Internet Security Architect

Vision Square
United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Active Directory Amazon Web Services Microsoft Azure Border Gateway Protocol Cloud Computing Cloud Computing Security Cyber Security Information Leak Prevention Domain Name System Security Extensions Multi-Factor Authentication Internet Security
+28 more
Virtual Private Networks (VPN) Python (Programming Language) Network Security Microsoft Office Open Shortest Path First (OSPF) Ping (Networking Utility) Windows PowerShell Azure Active Directory Ansible Zero Trust Network Access Web Application Security Security Information and Event Management Systems Integration Wide Area Networks Transport Layer Security Google Cloud Okta QRadar Firewalls (Computer Science) Information Technology Microsoft Sentinel Routing & Switching Terraform Open Network Automation Platform Splunk Cisco Servicenow Vmware

Job description

We are seeking an experienced Internet Security Architect with expertise in Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Internet Breakout (IBC), and Office Breakout (OBC) to architect, implement, and optimize enterprise internet security solutions. The ideal candidate will have strong experience in Zero Trust architecture, SASE, cloud security, secure web gateways, and enterprise networking., * Design and implement enterprise internet security architecture using Zscaler IBC/OBC solutions.

  • Architect and deploy Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) environments.
  • Develop secure Internet Breakout and Office Breakout strategies for branch offices and enterprise campuses.
  • Design and implement Zero Trust Network Access (ZTNA) solutions.
  • Configure and manage security policies including SSL inspection, URL filtering, DNS security, cloud firewall, and Data Loss Prevention (DLP).
  • Integrate Zscaler with Identity Providers (Azure AD, Okta, Ping Identity, Active Directory).
  • Collaborate with Network, Cloud, and Security teams to support SASE and SD-WAN initiatives.
  • Troubleshoot complex internet access, proxy, and cloud connectivity issues.
  • Perform architecture reviews, security assessments, and infrastructure optimization.
  • Create technical documentation, implementation guides, and operational standards.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, or a related field.
  • 8+ years of experience in Network Security or Cybersecurity.
  • 4+ years of hands-on experience implementing and supporting Zscaler solutions.
  • Strong expertise with:
  • Zscaler Internet Access (ZIA), + Routing & Switching
  • VPN
  • BGP
  • OSPF
  • Experience with cloud platforms:
  • Microsoft Azure
  • AWS
  • Google Cloud Platform (GCP)
  • Experience integrating Zscaler with Azure AD, Okta, Active Directory, and MFA solutions.
  • Familiarity with automation using Python, PowerShell, Terraform, or Ansible is a plus.
  • Strong analytical, troubleshooting, and communication skills.

Preferred Certifications

  • Zscaler Certified Administrator (ZCCA)
  • Zscaler Certified Architect
  • CISSP
  • CCSP
  • CISM
  • CCNP Security or CCIE Security

Preferred Skills

  • SD-WAN (Cisco Viptela, Versa, VMware SD-WAN)
  • CASB
  • DNS Security
  • Cloud Firewall
  • DLP
  • SIEM (Splunk, Microsoft Sentinel, QRadar)
  • ServiceNow
  • Network Automation
  • Zero Trust Security Architecture

Benefits & conditions

  • Hands-on experience with modern SASE and Zscaler technologies.
  • Opportunity to collaborate with leading Network, Cloud, and Security teams.
  • Long-term contract with cutting-edge enterprise infrastructure projects.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · WWC 2025

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

1:41 min

Parallels between cloud and legacy infrastructure lock-ins

Björn Stahl Björn Stahl · WWC 2024

Videos

See all

Related articles

See all