> Markdown version of [/jobs/ext/2012454-zscaler-engineer-secure-access-service-edge](https://www.wearedevelopers.com/jobs/ext/2012454-zscaler-engineer-secure-access-service-edge). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Zscaler Engineer / Secure Access Service Edge - **Company:** General Dynamics Information Technology - **Location:** Rockville, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $124,093.0 - $165,600.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), User Authentication, Health Informatics, Cloud Computing, Complex Networks, Cyber Security, Information Systems, Domain Name System (DNS), Identity and Access Management, Information Security Management, IPv4, IPv6, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Network Architecture, Windows PowerShell, RSA (Cryptosystem), Security Assertion Markup Language (SAML), Single Sign-On, TCP/IP, Cloud-native Network Functions (CNF), Transport Layer Security, Okta, Firewalls (Computer Science), Information Technology, RSA SecurID, Tools for Reporting, Splunk - **Published:** August 10, 2026 - **Apply:** https://www.dice.com/job-detail/6cd7049e-1909-4800-b937-7caf23e758a1 ## About the Role Cloud Network Architecture, Network Architecture, SCIM (Inactive), Security Assertion Markup Language (SAML), Zscaler Architecture, 10 + years of related experience, * Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent experience). * 10+ years of hands-on experience administering and engineering Zscaler platforms (ZIA, ZPA, ZDX). * Strong knowledge of Secure Access Service Edge (SASE) concepts and architecture. * Experience integrating Okta (or other IDPs) with Zscaler using SAML/SCIM. * Proven expertise in policy creation: SSL inspection, URL filtering, DLP, CASB, and advanced threat protection. * Strong background in networking (TCP/IP, DNS, VPNs, firewalls) and troubleshooting end-to-end connectivity. * Experience in federal or enterprise-scale IT environments with strict compliance and uptime requirements (99.9%+). * Familiarity with federal security standards (NIST 800-53, TIC 3.0, CISA BODs). * Excellent communication, documentation, and collaboration skills., * Zscaler Certified Cloud Professional (ZCCP) or Zscaler Certified Cloud Administrator (ZCCA). * Okta Certified Professional or higher. * Experience supporting federal agencies or healthcare IT environments. * Prior experience in Security Lifecycle Review (SLR) workshops with Zscaler. * Knowledge of automation and reporting tools (e.g., APIs, Splunk, PowerShell, or Python)., Ability to obtain a Public Trust: candidate must have lived in the United States for at least three (3) out of the last five (5) years and pass a public trust background investigation. ## Description We are seeking a highly skilled Senior Zscaler Engineer / Secure Access Service Edge (SASE) Subject Matter Expert (SME) to support the Health Resources and Services Administration (HRSA). This role will lead the design, implementation, and operational support of Zscaler Internet Access (ZIA), Single Sign-On (SSO), and other SASE technologies, ensuring HRSA's cloud and network security posture is aligned with federal security mandates and best practices., * Serve as the SME for SASE technologies; provide architectural guidance for new initiatives and support existing infrastructure. * Perform upgrades and updates (major and minor) for Zscaler solutions; generate reports and implement security blocks as needed. * Troubleshoot complex issues within the SASE solution stack, including hardware, software, and network-related problems. * Configure and maintain Single Sign-On (SSO) integration with HRSA's Identity Provider (Okta) for Zscaler Internet Access (ZIA), ensuring proper SAML attribute and SCIM configuration. * Develop troubleshooting playbooks for endpoint Zscaler client application issues; support HRSA server and desktop support teams. * Conduct Best Practices Assessments and Security Lifecycle Reviews for Zscaler technologies. * Provide recommendations to strengthen HRSA's security posture and assist in implementing new rulesets based on evolving security and networking requirements. * Create and maintain ZIA security policies (SSL inspection, URL filtering, DLP, app control, threat protection) in collaboration with the Office of Information Security and Privacy (OISP). * Develop and deliver ad-hoc Zscaler reports for leadership and stakeholders. * Ensure all changes and updates follow HRSA's Change Management Process with full documentation. * Meet SLA commitments by responding to change requests/tickets within two (2) business days. * Implement and support RSA SecurID / RSA Authentication Manager solutions, including integration with VPNs, RADIUS, and enterprise authentication systems * Design, implement, and troubleshoot IPv4 and IPv6 network architectures, ensuring seamless integration and scalability across environments * Provides innovative methods and technical solutions using the engineering design process. * Collaborate closely with Project Managers, engineers, and stakeholders to deliver complex network projects on time and within scope * Analyze customer and business requirements to develop technical solutions for complex networking challenges ## Related Videos - [IP Authentication: A Tale of Performance Pitfalls and Challenges in Prod](https://www.wearedevelopers.com/videos/1413-ip-authentication-a-tale-of-performance-pitfalls-and-challenges-in-prod) - [IoT: The road to sustainability](https://www.wearedevelopers.com/videos/557-iot-the-road-to-sustainability) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)