Zscaler Managing Engineer

Excelgens, Inc
United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$145,600.0 - $166,400.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Access Network Active Directory Amazon Web Services Apple Mac Systems Microsoft Azure Internet Protocol Security (IP SEC) Virtual Private Networks (VPN) Network Segmentation OpenID Azure Active Directory Zero Trust Network Access
+9 more
Security Assertion Markup Language (SAML) Systems Integration Wide Area Networks Transport Layer Security Okta HybridCloud Microsoft InTune Azure Security Center Pingfederate

Job description

Architecture & Design

Designed and deployed enterprise-scale Zscaler (ZIA, ZPA, ZDX) and SASE architectures supporting tens of thousands of users across globally distributed sites, including SD-WAN integration, regional cloud egress, GRE/IPsec tunneling, and site-survivability patterns aligned to a Zero Trust enforcement model.

Identity & Zero Trust Integration

Integrated Zscaler with enterprise identity providers (Entra ID/Azure AD, Okta, Active Directory, PingFederate) using SAML/OIDC/SCIM to enable conditional access, MFA, device posture checks, and risk-based policy enforcement - operationalizing Zero Trust across user-to-app and app-to-app flows.

ZPA & Application Segmentation

Led ZPA application discovery, segmentation, and least-privilege access design for hundreds of internal applications, eliminating legacy VPN dependencies, reducing the attack surface, and replacing flat network access with identity- and posture-aware micro-segmentation across hybrid cloud (AWS, Azure) and on-prem workloads.

Endpoint & Policy Engineering

Engineered Zscaler Client Connector (ZCC) deployment and policy baselines at scale (Windows, macOS, mobile), integrating with Microsoft Defender for Endpoint, Intune, and EDR/XDR telemetry to unify endpoint posture, SSL inspection, DLP, and CASB controls into a single enforcement plane.

Requirements

Do you have experience in macOS?, Zscaler ZDTA or ZDTE certifications preferred, * Zscaler: 4 years (Required)

  • ZDTA: 1 year (Required)
  • ZDTE: 1 year (Required)

Benefits & conditions

$70 - $80 an hour - Temporary, Full-time, Contract, Pulled from the full job description

  • Professional development assistance
  • Employee discount
  • Health savings account
  • Flexible spending account
  • Career development plan
  • Flexible schedule, * Employee discount
  • Flexible schedule
  • Flexible spending account
  • Health savings account
  • Professional development assistance

Application Question(s):

  • Certification - ZDTA and ZDTE

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

4:27 min

Centralizing access with open source identity management providers

Den Prysukhin · LIVE

Videos

See all

Related articles

See all