Zscaler Engineer / Secure Access Service Edge

General Dynamics Information Technology
Rockville, MD, United States
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$124,093.0 - $165,600.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) User Authentication Health Informatics Cloud Computing Complex Networks Cyber Security Information Systems Domain Name System (DNS) Identity and Access Management Information Security Management IPv4 IPv6
+17 more
Virtual Private Networks (VPN) Python (Programming Language) Network Security Network Architecture Windows PowerShell RSA (Cryptosystem) Security Assertion Markup Language (SAML) Single Sign-On TCP/IP Cloud-native Network Functions (CNF) Transport Layer Security Okta Firewalls (Computer Science) Information Technology RSA SecurID Tools for Reporting Splunk

Job description

We are seeking a highly skilled Senior Zscaler Engineer / Secure Access Service Edge (SASE) Subject Matter Expert (SME) to support the Health Resources and Services Administration (HRSA). This role will lead the design, implementation, and operational support of Zscaler Internet Access (ZIA), Single Sign-On (SSO), and other SASE technologies, ensuring HRSA’s cloud and network security posture is aligned with federal security mandates and best practices., * Serve as the SME for SASE technologies; provide architectural guidance for new initiatives and support existing infrastructure.

  • Perform upgrades and updates (major and minor) for Zscaler solutions; generate reports and implement security blocks as needed.
  • Troubleshoot complex issues within the SASE solution stack, including hardware, software, and network-related problems.
  • Configure and maintain Single Sign-On (SSO) integration with HRSA’s Identity Provider (Okta) for Zscaler Internet Access (ZIA), ensuring proper SAML attribute and SCIM configuration.
  • Develop troubleshooting playbooks for endpoint Zscaler client application issues; support HRSA server and desktop support teams.
  • Conduct Best Practices Assessments and Security Lifecycle Reviews for Zscaler technologies.
  • Provide recommendations to strengthen HRSA’s security posture and assist in implementing new rulesets based on evolving security and networking requirements.
  • Create and maintain ZIA security policies (SSL inspection, URL filtering, DLP, app control, threat protection) in collaboration with the Office of Information Security and Privacy (OISP).
  • Develop and deliver ad-hoc Zscaler reports for leadership and stakeholders.
  • Ensure all changes and updates follow HRSA’s Change Management Process with full documentation.
  • Meet SLA commitments by responding to change requests/tickets within two (2) business days.
  • Implement and support RSA SecurID / RSA Authentication Manager solutions, including integration with VPNs, RADIUS, and enterprise authentication systems
  • Design, implement, and troubleshoot IPv4 and IPv6 network architectures, ensuring seamless integration and scalability across environments
  • Provides innovative methods and technical solutions using the engineering design process.
  • Collaborate closely with Project Managers, engineers, and stakeholders to deliver complex network projects on time and within scope
  • Analyze customer and business requirements to develop technical solutions for complex networking challenges

Requirements

Cloud Network Architecture, Network Architecture, SCIM (Inactive), Security Assertion Markup Language (SAML), Zscaler Architecture, 10 + years of related experience, * Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent experience).

  • 10+ years of hands-on experience administering and engineering Zscaler platforms (ZIA, ZPA, ZDX).
  • Strong knowledge of Secure Access Service Edge (SASE) concepts and architecture.
  • Experience integrating Okta (or other IDPs) with Zscaler using SAML/SCIM.
  • Proven expertise in policy creation: SSL inspection, URL filtering, DLP, CASB, and advanced threat protection.
  • Strong background in networking (TCP/IP, DNS, VPNs, firewalls) and troubleshooting end-to-end connectivity.
  • Experience in federal or enterprise-scale IT environments with strict compliance and uptime requirements (99.9%+).
  • Familiarity with federal security standards (NIST 800-53, TIC 3.0, CISA BODs).
  • Excellent communication, documentation, and collaboration skills., * Zscaler Certified Cloud Professional (ZCCP) or Zscaler Certified Cloud Administrator (ZCCA).
  • Okta Certified Professional or higher.
  • Experience supporting federal agencies or healthcare IT environments.
  • Prior experience in Security Lifecycle Review (SLR) workshops with Zscaler.
  • Knowledge of automation and reporting tools (e.g., APIs, Splunk, PowerShell, or Python)., Ability to obtain a Public Trust: candidate must have lived in the United States for at least three (3) out of the last five (5) years and pass a public trust background investigation.

Benefits & conditions

  • Full-flex work week.
  • 401K with company match.
  • Customizable health benefits packages.
  • Collaborative teams of highly motivated critical thinkers and innovators.
  • Internal mobility team dedicated to helping you own your career.
  • Rewards program for high-performing employees.

The likely salary range for this position is $124,093 - $165,600. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours: 40

Travel Required: None

Telecommuting Options: Onsite

Work Location: USA MD Rockville

Additional Work Locations:

Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process: As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About the company

This position offers the opportunity to be the lead SASE and Zero Trust security engineer for a federal health agency, shaping cloud security strategies that directly support HRSA’s mission to improve access to healthcare nationwide., We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Introducing Skupper for application connectivity

Alex Soto Alex Soto · WWC 2024

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · WWC 2025

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

3:05 min

Exploring microcontrollers and communication protocols for amateur hardware

Philipp-Alexander Blum · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all