Logo for Bee Talent Solutions

Senior Zscaler Engineer (ZIA/ZPA)

Role overview

Qualifications

  • 5+ years of hands-on network or security engineering experience in enterprise environments
  • Deep hands-on expertise in both ZIA and ZPA
  • Experience with SSL inspection deployment and DLP policy design
  • Strong technical writing skills

Responsibilities

  • Design, build, and tune ZIA policies and ZPA application segments
  • Deploy and maintain App Connectors and Private Service Edges
  • Integrate Zscaler with identity stack and enforce device posture
  • Troubleshoot user, application, and network issues

About the company

Bee Talent Solutions logo

Bee Talent Solutions

Staffing & Recruiting

Bee Talent Solutions is a staffing agency dedicated to partnering with our clients to drive key business initiatives through mindful talent engagements. Headquartered in Bellevue, WA, with a national client foot-print, our agency has a proven track record of delivering successful talent solutions fostering growth and innovation for our clients.

Company details

Company typeStartup
IndustryStaffing & Recruiting
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Our client is seeking a contract Zscaler Engineer to design, deploy, configure, and optimize Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) across the organization. This is a hands-on engineering role: the consultant will own the technical build — making, implementing, and validating configuration decisions — rather than tracking them. Two positions are available, working in parallel across the ZIA and ZPAworkstreams.

Responsibilities:

  • Design, build, and tune ZIA policies — URL filtering, SSL inspection, DLP, and cloud app control — and ZPA application segments, access policies, and App Connector architecture
  • Deploy and maintain App Connectors and Private Service Edges, including sizing, high availability, and placement across data center and cloud environments
  • Integrate Zscaler with our identity stack (Okta SAML/SCIM) and enforce device posture / Device Assurance within access policy
  • Partner with IT Security, Network, and Identity teams to align Zscaler policy with existing access control models
  • Work with endpoint teams (Jamf/Intune) to package, deploy, and troubleshoot Zscaler Client Connector across macOS and Windows fleets
  • Support BYOD/MAM scoping decisions where Zscaler intersects with mobile access
  • Troubleshoot user, application, and network issues using ZIA/ZPA diagnostics, log streaming, and packet capture, and drive root cause to resolution
  • Execute cutover and migration work to decommission the legacy GlobalProtect VPN, including pilot waves, application testing, and rollback planning
  • Document configuration standards and decisions for compliance purposes, including UK Cyber Essentials Plus (CE+) control mapping
  • Identify and remediate gaps between the current state and the target Zero Trust architecture
  • Provide clear technical status updates and escalate risks and blockers to the project lead

Requirements:

  • 5+ years of hands-on network or security engineering experience in enterprise environments, including at least 2 years deploying and operating Zscaler
  • Deep hands-on expertise in both ZIA and ZPA — architecture, policy configuration, connector deployment, and troubleshooting
  • Experience with SSL inspection deployment (certificate distribution, bypass management), DLP policy design, and Zero Trust access models
  • Solid enterprise networking fundamentals: DNS, Client files, GRE/IPSec tunneling, routing, proxy behavior, and TLS
  • Experience with identity providers (Okta preferred), SAML/SCIM provisioning, and device posture / conditional access concepts
  • Strong technical writing skills — this role will produce compliance-facing documentation
  • Zscaler certification(s) preferred (ZDTA, ZDTP, or equivalent)

Benefits: Bee Talent Solutions offers a competitive benefits package for eligible full-time employees, including medical, dental, and vision coverage. Additional details regarding eligibility and plan offerings will be provided during the interview and onboarding process.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Field Engineer (Solutions) Related jobs

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.