> Markdown version of [/jobs/ext/1853821-zscaler-enterprise-architect](https://www.wearedevelopers.com/jobs/ext/1853821-zscaler-enterprise-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Zscaler Enterprise Architect - **Company:** GovCIO - **Location:** Lansing, MI, United States (Remote available) - **Experience:** Expert - **Salary:** $180,000.0 - **Contract:** Permanent contract - **Skills:** IEEE 802.1X, Access Network, Active Directory, Amazon Web Services, Microsoft Azure, Biometrics, Cloud Computing, Configuration Management, Cyber Security, Data Centers, Dynamic Host Configuration Protocol, Software Design Patterns, Network Address Translation, Domain Name System (DNS), Internet Protocol Security (IP SEC), Intrusion Detection and Prevention, Virtual Private Networks (VPN), Network Security, Lightweight Directory Access Protocols (LDAP), McAfee VirusScan, Network Architecture, Network Planning and Design, Routing, Network Segmentation, Remote Access Technology, Ansible, Zero Trust Network Access, Web Application Security, Security Information and Event Management, Systems Integration, TCP/IP, Virtual Local Area Networks, Wide Area Networks, Data Logging, Scripting, Transport Layer Security, Information Technology, Deployment Automation, Palo Alto Networks, TACACS+ Protocol, Terraform, Cisco - **Published:** July 14, 2026 - **Apply:** https://dejobs.org/x/x/EC55B6D159A147A7B44AE95F70375F82/job/ ## About the Role Bachelor's degree in Computer Science, Information Technology, Engineering, or equivalent experience with 15+ years (or commensurate experience), * 10+ years of progressive networking and security experience, including 5+ years in architecture/lead roles. * Deep, demonstrable expertise with Palo Alto Networks NGFW architecture and deployment at enterprise scale. * Extensive experience with Cisco routing and switching design across enterprise LAN/WAN and data center environments. * Strong experience designing and deploying McAfee Web Gateway/Web Security Proxy and cloud secure web gateway solutions (e.g., Zscaler). * In-depth knowledge of TCP/IP, routing protocols, switching, VLANs, VRFs, ACLs, NAT, QoS, DNS/DHCP/NTP. * Expertise in VPN technologies (IPsec, SSL/TLS), secure remote access, and zero-trust network architectures. * Hands-on experience integrating security platforms with AD/LDAP, RADIUS/TACACS+, and 802.1X. * Proven ability with automation and Infrastructure as Code (Ansible, Terraform, Python scripting) for network/security operations. * Experience with logging / telemetry integration, SIEM, threat detection, and incident response processes. * Strong documentation, architecture modeling, and stakeholder communication skills. Clearance Required: Must be able to attain and maintain an AOUSC Public Trust Preferred Skills and Experience * Master's preferred * Relevant certifications: Palo Alto (PCNSE/PCNSA), Cisco (CCNP/CCIE), CISSP, SANS/GIAC. * Experience with SD-WAN, SASE, cloud networking (AWS, Azure), and micro-segmentation technologies. * Prior experience leading large-scale migrations, global rollouts, or managed security, * A valid photo ID must be presented during each interview * During the Hiring Process * Enhanced Biometrics ID verification screening * Background check, to include: * Criminal history (past 7 years) * Verification of your highest level of education * Verification of your employment history (past 7 years), based on information provided in your application ## Description * Define enterprise network security architecture and roadmap for next-generation firewalls, web security proxies, VPNs, and related controls across data centers, cloud, and branch/remote sites. * Lead design and implementation of Palo Alto Networks NGFW solutions at scale, including architecture patterns for segmentation, security policies, NAT, VPNs (IPsec/SSL), threat prevention, URL filtering, TLS/SSL decryption, and high-availability/clustering. * Architect and validate network designs for Cisco routing and switching across LAN/WAN, ensuring performance, resilience, and security for high-throughput environments. * Own architecture and deployment strategies for web security platforms (McAfee Web Gateway / Web Security Proxy) and cloud-based secure web gateways (e.g., Zscaler), including policy models, threat protection, content inspection, and telemetry integration. * Integrate network security solutions with enterprise identity and authentication services (Active Directory, LDAP, RADIUS, TACACS+, 802.1X), enabling centralized policy enforcement and role-based access controls. * Define secure network segmentation, micro-segmentation, and zero-trust network access strategies; produce reference architectures, design patterns, and configuration baselines. * Drive cross-functional security initiatives: large-scale firewall and proxy migrations, datacenter-to-cloud transition, SD-WAN and SASE adoption, and consolidation of security tooling. * Establish governance: security policy lifecycle, rulebase rationalization, change control, risk assessments, and exception processes. * Design and implement logging, telemetry, and monitoring architectures to surface threats, performance issues, and policy violations; integrate with SIEM, SOAR, and observability platforms. * Lead incident response for network security events, conduct root-cause analysis, and define remediation and preventative controls. * Optimize operational processes via automation and IaC (Ansible, Terraform, scripts) for deployment, configuration management, and compliance validation. * Provide technical leadership, mentor engineers, coordinate vendor engagements, and influence executive stakeholders on strategy, budgets, and roadmap. * Ensure architectures meet regulatory, compliance, and audit requirements; produce documentation, diagrams, and security design reviews. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Embracing the Hybrid Cloud: Unlocking Success with Ansible](https://www.wearedevelopers.com/videos/932-embracing-the-hybrid-cloud-unlocking-success-with-ansible) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)