ZPA Network Engineer design, implement, and optimize ZPA solutions for secure application access. Collaborate with clients on their transition to a secure network environment while maintaining top-notch security.
Responsibilities
Collaborate with Enterprise ZTNA network and security teams, as well as identity and application stakeholders, to design and support ZPA-based access to internal applications.
Design, implement, and maintain Zscaler Private Access connectivity, including App Connectors, Server Groups, Application Segments, and access policy configurations.
Analyze and assess legacy network and VPN-based access requirements, agency-specific application needs, and connectivity dependencies, and translate them into ZPA application-level access models.
Support the onboarding of applications to ZPA by validating network paths, ports, protocols, and dependency requirements, and coordinating testing and validation activities.
Configure and support ZPA access policies that enforce least-privileged access while minimizing disruption to mission-critical operations.
Troubleshoot ZPA-related access and connectivity issues, including user access failures, application reachability concerns, and connector health or routing issues.
Participate in migration activities to transition users and applications from legacy access models to ZPA in coordination with enterprise and agency stakeholders.
Ensure ZPA configurations and access models are documented, auditable, and aligned with Commonwealth security, governance, and compliance requirements.
Develop and maintain technical documentation, including configuration standards, procedures, diagrams, and operational runbooks.
Engage with vendors and Zscaler support to resolve complex issues and support platform stability and optimization.
Requirements
Strong background in enterprise networking, including routing, firewalling, DNS, and traffic flow analysis.
Experience implementing and supporting secure application access technologies such as Zscaler Private Access or similar Zero Trust access platforms.
In-depth understanding of Zero Trust Network Access concepts and application-level segmentation.
Ability to analyze complex, legacy network environments and translate them into scalable, enforceable access models.
Experience working in regulated or compliance-driven environments, ensuring adherence to security and governance standards.
Strong documentation, communication, and collaboration skills for cross-functional engagement.
Zscaler certifications such as Zscaler Digital Transformation Administrator or Zscaler Digital Transformation Engineer (preferred).
Completion of Zscaler administrator or engineer training courses relevant to ZPA (preferred).
Industry-recognized certifications such as CCNP, Security+, CySA+, or equivalent (preferred).
Experience supporting large, multi-agency, or public-sector enterprise environments (preferred).
Familiarity with regulatory and security frameworks such as CJIS, NIST 800-53, or similar standards (preferred).
Network Analyst ensuring high availability and security of networks in a growing company focused on cutting - edge technology. Collaborating in a 24x7 operational environment with internal teams and strategic projects.
IT Network Analyst responsible for monitoring and evolving network infrastructure performance and security. Collaborates with multiple areas to ensure operational efficiency and support services.
TSTC is seeking a Network Engineer to design and maintain network infrastructure, ensuring high reliability and security for federal agencies. Ideal for candidates with strong networking skills and experience in network automation.
Senior Principal Cellular and Wi - Fi Network Architect at Boeing envisioning and designing global cellular architecture. Mentoring engineers while ensuring operational excellence across various environments.
Network Engineer responsible for installing, configuring, and maintaining network infrastructure at Cayuse. Collaborate with teams to ensure smooth and secure network operations.
Manager of Network Engineering leading a team for network infrastructure at Connecticut Children’s. Responsible for technical architecture and managing customer relations with IT clients.
Cisco ISE Network Engineer working onsite in Washington D.C. for federal civilian client. Responsible for network services, testing systems, and providing technical expertise.
Network Engineer ensuring efficient operation of network infrastructure at Sword. Requires CCNP - level expertise and Palo Alto security knowledge to maintain service reliability and security posture.
Director of Network Engineering overseeing large - scale enterprise networks at MUFG. Leading transformational initiatives and collaborating with cross - functional teams to deliver reliable network solutions.
Tier 2 Network Administrator supporting intel customer with enterprise support problems and managing network incidents. Responsible for conducting network changes and resolving system failures.