Security Engineer -Zscalar (India)

Security Engineer -Zscalar (India)

29 Aug
|
TRIGENT SOFTWARE PRIVATE
|
India

29 Aug

TRIGENT SOFTWARE PRIVATE

India

Key Responsibilities

Tenant Separation & Build-Out
Build and configure a new Zscaler tenant (ZIA and ZPA) as a full net-recent deployment for the retained entity
Configure ZIA internet security policies (URL filtering, threat protection, DLP, SSL inspection, cloud firewall)
Configure ZPA access policies, forwarding policies, inspection policies, and isolation policies
Deploy ZPA App Connectors in retained-entity network segments and validate connectivity
Establish GRE tunnels from PoP internet routers to the new ZIA cloud instance
Configure Zscaler Digital Experience (ZDX) monitoring

Identity Integration
Configure SAML/OIDC federation between the new Zscaler tenant and the shared identity provider (e.g. Okta)
Implement attribute-based user routing to ensure users are directed to the correct tenant
Coordinate with the identity team on group/attribute configuration for entity classification
Validate that users without valid entity classification are denied access to both tenants

Separacy Enforcement
Implement and validate bidirectional separacy controls - ensuring neither entity's users can access the other's private applications without explicit authorisation
Configure automated policy audit mechanisms to detect and alert on separacy violations
Support Day 1 readiness testing including cross-tenant access validation

Transitional Cross-Tenant Access
Configure Multi-ZPA Tenant Access for explicitly agreed shared services during the transitional period
Maintain cross-tenant access policies aligned to the transitional services schedule
Conduct periodic access reviews and revoke access for services that have completed transition

Divested Tenant Cleanup
Remove retained-entity users, policies, application segments, and App Connectors from the divested tenant
Reconfigure RBAC and administrative access on the divested tenant for the divested entity's operations team
Support devolved policy management models for divested teams using IaC/CICD

Transitional Service Operations & Exit
Provide administration of the divested tenant during the transitional period (platform management, connector management, tunnel management)




Produce periodic service reports covering availability and incident metrics
Support handover including admin transfer, IdP migration, and cross-tenant policy removal

Reporting & Analytics
Configure independent cyber reporting (e.g. Zscaler 360i) for each tenant
Ensure no cross-entity data leakage in reporting and analytics dashboards

Collaboration & Delivery
Work with Zscaler Professional Services on tenant provisioning and configuration
Coordinate with the core routing team on GRE tunnel and internet edge integration
Collaborate with the workplace team on Client Connector deployment and MDM integration
Participate in design assurance reviews and produce technical documentation

---

Required Skills & Experience

Zscaler Platform
Deep hands-on experience administering Zscaler ZIA (URL filtering, threat protection, DLP, SSL inspection, cloud firewall rules)
Deep hands-on experience administering Zscaler ZPA (access policies, App Connectors, application segments, segment groups, server groups)
Experience with Zscaler Client Connector deployment and configuration
Understanding of Zscaler GRE/IPSec tunnel integration for non-Client Connector traffic
Familiarity with Zscaler Digital Experience (ZDX) monitoring
Experience with multi-tenant or divestiture scenarios in Zscaler

Identity & Access
Strong understanding of SAML/OIDC federation and identity provider integration
Experience with Okta or equivalent enterprise identity provider
Understanding of attribute-based access control and user routing
Familiarity with SCIM provisioning for user/group synchronisation

Infrastructure as Code
Experience managing Zscaler configuration via Terraform (Zscaler Terraform provider)
Familiarity with CICD pipelines for policy deployment (GitHub Actions or equivalent)
Understanding of GitOps practices for configuration management





Security & Policy Design
Strong understanding of zero trust network access (ZTNA) principles
Experience designing internet security policies (web filtering, threat prevention, DLP)
Understanding of SSL inspection, certificate management, and bypass policies
Familiarity with cloud firewall rule design and traffic forwarding policies

VPN & Legacy Remote Access
Understanding of traditional VPN technologies (Cisco ASA, AnyConnect) and how they relate to/migrate towards ZTNA
Experience with VPN separation or decommissioning as part of Zscaler adoption programmes
Familiarity with split-tunnel vs full-tunnel architectures and coexistence with Zscaler Client Connector

Identity & Access Control
Familiarity with Cisco ISE or equivalent NAC platforms - understanding of how Zscaler integrates with broader identity and access control ecosystems
Understanding of TACACS+/RADIUS in the context of network device authentication alongside ZTNA

Cloud Security Integration
Understanding of cloud security architecture in AWS, Azure, and/or GCP (VPC security groups, NSGs, cloud firewalls)
Familiarity with deploying Zscaler App Connectors and Private Service Edges in cloud environments
Experience with securing hybrid connectivity (Direct Connect, ExpressRoute, GRE/IPSec tunnels) through Zscaler

Automation, DevOps & Tooling
Daily use of Git and GitHub (branching, pull requests, code review workflows)
Working knowledge of Python - able to read, run, and contribute to automation codebases (e.g. Zscaler SDK scripts, policy validation)
Experience with Terraform for Zscaler configuration management (Zscaler Terraform provider - consuming and contributing to modules)
Ability to consume and operate CI/CD-driven policy deployment pipelines built by the automation team
Comfortable working with structured data formats (JSON, YAML, HCL) used in automation templates

General
Understanding of network fundamentals (routing, DNS, IP addressing) sufficient to configure tunnel integrations
Experience with change management and controlled policy rollout
Ability to produce clear technical documentation and runbooks

📌 Security Engineer -Zscalar (India)
🏢 TRIGENT SOFTWARE PRIVATE
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security engineer -zscalar (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: security engineer -zscalar (india) / india