Skip to content

Open nowPosted 9 days ago

ZScaler Engineer - part-time (R-00232)

truezerotech33 open roles

Where
Remote/Telework
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowZScaler Engineer - part-time (R-00232)truezerotech · Remote/Telework
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on truezerotech's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 9 days ago

The posting

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

Position Overview

The Zscaler Engineer will support the design, implementation, production deployment, and operational transition of a Zscaler Private Access (ZPA) environment as part of an enterprise identity and secure access modernization initiative. The role will focus on replacing legacy VPN and site-to-site tunnel access with a scalable, Zero Trust–aligned access architecture supporting a large, distributed population of external users and organizations. The initial environment is expected to support approximately 16,600 external users across roughly 1,600 independent agencies, with the architecture designed to accommodate future expansion to the internal workforce.

The engineer will be responsible for translating a validated proof-of-value architecture into a secure production environment, including ZPA tenant configuration, App Connector architecture, application segmentation, access policies, Client Connector and Browser Access strategies, DNS design, identity integration, logging, migration planning, documentation, and knowledge transfer. The position will work closely with cybersecurity, identity, networking, application, helpdesk, and agency stakeholders throughout implementation and rollout.

Job Responsibilities

  • Design and implement enterprise Zscaler Private Access (ZPA) architectures, including App Connector placement, redundancy, capacity planning, application segments, access policies, and naming standards.
  • Configure and harden the ZPA tenant using least-privilege administrative roles, appropriate administrator authentication requirements, and secure platform configuration standards.
  • Develop and implement Zscaler Client Connector configurations that can coexist with third-party agency VPN clients without disrupting access to agency-owned resources.
  • Design and support both Client Connector and ZPA Browser Access solutions, selecting the appropriate access method based on user population, application requirements, and endpoint management capabilities.
  • Engineer DNS and application access configurations, including internal FQDN design, connector-side DNS resolution, application segmentation, and controls that prevent external agencies from receiving direct access to internal DNS infrastructure.
  • Validate end-to-end brokered application connectivity from external endpoints through Zscaler and the enterprise data center to protected applications, including performance, latency, connectivity, and transaction testing.
  • Integrate ZPA with enterprise identity services, including SAML federation with Okta and identity/group mappings used to enforce access policies.
  • Configure Zscaler Log Streaming Service (LSS) and integrate ZPA activity and security logging with Rapid7 InsightIDR or comparable SIEM/security monitoring platforms.
  • Develop repeatable migration procedures for onboarding organizations and applications, including application publishing, identity/group mapping, legacy VPN or tunnel cutover, validation, rollback, and decommissioning activities.
  • Produce detailed as-built documentation covering the production ZPA tenant, App Connectors, application segments, policies, security hardening, and supporting configurations.
  • Develop operational runbooks and troubleshooting procedures for administrators, helpdesk personnel, technical agency contacts, and other support teams.
  • Provide technical guidance and knowledge transfer to internal engineering and security teams, including train-the-trainer sessions and post-deployment hypercare support.

Job Qualifications

  • Demonstrated hands-on experience designing, deploying, configuring, and supporting Zscaler Private Access (ZPA) in enterprise environments.
  • Strong understanding of Zero Trust Network Access (ZTNA) concepts and replacing traditional VPN or network-level access with application-centric, identity-aware access controls.
  • Experience deploying and troubleshooting Zscaler Client Connector, including environments where Client Connector must coexist with other endpoint VPN technologies.
  • Experience architecting and administering ZPA App Connectors, App Connector Groups, application segments, segment groups, access policies, and Browser Access.
  • Strong knowledge of enterprise networking concepts, including DNS, routing, firewall rules, TCP/IP, application connectivity, proxy technologies, VPNs, and data center connectivity.
  • Experience with enterprise identity federation and access management technologies, preferably Okta, SAML, MFA, identity groups, and identity-based access policies.
  • Experience integrating Zscaler logging and telemetry with SIEM or security analytics platforms; experience with Zscaler LSS and Rapid7 InsightIDR is highly desirable.
  • Ability to perform end-to-end troubleshooting across endpoints, Zscaler services, App Connectors, enterprise networks, identity systems, and protected applications.
  • Experience designing highly available and scalable ZPA environments, including connector sizing, redundancy, bandwidth planning, and capacity planning for large user populations. The source specifically requires the architecture to accommodate the initial external population as well as subsequent workforce growth.
  • Experience developing migration plans and executing phased or wave-based migrations involving multiple independent organizations or business units.
  • Strong documentation skills with experience producing solution designs, as-built documentation, administrator runbooks, deployment guides, troubleshooting procedures, and end-user documentation.
  • Ability to communicate technical concepts to audiences with varying levels of expertise, including engineers, cybersecurity teams, support personnel, business stakeholders, and nontechnical external administrators.
  • Experience conducting technical knowledge-transfer sessions and transitioning newly implemented platforms to operational support teams.
  • Ability to coordinate activities across parallel identity, networking, security, application, and third-party vendor workstreams.
  • Zscaler certifications such as Zscaler Certified Engineer/Administrator in ZPA or Zero Trust Access
  • Applicable networking or cybersecurity certifications, and prior experience implementing Zscaler within government, public safety, criminal justice, or other highly regulated environments would be beneficial.

We’re actively searching for talented and expereinced professionals who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:

- Competitive salary, paid twice per month

- Best in class medical coverage

- 100% of medical premiums covered by True Zero

- Company wide new business incentive programs

- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)

- 3 weeks of PTO starting + 11 Paid Holidays Annually

- 401k Program with 100% company match on the first 4%

- Monthly reimbursement of Cell Phone and Home Internet costs

- Paternity/Maternity Leave

- Investment in training and certifications to broaden and deepen your technical skills

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against truezerotech's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on truezerotech's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    truezerotech's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.