Zscaler Network Security Engineer (Bengaluru)

Zscaler Network Security Engineer (Bengaluru)

10 Sep
|
EY
|
Bengaluru

10 Sep

EY

Bengaluru

At EY, you ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Security Technology Services - Network Security Technology

Senior Associate - Network Security Engineer | India

EY Technology

Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organiza on the size of ours working e ciently and securely. We have more than 400,000 people in over 150 countries, all of whom rely on secure technology to perform their jobs every day.

Everything we use as a rm depends on our security- rst mindset. Our users, applica ons, cloud pla orms, data centers, AI services, and business-cri cal systems all rely on modern security technologies to enable secure access, protect sensi ve informa on, and reduce cyber risk.

Within Security Technology Services, our mission is to deliver world-class security engineering capabili es that enable Zero Trust, cloud transforma on, a ack surface reduc on, and secure digital experiences. If you are passionate about building and engineering security solu ons at global scale, we want to hear from you.

The Opportunity

We are looking for a Senior Associate - Network Security Engineer to join Security Technology Services as a hands-on engineering specialist focused on Zscaler Private Access, Zero Trust Network Access, private applica on onboarding, App Connectors, Private Service Edges, Client Connector integra on, and least-privilege user-to-applica on access.

This role will report to the Assistant Director and will be responsible for detailed engineering, deployment, con gura on, tes ng, troubleshoo ng, op miza on and opera onal transi on of ZPA services used to securely connect users, devices and applica ons without exposing private applica ons to the internet.

The successful candidate must be able to explain and demonstrate hands-on experience across ZPA applica on segments, segment groups, server groups, App Connector groups, Private Service Edge deployments, authen ca on and iden ty integra ons, DNS, rou ng, TLS, SAML, SCIM, device posture, Client Connector behavior, live logs, diagnos cs, and end-to-end tra c ow troubleshoo ng.

This role will support engineering ini a ves focused on:

- Zscaler Private Access engineering for secure private applica on access Design and implementa on of granular ZPA applica on segments, segment groups and access policies
- Deployment and support of App Connectors, Private Service Edges and connector groups across cloud and data center environments
- Least-privilege user-to-applica on access and migra on from VPN-style network access to applica on-level access
- ZPA diagnos cs, policy valida on, opera onal readiness and produc on troubleshoo ng

The role will work closely with Network Security Technology, Cloud Engineering, Iden ty, Endpoint, Infrastructure, Applica on and Architecture teams to deploy scalable ZPA capabili es across global enterprise environments.

Your Key Responsibili es

The Senior Associate - Network Security Engineer, Zscaler/ZPA will work under the direc on of the Assistant Director and provide hands-on engineering support for ZPA deployment, integra on, op miza on, troubleshoo ng and con nuous improvement.

Zscaler Private Access Engineering

- Build, con gure and troubleshoot ZPA constructs including applica on segments, segment groups, server groups, servers, access policies, connector groups, App Connectors and Private Service Edges.
- Translate applica on details such as FQDNs, IPs, TCP/UDP ports, protocols, users, groups and source condi ons into secure ZPA applica on access policies.
- Validate end-to-end tra c ows from Client Connector to ZPA Service Edge or Private Service Edge, App Connector, server group and target applica on.
- Support onboarding of internal applica ons, administrator services, developer pla orms, privileged access services and business workloads into ZPA.
- Validate DNS, rou ng, TLS, IdP, SAML, SCIM, device posture, Client Connector and authen ca on integra ons required for successful ZPA deployments.
- Produce low-level implementa on steps, test evidence, troubleshoo ng notes, rollback considera ons and opera onal handover material.

App Connector and Private Service Edge Deployment

- Deploy and support App Connectors and Private Service Edges across Azure, VMware and data center environments.
- Design connector placement, connector groups, resiliency, capacity, pla orm sizing and outbound connec vity requirements.
- Troubleshoot connector health, registra on, provisioning keys, so ware updates, service edge connec vity and tunnel establishment issues.
- Validate required outbound connec vity, DNS resolu on, cer cate handling, NTP, rewall allowlists and rou ng paths for ZPA components.
- Work with infrastructure teams to ensure high availability,



service resilience and opera supportability for produc on ZPA deploymentsonal

Least-Privilege Access and Applica on Segmenta on

- Create granular applica on segments and access policies aligned to least-privilege principles for employees, administrators, vendors, service accounts and support groups.
- Use ZPA applica on discovery, policy insights, access logs and diagnos cs to validate user- toapplica on access pa erns.
- Review exis ng access models, iden fy over-permissive access and support migra on from VPN or network-level access to ZPA applica on-level access.
- Partner with applica on, iden ty and infrastructure teams to con rm business access requirements before policy enforcement.
- Con nuously improve policy quality using logs, dashboards, diagnos cs, access review outputs and produc on support ndings.

ZPA Troubleshoo ng, Diagnos cs and Opera ons

- Troubleshoot ZPA issues using a structured approach across endpoint, Client Connector, iden ty provider, ZPA policy, Service Edge, App Connector, DNS, rou ng, rewall and target applica on layers.
- Use ZPA live logs, user ac vity diagnos cs, user status diagnos cs, applica on diagnos cs, connector status, Private Service Edge status, service edge health and audit logs to iden fy root cause.
- Diagnose common scenarios including policy mismatch, unauthen cated users, failed SAML claims, missing SCIM groups, connector o ine state, DNS resolu on failure, cer cate errors, port mismatch, asymmetric rou ng and applica on unavailability.
- Develop structured test plans for applica on onboarding, policy changes, connector changes, Private Service Edge rollout and produc on migra on waves.
- Document known issues, opera onal procedures, support steps, log loca ons, escala on evidence and rollback considera ons for produc on deployments.
- Drive con nuous pla orm improvement through problem management, automa on opportuni es and implementa on lessons learned.

Engineering Automa on and Pla orm Op miza on

- Build and maintain automa on solu ons to improve security engineering e ciency.
- Automate deployment, con gura on valida on and policy management ac vi es.
- U lize Terraform, Python, PowerShell, APIs and Infrastructure-as-Code approaches.
- Improve pla orm scalability, consistency and opera onal e ec veness through automa on. -
- Contribute engineering inputs, deployment feedback and technical valida on to future-state security engineering plans.

Engineering Execu on and Collabora on

- Work under the direc on of the Assistant Director to implement approved ZPA engineering pa erns and deployment standards.
- Act as a hands-on escala on point for Zscaler, ZPA, DNS, TLS, rou ng, Client Connector and authen ca on issues.
- Collaborate with cloud, data center, iden ty, applica on and infrastructure teams during design valida on, pilot and produc on rollout.
- Provide technical guidance to engineers and support teams involved in onboarding applica ons and workloads.
- Communicate implementa on risks, dependencies and progress clearly to the Assistant Director and project stakeholders.

Technical Interview Focus Areas

Candidates should be prepared to discuss real implementa troubleshoo ng on examples and demonstrate prac cal depth in the following areas:

- Explain the ZPA connec on ow from user device and Client Connector to Service Edge or Private Service Edge, App Connector and target private applica on.
- Design an applica on segment for a private web applica on, SSH service, RDP service or administrator portal using FQDNs, ports, server groups, connector groups and access policy rules.
- Troubleshoot a user who is authen cated but unable to access one ZPA applica on while other applica ons work successfully.
- Troubleshoot an App Connector or Private Service Edge that is registered but unhealthy, disconnected or unable to reach the target applica on.
- Explain how SAML a ributes, SCIM groups, iden ty provider claims, device posture and condi onal access inputs in uence ZPA access policy decisions.
- Describe DNS resolu on requirements for ZPA, including internal DNS dependencies, splithorizon DNS pa erns and Browser Access considera ons.
- Explain connector placement and resiliency strategy for Azure, VMware and data center environments.
- Interpret ZPA logs and diagnos cs to iden fy whether a failure is caused by policy, iden ty, connector, rou ng, DNS, TLS, endpoint or target applica on issues.
- Explain how to migrate an applica on from VPN-based network access to ZPA applica on-level access with tes ng, rollback and opera onal readiness steps.
- Discuss automa on opportuni es using APIs, Terraform, Python or PowerShell for repeatable
- ZPA con gura on, valida on and repor ng.

Skills and A ributes for Success





We are interested in candidates who bring deep hands-on ZPA engineering experience from large global enterprise environments and can combine technical execu on with strong implementa on discipline.

As a successful candidate, you will demonstrate:

- Strong hands-on engineering exper se in Zscaler Private Access and Zero Trust Network Access. Deep troubleshoo ng capability across DNS, rou ng, TLS, SAML, SCIM, device posture, Client Connector, App Connectors and Private Service Edges.
- Ability to deploy and validate ZPA solu ons at enterprise scale in partnership with pla orm architecture and opera ons teams.
- Strong understanding of Azure and data center networking pa erns relevant to ZPA deployment.
- Experience working across global teams and mul ple technology disciplines.
- Strong technical communica on skills with the ability to explain implementa on risks, dependencies and engineering decisions clearly.
- Passion for automa on, repeatable engineering standards and con nuous improvement. Ability to operate e ec vely in fast-paced and highly complex enterprise environments.

To Qualify for the Role, You Must Have

- Bachelor s degree in Computer Science, Informa on Technology, Engineering or equivalent experience.
- 4-7 years of hands-on experience in network security, cloud security, infrastructure security or security engineering.
- 3-5 years of prac cal Zscaler experience, including hands-on ZPA deployment, con gura on, troubleshoo ng or opera ons.
- Strong working knowledge of ZPA applica on segments, segment groups, server groups, access policies, App Connectors, connector groups, provisioning keys and Private Service Edges.
- Ability to troubleshoot live ZPA issues using logs, diagnos cs, packet-level reasoning, DNS checks, rou ng valida on, TLS/cer cate checks and endpoint-side observa ons.
- Experience integra ng ZPA with Microso Entra ID or equivalent iden ty providers using SAML, SCIM, user groups, device posture and condi onal access signals.
- Working knowledge of Azure networking and hybrid connec vity, including VNets, subnets, rou ng, Private Link, Private Endpoint, ExpressRoute, Azure Firewall and Applica on Gateway.
- Experience deploying or suppor ng ZPA components in VMware-based data center environments and Azure cloud environments.
- Strong understanding of TCP/IP, DNS, TLS, PKI, rou ng, proxy concepts, iden ty federa on, rewall policy and enterprise networking fundamentals.
- Experience with automa on or scrip ng using Python, PowerShell, Terraform, APIs or similar tools is preferred.
- Strong English communica on skills with the ability to explain troubleshoo ng logic, root cause and implementa on decisions clearly.

Ideally, You ll Also Have

- Hands-on experience with ZPA autonomous user-to-app segmenta on, policy insights, applica on discovery work ows or AI-generated policy recommenda ons.
- Experience with ZPA Private Service Edge reference architectures and deployments for onpremises and cloud-hosted private applica ons.
- Experience migra ng users and applica ons from VPN or legacy remote access to ZPA-based applica on access.
- Experience securing Azure-hosted private applica ons, administrator interfaces, developer services and internal pla orms through ZPA.
- Experience integra ng ZPA with Microso Entra ID, Condi onal Access, SCIM, SAML and endpoint posture signals.
- Strong understanding of SASE, SSE, ZTNA, Zero Trust segmenta on and private applica on protec on pa erns.
- Zscaler cer ca ons focused on ZPA, Client Connector, Private Service Edge or equivalent hands-on creden als.
- Azure Network Engineer Associate or Azure Security Engineer cer ca on.
- CISSP, CCSP, CCNP Security or equivalent cer ca ons.

What We Look For

- We are looking for a highly technical, hands-on Zscaler/ZPA engineer who can execute complex private access deployments, solve implementa on issues and support reliable produc on adop on of ZPA across global enterprise environments.
- The ideal candidate has successfully deployed ZPA least-privilege access, applica on segments, App Connectors, Private Service Edges, Client Connector integra ons and iden ty-based access controls across Azure, enterprise data centers and VMware-based infrastructure.

What working at EY o ers

At EY, we o er a compe ve remunera on package where you ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for exible working, career development and bene ts that support your personal and professional priori es.

Plus, we o er:

- Support, coaching and feedback from engaging colleagues.
- Opportuni es to develop current skills and progress your career.
- Exposure to large-scale global technology and cybersecurity transforma on programs. The freedom and exibility to handle your role in a way that s right for you.

EY | Building a better working world

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Zscaler Network Security Engineer (Bengaluru)
🏢 EY
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: zscaler network security engineer (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: zscaler network security engineer (bengaluru) / bengaluru