental and vision insurance
+2