Security Engineer - Zscaler

Sev1Tech LLC

Arlington (VA)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Entarian is hiring a Zscaler Engineer to support the CISA EEOSS program in the NCR. You will design, test, and implement ZScaler internet and private access, ensuring secure cloud connectivity and IT governance alignment.

The role requires hands-on cloud security, DLP practices, and managing access controls in cloud environments. A DHS EOD clearance is preferred and U.S. citizenship is required.

Qualifications

  • Hands-on network design and engineering in large enterprise environments.
  • Experience implementing ZScaler CASB in an enterprise.
  • Experience with cloud access management and DLP policies.
  • Experience with managing user access controls in cloud environments.

Responsibilities

  • Engineer, design, test, and implement ZScaler internet (TIC) and private access (VPN replacement) solution.
  • Develop Technical Requirements Document and Detailed Design Document (DDD) for the network architecture.
  • Develop and maintain monitoring processes supporting a 24/7/365 Network Operations Center (NOC).
  • Update documents with network design changes and test migrations to verify requirements and security.
  • Prepare test reports and Implementation Plans for changes impacting the network environment.
  • Implements the ZScaler solution across an enterprise.
  • Implements Data Loss Prevention (DLP) practices and policies.
  • Managing user access controls in cloud environments.
  • Serve as a Subject Matter Expert in CASB, DLP, API, SD-WAN, and related practices.
  • Provide internal consulting, technical guidance, and training support.
  • Must be able to work with minimal supervision and communicate effectively.

Skills

Zscaler CASB
DLP practices
Cloud IAM
Cloud access management
ServiceNow
Jira
VMware vCenter
Cloud computing concepts
Network design
Network engineering
Cloud migration
Cloud monitoring
Proxy concepts
Audit trails
Load balancers

Education

Bachelor's degree

Tools

VMware vCenter
Zscaler
Cloud-based monitoring tools
Jira
ServiceNow

Job description

The U.S. Cybersecurity and Infrastructure Security (CISA) mission is to lead the national effort to protect and enhance the resilience of the nation’s physical and cyber infrastructure. CISA includes the CISA Mission Enabling Offices (MEOs) and six Divisions: the Cybersecurity Division (CSD), the Emergency Communications Division (ECD), the Integrated Operations Division (IOD), Infrastructure Security Division (ISD), the Stakeholder Engagement Division (SED), as well as the National Risk Management Center (NRMC), which are headquartered within the National Capital Region (NCR).

CISA’s information technology (IT) landscape has historically produced networks and systems individually managed and maintained within each of its Divisions as well as its MEOs. This task order is to provide Enterprise Engineering and Operations Support Services (EEOSS) to CISA/OCIO to establish enterprise IT capabilities. These enterprise IT capabilities shall support CISA’s ability to continue establishing a modern IT infrastructure; engaging in various initiatives to evaluate and implement emerging technologies; migrating to the cloud; supporting mobility and collaboration platforms; and continually improving the performance, security, and availability of enterprise IT services.

Security Engineering role will focus on providing Zscaler Engineering support and will be responsible for implementing the ZScaler solutions to manage connections between CISA users and cloud environments, applying IT Security Governance policies to prevent data exposure, ensure compliance across SaaS applications, and drive innovation for management, functionality, and reporting between disparate mission and IT groups.

Primary Responsibilities
  • The Zscaler Engineer is responsible for the engineering, design, test, and implementation of ZScaler internet (TIC) and private access (VPN replacement) solution.
  • Support of the development of the Technical Requirements Document and a Detailed Design Document (DDD) for the network architecture, consistent with the associated Functional Requirements Document and DDD, before transitioning to Operations.
  • Development and maintenance of monitoring processes and procedures supporting a 24/7/365 Network Operations Center (NOC).
  • Support of all updates to all documents when there is change in the network design and/or technologies and collaborating with all stakeholders to test all related systems and application migration processes to verify that the systems meet requirements and can host applications with no degradation to performance or security.
  • Preparation of test reports and Implementation Plans for each change impacting the network environment.
  • Implements the ZScaler solution across an enterprise.
  • Implements Data Loss Prevention (DLP) practices and policies.
  • Managing user access controls in cloud environments.
  • Serves as a Subject Matter Expert in the advanced CASB, DLP, API, SD-WAN, and location implementation and best practices around those implementations.
  • Provides internal consulting, technical guidance, information and support to application developers, computer operations, company management and departmental clients. Assists in internal training programs.
  • Must be able to work with minimal supervision and possess excellent written and verbal communication skills.
Minimum Qualifications

Bachelors AND 5 years' experience OR 9 years' experience in lieu of a degree.

  • Requires hands‑on experience in Network Design, Network Engineering, Network Operational Support, and cloud engineering experience of Medium to Large enterprise network environments.
  • Experience implementing the ZScaler CASB solution in an enterprise.
  • Experience with Zscaler or related Data Loss Prevention (DLP) practices and policies.
  • Experience with managing user access controls in cloud environments.
  • Experience with ServiceNow, Jira, VMware vCenter, cloud computing concepts.
  • Experience with cloud reporting with preparation for both internal and executive stakeholders.
  • Experience migrating from legacy on‑prem networking to the cloud networking.
  • Experience with traditional on‑premises proxies.
  • Experience with cloud-based proxy concepts.
  • Experience with Cloud Identity and Access Management.
  • Experience deploying and managing virtual servers on premise and in the cloud.
  • Experience with concepts and operations of cloud-based on physical load balancers.
  • Experience with implementing and exporting audit trails.
  • Experience with cloud-based monitoring solutions.

Must be eligible to obtain a Department of Homeland Security EOD clearance (Requirements 1. US Citizenship, 2. Favorable Background Investigation).

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

Clearance Preference
  • DHS EOD - 1st priority
  • Any DHS badge + DoD Top Secret or Secret - 2nd choice
  • DoD Secret or Top Secret + willingness to get EOD clearance - 3rd choice (it can take 45 days to obtain EOD clearance – work can only begin once the clearance is fully adjudicated).
About Us

Formed through the strategic union of Sev1Tech and ERT, Entarian is a premier provider of mission‑critical engineering and technology solutions. Founded on a legacy of excellence dating back to 1993, Entarian is a product of an evolved and fully diversified engineering and federal technology leader. From deep space to defense and civilian missions, Entarian delivers secure, mission‑aligned digital solutions that drive national resilience and operational effectiveness. We don't just support modernization; we define it.

Join the Mission and Start your Career Journey: Apply Directly via our Careers Portal. Connect, Referrals & Inquiries? Email the team: careers@entarian.com.

Entarian is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Zscaler
Security Engineer - Zscaler

ERT, Inc. • Arlington (VA)

On-site
USD 90,000 - 120,000
Security Engineer - Zscaler
Security Engineer - Zscaler

Tech(X)- Techximius Corp • Washington

On-site
USD 150,000 - 190,000
Network Security Engineer (Zscaler)
Network Security Engineer (Zscaler)

Uvcyber • Arlington (VA)

On-site
USD 140,000 - 165,000
401(k) employer match
Medical, Dental, and Vision Insurance
Discretionary Time Off (DTO)
Manager, Information Security Engineering
Manager, Information Security Engineering

Zscaler • San Jose (CA)

Hybrid
USD 137,200 - 196,000
Technical Support Engineer II
Technical Support Engineer II

Framework Ventures • United States

Hybrid
USD 70,000 - 90,000
Health plans
Time off for vacation and sick time
Parental leave options
+2
Senior Manager, Zscaler
Senior Manager, Zscaler

Vanguard • Scottsdale (AZ)

On-site
USD 140,000 - 190,000
Senior Manager, Zscaler
Senior Manager, Zscaler

Vanguard • Charlotte (NC)

On-site
USD 140,000 - 210,000
Zscaler Security Engineer
Zscaler Security Engineer

Vytwo • Prosper (TX)

Hybrid
USD 110,000 - 140,000
Flexible work from home options
Product Support Engineer
Product Support Engineer

Framework Ventures • United States

Hybrid
USD 70,000 - 90,000
Various health plans
Time off for vacation and sick time
Parental leave options
+3
Zscaler Security Engineer – Cloud Access & DLP
Zscaler Security Engineer – Cloud Access & DLP

Sev1Tech LLC • Arlington (VA)

On-site
USD 120,000 - 150,000