Zscaler Engineer/ (Pune)

Zscaler Engineer/ (Pune)

31 Jul
|
Neev
|
Pune

31 Jul

Neev

Pune

: Zscaler Network & Security Engineer (L2 / L3) Job Title: Zscaler Security Engineer (L2 / L3) Experience Level L2 Engineer: 3 to 5 Years L3 Engineer / Subject Matter Expert: 5 to 7 Years Location: Mumbai | Pune | Bengaluru | Chennai | Hyderabad | Kolkata Work Model: Hybrid to Remote Opportunity Shift: Rotational / 24x7 Operations Support (as per business requirement) Joining: Immediate to 30 days only Job Overview We are seeking a hands-on Zscaler Network & Security Engineer to join our Enterprise Cloud Security Operations team. You will be responsible for the end-to-end management, troubleshooting, policy enforcement, and operational architecture of our Zscaler platform—specifically Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA). Candidates will undergo a technical pre-screening covering core platform fundamentals including PAC file management, ZIA Central Authority operations, ZPA App Connector delivery, traffic forwarding, and Zscaler Enforcement Node (ZEN) zone design.

Key ResponsibilitiesCore Platform Responsibilities (L2 & L3) ZIA Management (Secure Web Gateway): Manage outbound internet and SaaS-bound traffic inspection. Maintain policies for URL filtering, TLS/SSL decryption, threat protection, cloud sandboxing, and Web DLP (e.g., protecting Microsoft 365 and cloud SaaS apps). ZPA Management (ZTNA): Configure and maintain Zero Trust access policies for internal applications hosted on-premises or across public clouds (AWS, Azure, GCP) without exposing underlying network segments.

PAC File & Forwarding Logic: Write, update, and debug Proxy Auto-Configuration (PAC) files to route browser and user traffic efficiently to the appropriate Zscaler Enforcement Nodes (ZENs).

Identity & SSO Integration: Maintain SAML 2.0 and SCIM user provisioning flows with IdPs (Azure AD/Entra ID,



Okta).

Incident & Escalation Management: Troubleshoot performance, access, and connectivity issues using log inspection (Nanologs/LSS), packet captures, and diagnostic tools. Level-Specific ExpectationsL2 Engineer (3–5 Years Experience) Act as the primary operational responder for daily Zscaler tickets, user access requests, and traffic bypass rules. Monitor ZPA App Connectors and Private Service Edges to ensure continuous application connectivity and high availability across user zones.

Troubleshoot Zscaler Client

Connector (ZCC) adapter conflicts, PAC file routing errors, and local browser bypass rules. Perform traffic log analysis (Wireshark, Fiddler, ZIA/ZPA admin consoles) to pinpoint performance bottlenecks. L3 Engineer (5–7 Years Experience) Act as the top technical escalation point for complex, multi-site outages, leading Root Cause Analysis (RCA).

Architect, scale, and optimize Zscaler cloud infrastructure—including multi-zone deployment strategy, Central Authority policy sync validation, and App Connector sizing/grouping.

Oversee Advanced Threat

Protection (ATP), SSL Inspection bypass policies, and granular DLP dictionary tuning. Build automated workflows using Zscaler APIs, PowerShell, or Python for provisioning and operational health reporting. Conduct technical pre-screening and mentor L2 team members.

Required Technical





Competencies & Knowledge Areas Candidates must demonstrate a working understanding of the following core concepts during technical screening: PAC File Logic: Expertise in Proxy Auto-Configuration files, JavaScript routing conditions, and bypass functions for enterprise browsers. ZIA Architecture & Central Authority (CA): Understanding of the Zscaler cloud architecture—specifically how the Central Authority manages policy updates, software, and real-time threat intelligence replication across active/standby nodes. ZIA vs.

ZPA Use Cases: Hands-on experience separating SWG use cases (internet-bound inspection, SaaS protection) from ZTNA use cases (secure private application access without VPN/lateral network movement).

App Connectors: Practical knowledge of provisioning, configuring, and troubleshooting App Connectors as secure interfaces between private apps and the ZPA cloud.

Zscaler Zones: Ability to design and troubleshoot traffic routing, policy enforcement, and high availability across logical, geographic, and cloud-native Enforcement Node (ZEN) zones.

Technical Prerequisites Networking: TCP/IP, DNS, HTTP/HTTPS, GRE Tunnels, IPsec, NAT, and BGP/Static routing.

Security & Inspection: SSL/TLS Decryption, Web DLP, CASB, Next-Gen Firewalls (Palo Alto, Fortinet, Checkpoint), and SIEM integration (Splunk, QRadar, Sentinel).

Certifications (Preferred)

L2: Zscaler Certified Cloud Associate (ZCCA-IA / ZCCA-PA), CCNA Security. L3: Zscaler Certified Cloud Qualified (ZCCP-IA / ZCCP-PA), PCNSE, or CCNP Security.

Educational

Requirements B.E. / B.Tech / B.Sc in Computer Science, Information Technology, Electronics & Telecommunications, or equivalent field experience.

Skills: zpa,zscaler,pac,security,ztna,cloud,zia

📌 Zscaler Engineer/ (Pune)
🏢 Neev
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: zscaler engineer/ (pune) / pune

Subscribe to this job alert:

Get the latest job offers by email for: zscaler engineer/ (pune) / pune