Retour à la recherche
J
JobgetherSource d’offres vérifiée

Senior Zscaler Engineer (ZIA/ZPA)

Offre en anglais

Design, deploy, and optimize ZIA and ZPA solutions to implement a Zero Trust security model. Lead the migration from legacy VPN infrastructure to modern secure access while collaborating with cross-functional identity and network teams.

  • Sur place
  • Canada
  • Publié 26 août 2026
  • 1 poste

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Résumé du poste

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Zscaler Engineer (ZIA/ZPA) based in Canada. This is a hands-on engineering role focused on designing, deploying, and optimizing Zero Trust security capabilities across enterprise environments. You will take ownership of the technical implementation of Zscaler Internet Access and Zscaler Private Access solutions. The role spans security policy, application access, identity integration, endpoint connectivity, and infrastructure architecture. You will work closely with Security, Network, Identity, and Endpoint teams to build secure and scalable access models. A key focus will be migrating users and applications away from legacy VPN infrastructure toward modern Zero Trust architecture. You will also troubleshoot complex connectivity and access issues while driving technical decisions through to resolution. This opportunity is well suited to an experienced security engineer who enjoys deep technical ownership and enterprise-scale transformation. Accountabilities Design, deploy, configure, and optimize Zscaler Internet Access (ZIA) policies, including URL filtering, SSL inspection, DLP, and cloud application controls. Build and manage Zscaler Private Access (ZPA) application segments, access policies, App Connector architecture, and Private Service Edge deployments. Deploy and maintain App Connectors and Private Service Edges, ensuring appropriate sizing, high availability, and placement across data center and cloud environments. Integrate Zscaler with identity platforms such as Okta using SAML and SCIM, while implementing device posture and Device Assurance requirements. Collaborate with IT Security, Network, Identity, and Endpoint teams to align Zscaler configurations with enterprise access-control and security models. Partner with endpoint teams using Jamf and Intune to package, deploy, and troubleshoot Zscaler Client Connector across Windows and macOS environments. Support BYOD and mobile application management decisions where Zscaler solutions intersect with mobile access requirements. Troubleshoot user, application, and network connectivity issues using ZIA/ZPA diagnostics, log streaming, packet captures, and other technical analysis tools. Lead cutover and migration activities associated with replacing legacy GlobalProtect VPN infrastructure, including pilot deployments, application testing, and rollback planning. Identify security and architecture gaps between the current environment and the target Zero Trust model, and implement appropriate remediation strategies. Produce configuration standards, technical documentation, and compliance materials, including documentation supporting Cyber Essentials Plus requirements. Provide clear technical progress updates, communicate risks and dependencies, and escalate significant blockers to project leadership. Requirements 5+ years of hands-on experience in enterprise network or security engineering, including at least 2 years deploying and operating Zscaler solutions. Deep practical expertise with both Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA), including architecture, policy configuration, connector deployment, and troubleshooting. Experience implementing SSL inspection, including certificate distribution and bypass management, as well as DLP policies and Zero Trust access models. Strong understanding of enterprise networking fundamentals, including DNS, GRE/IPSec tunneling, routing, proxy behavior, TLS, and client connectivity. Experience working with identity providers, preferably Okta, and familiarity with SAML, SCIM provisioning, device posture, and conditional access concepts. Experience with endpoint management technologies such as Jamf and Microsoft Intune across Windows and macOS environments. Strong analytical and troubleshooting abilities, with the capacity to investigate complex security, application, and connectivity issues through to root cause. Excellent technical writing and documentation skills, particularly for compliance-facing standards, configuration decisions, and architecture documentation. Ability to collaborate effectively with cross-functional technical teams while taking ownership of hands-on engineering decisions and delivery. Zscaler certifications such as ZDTA, ZDTP, or equivalent credentials are preferred. Benefits Competitive contract compensation of $80.00–$85.16 per hour. Full-time contract opportunity with an enterprise-focused security engineering environment. Opportunity to work on a major Zero Trust transformation involving ZIA, ZPA, identity, endpoint security, and VPN modernization. Exposure to complex cloud, data center, networking, and cybersecurity environments. Opportunity to collaborate with multidisciplinary Security, Network, Identity, and Endpoint engineering teams. Eligible full-time employees may have access to medical, dental, and vision coverage, subject to applicable eligibility requirements. Additional benefits and plan details are provided during the interview and onboarding process. How Jobgether Works We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Ce que vous ferez

Design, deploy, and optimize ZIA and ZPA solutions to implement a Zero Trust security model. Lead the migration from legacy VPN infrastructure to modern secure access while collaborating with cross-functional identity and network teams.

Exigences

Requires 5+ years of network or security engineering experience, with at least 2 years specifically operating Zscaler solutions. Expertise in identity providers like Okta and endpoint management tools like Jamf and Intune is essential.

Avantages

• Medical Coverage • Dental Coverage • Vision Coverage

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Zscaler Internet Access
  • Zscaler Private Access
  • Zero Trust Architecture
  • SSL Inspection
  • DLP
  • Okta
  • SAML
  • SCIM
  • Jamf
  • Microsoft Intune
  • DNS
  • GRE/IPSec Tunneling
  • Network Security
  • Identity Integration
  • Endpoint Connectivity
  • VPN Migration

Domaines d’emploi

  • Security & Safety
  • Technology
  • Engineering
  • Software
  • Consulting

Renseignements supplémentaires

Expérience minimale
5+ ans
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Niveau d’expérience
Mid-Senior level
Mode de candidature
La candidature directe est offerte