Role: Zscaler Security Architect
Location: Cincinnati, OH – REMOTE
10-15+ years of Exp
Key Responsibilities
· Design and implement enterprise-scale Zscaler architectures supporting Zero Trust principles.
· Lead ZIA and ZPA deployment, migration, and optimization initiatives across global environments.
· Define secure internet access, private application access, SaaS security, and cloud access strategies.
· Develop SASE and Zero Trust roadmaps aligned with business, security, compliance, and operational goals.
· Conduct current-state architecture assessments and identify opportunities for modernization and risk reduction.
· Design secure access solutions for cloud, on-premises, hybrid, and remote workforce environments.
· Integrate Zscaler solutions with Identity Providers such as Microsoft Entra ID / Azure AD, Okta, Ping Identity, and other IAM platforms.
· Implement application segmentation strategies using ZPA and Zero Trust access policies.
· Design and govern URL filtering, CASB, Cloud Firewall, DLP, SSL inspection, sandboxing, and data protection policies.
· Support network transformation programs replacing or reducing dependency on traditional VPN architectures.
· Collaborate with network, cloud, IAM, endpoint, SOC, and GRC teams to implement effective security controls.
· Lead troubleshooting and remediation of complex Zscaler, traffic steering, authentication, and policy-related issues.
· Develop architecture standards, reference designs, HLDs, LLDs, migration plans, runbooks, and operational handover documents.
· Provide governance, risk, control, and compliance guidance related to Zscaler implementations.
· Mentor engineering teams and provide technical leadership for project delivery and managed services transition.
TECHNICAL SKILLS / COMPETENCIES:
Zscaler Platform (Need strong)
ZIA, ZPA, ZDX, Cloud Firewall, CASB, Data Protection, SSL Inspection, Sandbox, URL Filtering
Architecture
Zero Trust Architecture, SASE, Software Defined Perimeter, Network Security Architecture, Cloud SecurityArchitecture
Identity Integration
Microsoft Entra ID / Azure AD, Okta, Ping Identity, SAML, OAuth, OIDC, MFA, conditional access patterns
Networking
DNS, Proxy, VPN, SD-WAN, GRE/IPSec tunnels, PAC files, traffic forwarding, routing, firewalls, certificates
Cloud & Security
Azure, AWS, GCP, SaaS security, DLP, SWG, endpoint security, PKI, SIEM/SOC integration
Documentation
HLD, LLD, migration strategy, reference architecture, SOP, runbook, operational acceptance documentation
Mandatory Skills
· Expert-level hands-on experience with Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zscaler Digital Experience (ZDX).
· Strong understanding of Zero Trust, SASE, secure web gateway, cloud firewall, CASB, DLP, and traffic inspection concepts.
· Proven experience designing Zscaler architecture for large enterprise and global transformation programs.
· Ability to integrate Zscaler with IAM, endpoint, network, cloud, and SOC/security monitoring ecosystems.
· Experience preparing HLD/LLD, migration plans, implementation playbooks, test plans, and operational transition documents.
· Excellent customer-facing communication, stakeholder management, and technical presentation skills.
Preferred Skills
· Palo Alto Prisma Access, Netskope, Cisco Umbrella, Microsoft Defender Suite, and Sentinel SIEM exposure.
· Security automation, SOAR integration, Terraform, API-based integrations, and infrastructure-as-code knowledge.
· Experience with manufacturing, healthcare, retail, financial services, energy/utilities, or consumer goods domains.
Job Requirements
· 10+ years of overall Cyber Security experience with architecture and consulting exposure.
· 5+ years of hands-on Zscaler architecture, design, deployment, and optimization experience.
· Experience leading global Zscaler or SASE transformation engagements.
· Strong knowledge of enterprise networking, cloud security, identity, and endpoint security integration.
· Ability to interact with executive stakeholders, customer security leadership, architects, and delivery teams.
· Experience in multi-vendor security environments and managed services transition.
PREFERRED CERTIFICATIONS
Strongly Preferred
Zscaler Certified Architect (ZCA), Zscaler Certified Cloud Administrator (ZCCA)
Preferred
CISSP, CCSP, CISM, AWS Security Specialty, Microsoft Azure Security Engineer Associate, Certified Zero Trust Practitioner
Soft Skills
· Excellent client-facing communication and consulting skills.
· Strong presentation, architecture review, and documentation capabilities.
· Leadership and stakeholder management skills.
· Ability to lead globally distributed teams and coordinate with cross-functional groups.
· Analytical thinking, problem-solving mindset, and ownership-driven delivery approach.10. Responsibilities During Transformation Programs · Assess current-state network security architecture and gaps.
· Develop future-state SASE and Zero Trust architecture.
· Lead ZIA/ZPA migration strategy, design, build, test, and deployment activities.
· Establish governance, operational support model, and transition readiness.
· Drive security modernization initiatives and support audits, compliance reviews, and risk assessments.
· Work closely with OEMs, client stakeholders, and delivery teams on strategic and technical decisions