ZScaler Engineer - part-time (R-00232)

Lever, Inc.

United States

On-site

USD 120,000 - 180,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive salary
Best in class medical coverage
401k with company match

Job summary

True Zero Technologies is seeking a Zscaler Engineer to design, deploy, and operate a Zero Trust–aligned ZPA environment. You will replace legacy VPNs with scalable access, support 16,600 external users across 1,600 agencies, and work with identity, networking, and security teams to ensure secure access.

You will configure App Connectors, browsers, and client connectors, integrate logging with SIEMs, and develop migration plans with thorough documentation for deployment and ongoing support.

Qualifications

  • Hands-on experience designing, deploying, configuring, and supporting ZPA in enterprise environments.
  • Strong understanding of Zero Trust Network Access concepts and replacing traditional VPN with app-centric access.
  • Experience deploying Zscaler Client Connector and coexisting with other VPN technologies.
  • Experience architecting ZPA App Connectors, App Connector Groups, segments, and Browser Access.
  • Knowledge of DNS, routing, and firewall rules in enterprise networks.
  • Experience with identity federation technologies (Okta, SAML, MFA).
  • Experience integrating Zscaler logging with SIEM or analytics (LSS, InsightIDR).
  • Ability to troubleshoot end-to-end across endpoints, ZPA, networks, and identity systems.
  • Experience planning large-scale migrations across multiple org units.
  • Strong documentation skills for designs, as-builts, runbooks, and guides.

Responsibilities

  • Design and implement ZPA architectures, including App Connector placement, redundancy, and policies.
  • Harden ZPA tenant with least-privilege admin roles and secure configurations.
  • Develop ZPA Client Connector configurations coexisting with other VPNs.
  • Design Client Connector and Browser Access solutions based on user population and requirements.
  • Configure DNS and app access with internal FQDN design and controlled exposure.
  • Validate end-to-end connectivity from external endpoints to protected apps.
  • Integrate ZPA with identity services (SAML with Okta) and mapping.
  • Configure Zscaler LSS and SIEM/monitoring integrations.
  • Create migration procedures for onboarding organizations and apps.
  • Produce as-built docs covering tenant, connectors, policies, and configurations.
  • Develop runbooks and troubleshooting procedures for admins and support.

Skills

Zscaler Private Access (ZPA) design
ZTNA concepts
Zscaler Client Connector deployment
ZPA App Connectors configuration
DNS and Network design
SAML federation with Okta
LSS and SIEM integration
Migration planning
Documentation and runbooks
Cross-team communication

Job description

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of theBest Places to Workin 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as aBest Places to Workhonoree. In addition, True Zero earned coveted spots on theInc. 5000list of fastest-growing companies in America in2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

Position Overview

The Zscaler Engineer will support the design, implementation, production deployment, and operational transition of aZscaler Private Access (ZPA)environment as part of an enterprise identity and secure access modernization initiative. The role will focus on replacing legacy VPN and site-to-site tunnel access with a scalable, Zero Trust–aligned access architecture supporting a large, distributed population of external users and organizations. The initial environment is expected to support approximately16,600 external users across roughly 1,600 independent agencies, with the architecture designed to accommodate future expansion to the internal workforce.

The engineer will be responsible for translating a validated proof-of-value architecture into a secure production environment, including ZPA tenant configuration, App Connector architecture, application segmentation, access policies, Client Connector and Browser Access strategies, DNS design, identity integration, logging, migration planning, documentation, and knowledge transfer. The position will work closely with cybersecurity, identity, networking, application, helpdesk, and agency stakeholders throughout implementation and rollout.

Job Responsibilities
  • Design and implement enterpriseZscaler Private Access (ZPA)architectures, including App Connector placement, redundancy, capacity planning, application segments, access policies, and naming standards.
  • Configure and harden the ZPA tenant using least-privilege administrative roles, appropriate administrator authentication requirements, and secure platform configuration standards.
  • Develop and implementZscaler Client Connectorconfigurations that can coexist with third-party agency VPN clients without disrupting access to agency-owned resources.
  • Design and support bothClient Connector and ZPA Browser Accesssolutions, selecting the appropriate access method based on user population, application requirements, and endpoint management capabilities.
  • Engineer DNS and application access configurations, including internal FQDN design, connector-side DNS resolution, application segmentation, and controls that prevent external agencies from receiving direct access to internal DNS infrastructure.
  • Validate end-to-end brokered application connectivity from external endpoints through Zscaler and the enterprise data center to protected applications, including performance, latency, connectivity, and transaction testing.
  • Integrate ZPA with enterprise identity services, includingSAML federation with Oktaand identity/group mappings used to enforce access policies.
  • Configure ZscalerLog Streaming Service (LSS)and integrate ZPA activity and security logging withRapid7 InsightIDRor comparable SIEM/security monitoring platforms.
  • Develop repeatable migration procedures for onboarding organizations and applications, including application publishing, identity/group mapping, legacy VPN or tunnel cutover, validation, rollback, and decommissioning activities.
  • Produce detailed as-built documentation covering the production ZPA tenant, App Connectors, application segments, policies, security hardening, and supporting configurations.
  • Develop operational runbooks and troubleshooting procedures for administrators, helpdesk personnel, technical agency contacts, and other support teams.
  • Provide technical guidance and knowledge transfer to internal engineering and security teams, including train-the-trainer sessions and post-deployment hypercare support.
Job Qualifications
  • Demonstrated hands-on experience designing, deploying, configuring, and supportingZscaler Private Access (ZPA)in enterprise environments.
  • Strong understanding ofZero Trust Network Access (ZTNA)concepts and replacing traditional VPN or network-level access with application-centric, identity-aware access controls.
  • Experience deploying and troubleshootingZscaler Client Connector, including environments where Client Connector must coexist with other endpoint VPN technologies.
  • Experience architecting and administeringZPA App Connectors, App Connector Groups, application segments, segment groups, access policies, and Browser Access.
  • Strong knowledge of enterprise networking concepts, including DNS, routing, firewall rules, TCP/IP, application connectivity, proxy technologies, VPNs, and data center connectivity.
  • Experience with enterprise identity federation and access management technologies, preferablyOkta, SAML, MFA, identity groups, and identity-based access policies.
  • Experience integrating Zscaler logging and telemetry with SIEM or security analytics platforms; experience withZscaler LSS and Rapid7 InsightIDRis highly desirable.
  • Ability to perform end-to-end troubleshooting across endpoints, Zscaler services, App Connectors, enterprise networks, identity systems, and protected applications.
  • Experience designing highly available and scalable ZPA environments, including connector sizing, redundancy, bandwidth planning, and capacity planning for large user populations. The source specifically requires the architecture to accommodate the initial external population as well as subsequent workforce growth.
  • Experience developing migration plans and executing phased or wave-based migrations involving multiple independent organizations or business units.
  • Strong documentation skills with experience producing solution designs, as-built documentation, administrator runbooks, deployment guides, troubleshooting procedures, and end-user documentation.
  • Ability to communicate technical concepts to audiences with varying levels of expertise, including engineers, cybersecurity teams, support personnel, business stakeholders, and nontechnical external administrators.
  • Experience conducting technical knowledge-transfer sessions and transitioning newly implemented platforms to operational support teams.
  • Ability to coordinate activities across parallel identity, networking, security, application, and third-party vendor workstreams.
Preferred Qualifications
  • Zscaler certifications such asZscaler Certified Engineer/Administrator in ZPA or Zero Trust Access
  • Applicable networking or cybersecurity certifications, and prior experience implementing Zscaler within government, public safety, criminal justice, or other highly regulated environments would be beneficial.
  • - Competitive salary, paid twice per month
  • - Best in class medical coverage
  • - 100% of medical premiums covered by True Zero
  • - Company wide new business incentive programs
  • - Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)
  • - 3 weeks of PTO starting + 11 Paid Holidays Annually
  • - 401k Program with 100% company match on the first 4%
  • - Monthly reimbursement of Cell Phone and Home Internet costs
  • - Paternity/Maternity Leave
  • - Investment in training and certifications to broaden and deepen your technical skills

We’re actively searching for talented and expereinced professionals who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Professional Services Consultant
Senior Professional Services Consultant

Zscaler • United States

Remote
USD 164,000 - 205,000
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • New York (NY)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Technical Marketing Engineer
Principal Technical Marketing Engineer

Zscaler • San Jose (CA)

Remote
USD 196,000 - 245,000
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Seattle (WA)

On-site
USD 150,000 - 300,000
401(k) with employer matching 6%
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Boston (MA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health, dental, and vision insurance
Paid time off
+1
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Dallas (TX)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Richmond (VA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental and vision insurance
+2
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Austin (TX)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Atlanta (GA)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture
Principal Consultant, Zscaler ZIA/ZPA and Zero Trust Architecture

DevAltus • Phoenix (AZ)

On-site
USD 150,000 - 300,000
401(k) with employer matching
Health insurance
Dental insurance
+3