> Markdown version of [/jobs/ext/3606051-zero-trust-network-access-ztna-engineer](https://www.wearedevelopers.com/jobs/ext/3606051-zero-trust-network-access-ztna-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Zero Trust Network Access (ZTNA) Engineer - **Company:** CoStar Group - **Location:** Arlington, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $118,000.0 - $176,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Amazon Web Services, Proxy Servers, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Dynamic Host Configuration Protocol, Network Address Translation, Domain Name System (DNS), Multi-Factor Authentication, Internet Protocol Security (IP SEC), Virtual Private Networks (VPN), Python (Programming Language), Network Security, Network Troubleshooting, Routing, Packet Analyzer, Performance Tuning, Windows PowerShell, Remote Access Technology, Zero Trust Network Access, Runbook, Security Information and Event Management, TCP/IP, Tcpdump, Wireshark, Cloud-native Network Functions (CNF), Computer Networking Systems, Transport Layer Security, Google Cloud, Enterprise Software Applications, Okta, Firewalls (Computer Science), Infrastructure Automation Frameworks, Cloudflare, Cisco - **Published:** October 7, 2026 - **Apply:** https://www.dice.com/job-detail/2d30f0c8-4823-4e4f-a533-773c3ddc8a9f ## About the Role * Bachelor's Degree required from an accredited, not-for-profit, in-person university or college. * A track record of commitment to prior employers. * 7+ years of progressive experience in enterprise networking, network security engineering, or related infrastructure engineering roles. * 3+ years of hands-on experience implementing, operating, and supporting one or more enterprise ZTNA or SSE platforms, such as Zscaler, Netskope, Cloudflare, Palo Alto Prisma Access, or Cisco Secure Access. * Strong experience supporting globally distributed endpoints, users, applications, and networks within a large enterprise. * Expert-level knowledge of TCP/IP, DNS, DHCP, routing, NAT, TLS, proxies, VPN technologies, firewalls, and application traffic flows. * Proven ability to use packet captures, flow data, routing tables, firewall sessions, endpoint telemetry, and platform logs to isolate complex connectivity and performance problems. * Experience troubleshooting across networking, identity, endpoint, cloud, security-platform, and application domains. * Experience leading Tier-3 incident response and root-cause analysis for business-critical services. * Experience independently designing and implementing highly available enterprise network or security services. * Strong analytical, problem-solving, documentation, and communication skills. * Ability to clearly communicate technical findings, risk, and remediation plans to engineering teams and technology leadership. * Ability to independently own services and projects from technical design through implementation, production support, and continuous improvement. Preferred Qualifications and Skills * Subject matter expertise in one or more enterprise ZTNA or SSE platforms, including Zscaler, Netskope, Cloudflare, Palo Alto Prisma Access, or Cisco Secure Access. * Hands-on experience leading enterprise-scale migrations between ZTNA or SSE platforms or from legacy VPN and on-premises solutions. * Experience integrating ZTNA platforms with Entra ID, Okta, multifactor authentication services, SIEM solutions, and other enterprise security tooling. * Strong proficiency in scripting and automation using PowerShell or Python. * Experience supporting cloud networking environments in Azure, AWS, or Google Cloud Platform. * Experience leading major-incident root-cause analysis and remediation efforts. * Ability to create clear architecture diagrams, operational procedures, technical standards, incident analyses, and recommendations for engineering and leadership audiences. * Relevant industry or vendor certifications, such as Zscaler ZCCA or ZCCP, Netskope NCCSA or NCCSP, Palo Alto PCNSE, Cisco CCNP Enterprise or CCNP Security, or Microsoft Certified: Azure Network Engineer Associate. ## Description Our team is seeking a Senior Zero Trust Network Access Engineer who combines deep expertise in modern secure access technologies with advanced network troubleshooting skills. This is not solely a ZTNA platform administration role. The successful candidate must understand end-to-end network behavior and independently diagnose complex connectivity, authentication, routing, DNS, performance, and application-access issues across endpoints, enterprise networks, cloud security platforms, identity providers, and applications. This engineer will be a hands-on technical leader who owns critical services from design through production operations, leads difficult troubleshooting efforts, and drives solutions that help the company scale. This position is in Arlington, VA and offers a schedule of Monday through Thursday in office, with the option to work from home on Friday. Responsibilities * Design, deploy, configure, operate, and optimize enterprise Zero Trust Network Access (ZTNA) and Security Service Edge (SSE) platforms, such as Zscaler, Netskope, Cloudflare, Palo Alto Prisma Access, or Cisco Secure Access. * Design and manage ZTNA security and access policies, including traffic steering, application segmentation, policy evaluation, access controls, and performance optimization. * Lead migrations from traditional VPN, on-premises security architectures, and other ZTNA or SaaS solutions to modern cloud-delivered ZTNA platforms while maintaining secure and reliable access. * Serve as a senior technical escalation point for complex connectivity, authentication, routing, application-access, and performance issues. * Lead cross-domain troubleshooting across endpoints, DNS, routing, NAT, proxies, firewalls, identity providers, ZTNA and SSE services, cloud networks, and enterprise applications. * Perform packet-level and session-level analysis using tools such as Wireshark, TCPDump, platform logs, flow records, endpoint telemetry, and digital experience monitoring data. * Diagnose TCP/IP, DNS, DHCP, TLS, MTU and MSS, fragmentation, asymmetric routing, proxy, firewall-session, tunnel, and application-performance issues across end-to-end traffic paths. * Troubleshoot advanced ZTNA and SSE components and features, including PAC files, GRE and IPsec tunnels, App Connectors, Client Connectors, Branch Connectors, private access, internet access, log streaming services, digital experience monitoring, and platform configurations. * Lead technical response during high-impact incidents, coordinating troubleshooting across network, security, endpoint, identity, cloud, and application teams. * Monitor platform health, performance, availability, logs, security events, and user experience; proactively identify issues and drive remediation. * Integrate ZTNA platforms with enterprise identity providers and security platforms, including Entra ID, Okta, multifactor authentication services, and SIEM solutions. * Own technical designs and implementation standards for ZTNA connectivity, traffic steering, private application access, internet access, branch connectivity, and service resilience. * Lead architecture reviews, proofs of concept, technical evaluations, technology refreshes, security migrations, root-cause analyses, and corrective-action planning. * Create and maintain architecture diagrams, engineering standards, standard operating procedures, deployment guides, runbooks, and incident and change records. * Automate operational, monitoring, and reporting tasks using PowerShell, Python, and other infrastructure automation tools. * Collaborate with network, security, systems, cloud, operations, and compliance teams to strengthen the organization's security posture and service reliability. * Provide technical guidance, design reviews, and troubleshooting mentorship to other engineers while staying current with ZTNA, SSE, networking, identity, and cloud security technologies.