Zscaler Network Security Engineer
Ernst & Young
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Security Technology Services – Network Security Technology
Senior Associate – Network Security Engineer | India
EY Technology
Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organizaƟon the size of ours working efficiently and securely. We have more than 400,000 people in over 150 countries, all of whom rely on secure technology to perform their jobs every day.
Everything we use as a firm depends on our security-first mindset. Our users, applicaƟons, cloud plaƞorms, data centers, AI services, and business-criƟcal systems all rely on modern security technologies to enable secure access, protect sensiƟve informaƟon, and reduce cyber risk.
Within Security Technology Services, our mission is to deliver world-class security engineering capabiliƟes that enable Zero Trust, cloud transformaƟon, aƩack surface reducƟon, and secure digital experiences. If you are passionate about building and engineering security soluƟons at global scale, we want to hear from you.
The Opportunity
We are looking for a Senior Associate – Network Security Engineer to join Security Technology Services as a hands-on engineering specialist focused on Zscaler Private Access, Zero Trust Network Access, private applicaƟon onboarding, App Connectors, Private Service Edges, Client Connector integraƟon, and least-privilege user-to-applicaƟon access.
This role will report to the Assistant Director and will be responsible for detailed engineering, deployment, configuraƟon, tesƟng, troubleshooƟng, opƟmizaƟon and operaƟonal transiƟon of ZPA services used to securely connect users, devices and applicaƟons without exposing private applicaƟons to the internet.
The successful candidate must be able to explain and demonstrate hands-on experience across ZPA applicaƟon segments, segment groups, server groups, App Connector groups, Private Service Edge deployments, authenƟcaƟon and idenƟty integraƟons, DNS, rouƟng, TLS, SAML, SCIM, device posture, Client Connector behavior, live logs, diagnosƟcs, and end-to-end traffic flow troubleshooƟng.
This role will support engineering iniƟaƟves focused on:
- Zscaler Private Access engineering for secure private applicaƟon access Design and implementaƟon of granular ZPA applicaƟon segments, segment groups and access policies
- Deployment and support of App Connectors, Private Service Edges and connector groups across cloud and data center environments
- Least-privilege user-to-applicaƟon access and migraƟon from VPN-style network access to applicaƟon-level access
- ZPA diagnosƟcs, policy validaƟon, operaƟonal readiness and producƟon troubleshooƟng
The role will work closely with Network Security Technology, Cloud Engineering, IdenƟty, Endpoint, Infrastructure, ApplicaƟon and Architecture teams to deploy scalable ZPA capabiliƟes across global enterprise environments.
Your Key ResponsibiliƟes
The Senior Associate – Network Security Engineer, Zscaler/ZPA will work under the direcƟon of the Assistant Director and provide hands-on engineering support for ZPA deployment, integraƟon, opƟmizaƟon, troubleshooƟng and conƟnuous improvement.
Zscaler Private Access Engineering
- Build, configure and troubleshoot ZPA constructs including applicaƟon segments, segment groups, server groups, servers, access policies, connector groups, App Connectors and Private Service Edges.
- Translate applicaƟon details such as FQDNs, IPs, TCP/UDP ports, protocols, users, groups and source condiƟons into secure ZPA applicaƟon access policies.
- Validate end-to-end traffic flows from Client Connector to ZPA Service Edge or Private Service Edge, App Connector, server group and target applicaƟon.
- Support onboarding of internal applicaƟons, administrator services, developer plaƞorms, privileged access services and business workloads into ZPA.
- Validate DNS, rouƟng, TLS, IdP, SAML, SCIM, device posture, Client Connector and authenƟcaƟon integraƟons required for successful ZPA deployments.
- Produce low-level implementaƟon steps, test evidence, troubleshooƟng notes, rollback consideraƟons and operaƟonal handover material.
App Connector and Private Service Edge Deployment
- Deploy and support App Connectors and Private Service Edges across Azure, VMware and data center environments.
- Design connector placement, connector groups, resiliency, capacity, plaƞorm sizing and outbound connecƟvity requirements.
- Troubleshoot connector health, registraƟon, provisioning keys, soŌware updates, service edge connecƟvity and tunnel establishment issues.
- Validate required outbound connecƟvity, DNS resoluƟon, cerƟficate handling, NTP, firewall allowlists and rouƟng paths for ZPA components.
- Work with infrastructure teams to ensure high availability, service resilience and operaƟ supportability for producƟon ZPA deploymentsonal
Least-Privilege Access and ApplicaƟon SegmentaƟon
- Create granular applicaƟon segments and access policies aligned to least-privilege principles for employees, administrators, vendors, service accounts and support groups.
- Use ZPA applicaƟon discovery, policy insights, access logs and diagnosƟcs to validate user- toapplicaƟon access paƩerns.
- Review exisƟng access models, idenƟfy over-permissive access and support migraƟon from VPN or network-level access to ZPA applicaƟon-level access.
- Partner with applicaƟon, idenƟty and infrastructure teams to confirm business access requirements before policy enforcement.
- ConƟnuously improve policy quality using logs, dashboards, diagnosƟcs, access review outputs and producƟon support findings.
ZPA TroubleshooƟng, DiagnosƟcs and OperaƟons
- Troubleshoot ZPA issues using a structured approach across endpoint, Client Connector, idenƟty provider, ZPA policy, Service Edge, App Connector, DNS, rouƟng, firewall and target applicaƟon layers.
- Use ZPA live logs, user acƟvity diagnosƟcs, user status diagnosƟcs, applicaƟon diagnosƟcs, connector status, Private Service Edge status, service edge health and audit logs to idenƟfy root cause.
- Diagnose common scenarios including policy mismatch, unauthenƟcated users, failed SAML claims, missing SCIM groups, connector offline state, DNS resoluƟon failure, cerƟficate errors, port mismatch, asymmetric rouƟng and applicaƟon unavailability.
- Develop structured test plans for applicaƟon onboarding, policy changes, connector changes, Private Service Edge rollout and producƟon migraƟon waves.
- Document known issues, operaƟonal procedures, support steps, log locaƟons, escalaƟon evidence and rollback consideraƟons for producƟon deployments.
- Drive conƟnuous plaƞorm improvement through problem management, automaƟon opportuniƟes and implementaƟon lessons learned.
Engineering AutomaƟon and Plaƞorm OpƟmizaƟon
- Build and maintain automaƟon soluƟons to improve security engineering efficiency.
- Automate deployment, configuraƟon validaƟon and policy management acƟviƟes.
- UƟlize Terraform, Python, PowerShell, APIs and Infrastructure-as-Code approaches.
- Improve plaƞorm scalability, consistency and operaƟonal effecƟveness through automaƟon. •
- Contribute engineering inputs, deployment feedback and technical validaƟon to future-state security engineering plans.
Engineering ExecuƟon and CollaboraƟon
- Work under the direcƟon of the Assistant Director to implement approved ZPA engineering paƩerns and deployment standards.
- Act as a hands-on escalaƟon point for Zscaler, ZPA, DNS, TLS, rouƟng, Client Connector and authenƟcaƟon issues.
- Collaborate with cloud, data center, idenƟty, applicaƟon and infrastructure teams during design validaƟon, pilot and producƟon rollout.
- Provide technical guidance to engineers and support teams involved in onboarding applicaƟons and workloads.
- Communicate implementaƟon risks, dependencies and progress clearly to the Assistant Director and project stakeholders.
Technical Interview Focus Areas
Candidates should be prepared to discuss real implementaƟ troubleshooƟng on examples and demonstrate pracƟcal depth in the following areas:
- Explain the ZPA connecƟon flow from user device and Client Connector to Service Edge or Private Service Edge, App Connector and target private applicaƟon.
- Design an applicaƟon segment for a private web applicaƟon, SSH service, RDP service or administrator portal using FQDNs, ports, server groups, connector groups and access policy rules.
- Troubleshoot a user who is authenƟcated but unable to access one ZPA applicaƟon while other applicaƟons work successfully.
- Troubleshoot an App Connector or Private Service Edge that is registered but unhealthy, disconnected or unable to reach the target applicaƟon.
- Explain how SAML aƩributes, SCIM groups, idenƟty provider claims, device posture and condiƟonal access inputs influence ZPA access policy decisions.
- Describe DNS resoluƟon requirements for ZPA, including internal DNS dependencies, splithorizon DNS paƩerns and Browser Access consideraƟons.
- Explain connector placement and resiliency strategy for Azure, VMware and data center environments.
- Interpret ZPA logs and diagnosƟcs to idenƟfy whether a failure is caused by policy, idenƟty, connector, rouƟng, DNS, TLS, endpoint or target applicaƟon issues.
- Explain how to migrate an applicaƟon from VPN-based network access to ZPA applicaƟon-level access with tesƟng, rollback and operaƟonal readiness steps.
- Discuss automaƟon opportuniƟes using APIs, Terraform, Python or PowerShell for repeatable
- ZPA configuraƟon, validaƟon and reporƟng.
Skills and AƩributes for Success
We are interested in candidates who bring deep hands-on ZPA engineering experience from large global enterprise environments and can combine technical execuƟon with strong implementaƟon discipline.
As a successful candidate, you will demonstrate:
- Strong hands-on engineering experƟse in Zscaler Private Access and Zero Trust Network Access. Deep troubleshooƟng capability across DNS, rouƟng, TLS, SAML, SCIM, device posture, Client Connector, App Connectors and Private Service Edges.
- Ability to deploy and validate ZPA soluƟons at enterprise scale in partnership with plaƞorm architecture and operaƟons teams.
- Strong understanding of Azure and data center networking paƩerns relevant to ZPA deployment.
- Experience working across global teams and mulƟple technology disciplines.
- Strong technical communicaƟon skills with the ability to explain implementaƟon risks, dependencies and engineering decisions clearly.
- Passion for automaƟon, repeatable engineering standards and conƟnuous improvement. Ability to operate effecƟvely in fast-paced and highly complex enterprise environments.
To Qualify for the Role, You Must Have
- Bachelor’s degree in Computer Science, InformaƟon Technology, Engineering or equivalent experience.
- 4-7 years of hands-on experience in network security, cloud security, infrastructure security or security engineering.
- 3-5 years of pracƟcal Zscaler experience, including hands-on ZPA deployment, configuraƟon, troubleshooƟng or operaƟons.
- Strong working knowledge of ZPA applicaƟon segments, segment groups, server groups, access policies, App Connectors, connector groups, provisioning keys and Private Service Edges.
- Ability to troubleshoot live ZPA issues using logs, diagnosƟcs, packet-level reasoning, DNS checks, rouƟng validaƟon, TLS/cerƟficate checks and endpoint-side observaƟons.
- Experience integraƟng ZPA with MicrosoŌ Entra ID or equivalent idenƟty providers using SAML, SCIM, user groups, device posture and condiƟonal access signals.
- Working knowledge of Azure networking and hybrid connecƟvity, including VNets, subnets, rouƟng, Private Link, Private Endpoint, ExpressRoute, Azure Firewall and ApplicaƟon Gateway.
- Experience deploying or supporƟng ZPA components in VMware-based data center environments and Azure cloud environments.
- Strong understanding of TCP/IP, DNS, TLS, PKI, rouƟng, proxy concepts, idenƟty federaƟon, firewall policy and enterprise networking fundamentals.
- Experience with automaƟon or scripƟng using Python, PowerShell, Terraform, APIs or similar tools is preferred.
- Strong English communicaƟon skills with the ability to explain troubleshooƟng logic, root cause and implementaƟon decisions clearly.
Ideally, You’ll Also Have
- Hands-on experience with ZPA autonomous user-to-app segmentaƟon, policy insights, applicaƟon discovery workflows or AI-generated policy recommendaƟons.
- Experience with ZPA Private Service Edge reference architectures and deployments for onpremises and cloud-hosted private applicaƟons.
- Experience migraƟng users and applicaƟons from VPN or legacy remote access to ZPA-based applicaƟon access.
- Experience securing Azure-hosted private applicaƟons, administrator interfaces, developer services and internal plaƞorms through ZPA.
- Experience integraƟng ZPA with MicrosoŌ Entra ID, CondiƟonal Access, SCIM, SAML and endpoint posture signals.
- Strong understanding of SASE, SSE, ZTNA, Zero Trust segmentaƟon and private applicaƟon protecƟon paƩerns.
- Zscaler cerƟficaƟons focused on ZPA, Client Connector, Private Service Edge or equivalent hands-on credenƟals.
- Azure Network Engineer Associate or Azure Security Engineer cerƟficaƟon.
- CISSP, CCSP, CCNP Security or equivalent cerƟficaƟons.
What We Look For
- We are looking for a highly technical, hands-on Zscaler/ZPA engineer who can execute complex private access deployments, solve implementaƟon issues and support reliable producƟon adopƟon of ZPA across global enterprise environments.
- The ideal candidate has successfully deployed ZPA least-privilege access, applicaƟon segments, App Connectors, Private Service Edges, Client Connector integraƟons and idenƟty-based access controls across Azure, enterprise data centers and VMware-based infrastructure.
What working at EY offers
At EY, we offer a compeƟƟve remuneraƟon package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working, career development and benefits that support your personal and professional prioriƟes.
Plus, we offer:
- Support, coaching and feedback from engaging colleagues.
- OpportuniƟes to develop new skills and progress your career.
- Exposure to large-scale global technology and cybersecurity transformaƟon programs. The freedom and flexibility to handle your role in a way that’s right for you.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.- ...We are seeking a Senior AI & Azure Security Architect to design and deliver secure... ...including Landing Zones, hub-and-spoke networking, NSGs, Azure Firewall, Private Endpoints... ...Bicep or Terraform . Lead and mentor engineers and communicate architecture and security...SuggestedPermanent employment
- About the Role:We are looking for a Security Architect with strong hands-on experience in Blockchain, Web3 and DeFi Security to own security... ..., wallets and DeFi products.The role will work closely with Engineering, Risk, Compliance and leadership to identify vulnerabilities,...SuggestedContract work
- ...Stryker seeks a Senior Security Engineer to lead cybersecurity risk analysis and threat modeling for medical devices. The role involves developing secure product architectures, ensuring regulatory compliance, and managing incident response across hardware and software systems...Suggested
- ...embedded product architecture and communication protocols for security weaknesses Extract and reverse firmware binaries to identify... ...Requirements ~ Bachelor's degree in Software, Electronics Engineering, or equivalent ~2-7 years hands-on vulnerability and penetration...Suggested
- ...Knowledge Center India (KCI) is the central engine that drives the operational value for the... ...Technology; Digital Technology; Security & Architecture; Infrastructure & Services... ...Server Security Microsoft Sentinel Zscaler ZIA Zscaler ZDX Trend Enterprise Application...SuggestedHybrid workWork at office
- Application Security (AppSec) Engineer (Fintech & Logistics)About Us & Our Mission : Protecting sensitive financial ledgers, transactional user data, and enterprise supply chain telemetry requires proactive threat modeling, continuous vulnerability scanning, and uncompromised...
- ...travelers, partners, and advertisers through our consumer brands, B2B network, and travel advertising business. Here, you'll do... ...everywhere. Introduction to the Team We are seeking a Security Engineer II to help drive the evolution of our vulnerability management...
- ...responsible for defining the organization's infrastructure and security strategy, ensuring compliance, driving digital transformation, and... ...govern DLP, MFA, identity security, endpoint protection, and network security controls.- Ensure compliance with regulatory, audit, and...Hybrid workRelocation
- ...Global IT Security Engineer Senior Specialist - Gurgaon, India Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy...Work at officeLocal area
- ...the ZeroHack XDR Suite and SIEM, Managed Security Audit Services and large scale cyber skilling... ...with cyber resilience in converged networks.Backed by PE funding, senior leadership with... ...a high-performing team of consultants, engineers, and VAPT specialists; foster partnerships...
- ...structure, and tone must be consistently professional. You can explain a control failure, a residual-risk position, or a quantified scenario to an engineer, an auditor, and a board member in the register each expects. A writing sample or timed drafting exercise may be required....Full timeFor contractorsHybrid work
- ...Deploy and operationalize AI security tools. Stand up, integrate, and... ...management, runtime boundaries), Zscaler AI Security (AI Guard, asset... ...with endpoint, identity, and network signals so detections are actionable... ...owners, legal/privacy, and engineers in clear, idiomatic English....Full time
Rs 20000 - Rs 23000 per month
...experience in B2B/enterprise sales. A Cyber Security Sales Manager drives revenue growth by... ...-market clients through cold outreach, networking, and channel partners. Solution... ...Coordination: Partner with pre-sales and technical engineering teams to schedule product demos and...Full timeContract workImmediate start- ...We are seeking a seasoned Senior/Lead Security Engineer to collaborate with and assist the client's security team. This specialist will partner closely with the wider security team, focusing on essential aspects of web application protection and security operations. Set...
- ...We're looking for a Senior/Lead Security Engineer to lead HIPAA and FedRAMP/NIST 800-53 compliance efforts, converting regulatory mandates into actionable engineering tasks, supporting third-party audits, and coordinating across security, privacy, and legal functions....Work at office
- ...We're looking for a Senior/Lead Security Engineer to lead HIPAA and FedRAMP/NIST 800-53 compliance efforts, turning regulatory requirements into concrete engineering tasks while supporting third-party audits and collaborating across security, privacy, and legal teams....Work at office
- ...We are looking for an experienced Senior/Lead Security Engineer to join and support the client's security team. The specialist will work closely with the broader security team, covering key areas of web application protection and security operations. Configure, tune,...
- Spectral Consultants is Hiring - Senior - IT Audit, Cybersecurity & Risk.Spectral Consultants is hiring for one of the leading global Accounting & Advisory firms for a Senior - IT Audit, Cybersecurity & Risk opportunity.Location : Gurgaon / Bengaluru.Experience : 3 - 6 Years...
- ...seeking a full time Cybersecurity Engineer– Technology and Engineering.... ...Position Overview: The Security Engineer – Secure Access owns... ...with extended cybersecurity, network, and cloud teams, the engineer... ...optimize, and automate the full Zscaler suite (ZIA, ZPA), ensuring secure...Full timeHybrid work
- Role :Work to ensure the organisation's overall compliance with global and regional information security and data privacy regulations, including but not limited to - GDPR, NIST Cybersecurity Framework and India's Digital Personal Data Protection (DPDP) Act.Act as the Data Protection...Work at office
- ...We are looking for someone who has built security capabilities at scale, not someone who has... ...data security, application security and network security.- Deep understanding of the modern... .../ DevSecOps practices in high-velocity engineering organisations.- Has led major security incidents...
- ...: We're looking for a Senior IT Support Engineer who thrives in complex environments and enjoys... ...infrastructure, endpoints, identity, and security. This is not a traditional support role -... ...with vendor coordination when needed.Network & Security Engineering : - Configure and...Long term contract
- Role : Security Architect - DeFi & Digital AssetsAbout Wio Bank : Wio Bank is the UAE's first platform bank - a digitally native financial... ...of everything we build. We are establishing deep security engineering expertise in our Gurgaon office to support this growth.Role Purpose...Contract workWork at office
- ...Built with full governance, compliance, security, and auditability at its core.Leena AI integrates... ...: Kubernetes clusters, cloud accounts, networking, CI runners, the observability stack,... ...bill.You lead a team of 3 - 5 DevOps engineers & SREs.You work alongside our Platform...Full time
- ...Tenable OEM tools, specifically Tenable Security Center (Tenable.sc), Tenable Vulnerability... ...platforms.- Plan, schedule, and execute full-network vulnerability scans across servers,... ...and fix security flaws.- Fine-tune scan engine policies, update plugins, manage license...Long term contractFull timeTemporary workImmediate start
- ...Industry: Cybersecurity / Enterprise SaaS / AI Security About the Opportunity... ...This role is suited to a systems-minded engineer who is comfortable working close to the... ...safe updates, and resilience on unreliable networks . Collaborate with security researchers...Remote jobFull timeLocal area
- ...: Cybersecurity / Enterprise SaaS / AI Security About the Opportunity Pragmatike... ..., and the data they access . The engineering organization is scaling rapidly in India... ...Strong understanding of Go concurrency, networking, and performance, including goroutines,...Remote jobFull time
- Role : Staff Security Engineer - Detection & ResponseYour goal is to improve the education process and better the lives of students by keeping... ...tradecraft and common attack paths across endpoint, identity, network, and cloud, and familiarity with a framework such as MITRE ATT...
- INNEFU LABS.VP - Engineering.AI-Native Data Analytics & Information Security Solutions.Location: Delhi, NSP - 5 Days WFO.Experience: 15+ Years (6+ in leadership).Employment: Full-Time.Company Overview :Founded in 2010, Innefu Labs is a cutting-edge AI-driven R&D organization...Full timeHybrid work
- ...and threat modeling and develop mitigation strategies to develop secure medical products. You will work closely with cross-functional... ...: Required Qualifications: Bachelor's degree in Software Engineering/ Computer Science or related discipline & 4+ years of work experience...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Zscaler Network Security Engineer. Be the first to apply!
