Sr. Zscaler Security Engineer
Indexed description
This role owns the end-to-end management, optimization, and troubleshooting of the organization’s Zscaler security stack (ZIA, ZCC, Zscaler Cloud Connector, CASB, SaaS Security API, etc.). You’ll handle configuration, policy management, traffic forwarding, monitoring, incident response, reporting, and alignment with compliance/security requirements. You’re the go-to person for keeping cloud security controls tight, stable, and aligned with best practices.
Key Responsibilities
1. Platform Configuration & Administration
- Configure and maintain Zscaler Internet Access (ZIA), including traffic routing through the Zscaler cloud.
- Manage firewall, VPN, DNS, ACL, SAML/SCIM authentication, and security profiles within Zscaler.
- Set up and manage GRE/IPsec tunnels and redundancy.
- Configure locations, sub-locations, virtual service edges, and ZCC client profiles.
- Build and tune forwarding profiles, app profiles, and PAC files (bypass and redirect logic).
2. Security Policy Management
- Create and optimize access control policies (allow/block/quarantine).
- Configure URL filtering, threat prevention (AV, sandboxing, IPS), SSL inspection, and compliance policies.
- Build DLP policies for sensitive data protection across web and SaaS platforms.
- Manage Cloud App Control, Cloud App Risk Assessment, Smart Browser Isolation, and Browser Control policies.
- Create and enforce bandwidth management, QoS, and traffic shaping rules.
3. Advanced CASB & SaaS Security
- Configure Zscaler CASB for sanctioned/unsanctioned cloud application monitoring.
- Implement CASB DLP, data protection, tokenization, encryption, and rights management.
- Configure CASB threat protection for malware, phishing, insider threat, and compromised-account detection.
- Manage SaaS Security API for DLP, malware detection, content scanning, and scheduled inspections.
4. Monitoring, Troubleshooting & Optimization
- Conduct end-to-end troubleshooting using MTR, Zscaler Analyzer, Cloud Performance Test tools, logs, and analytics.
- Identify misconfigurations, performance bottlenecks, or policy conflicts across all Zscaler components.
- Collaborate with Zscaler Support for complex escalations, providing logs and configuration details.
- Keep Zscaler agents, connectors, and signatures updated.
5. Reporting & Compliance
- Use dashboards to track traffic, threats, usage, violations, and anomalies.
- Build custom reports for security posture, web usage, application usage, threat intelligence, and compliance.
- Schedule recurring reports for stakeholders.
- Generate compliance reports aligned with regulatory and internal standards.
6. Capacity Planning & Best Practices
- Track resource utilization trends and forecast bandwidth, session counts, and capacity requirements.
- Ensure configurations align with best practices and organizational architecture.
- Maintain detailed documentation of configurations, test cases, troubleshooting steps, and audit artifacts.
Qualifications
Required
- Bachelor’s degree in computer science, Engineering, or a related field.
- 5 years of experience in network security, cloud security, or security engineering.
- Strong hands-on experience with Zscaler (ZIA, ZCC, GRE/IPsec, CASB, Zscaler Client Connector).
- Solid understanding of:
- TCP/IP, DNS, VPNs, HTTP/HTTPS, SSL/TLS
- Proxy technologies and traffic forwarding
- Firewalls, IPS, DLP, sandboxing
- Identity services (SAML, SCIM, AD/IDaaS)
Preferred
- Zscaler certifications (ZCCA-IA, ZCCP-IA, ZCCA-SE, ZCCP-SE, etc.).
- Experience with cloud platforms (Azure/AWS/GCP).
- Familiarity with SOC workflows, SIEM tools, or zero-trust architectures.
- Strong troubleshooting skills using logs, analytics, packet traces, and routing tools.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search