openleverjobgether
Senior Zscaler Engineer (ZIA/ZPA)
Jobgether
LocationBrazil
EmploymentContract
Posted2026-08-26T17:30:30.351000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:970ec8e6-e351-4f03-9f91-b8b5e0e22e43
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Zscaler Engineer (ZIA/ZPA) based in Brazil. This is a hands-on engineering role focused on designing, deploying, and optimizing Zero Trust security capabilities across enterprise environments. You will take ownership of the technical implementation of Zscaler Internet Access and Zscaler Private Access solutions. The role spans security policy, application access, identity integration, endpoint connectivity, and infrastructure architecture. You will work closely with Security, Network, Identity, and Endpoint teams to build secure and scalable access models. A key focus will be migrating users and applications away from legacy VPN infrastructure toward modern Zero Trust architecture. You will also troubleshoot complex connectivity and access issues while driving technical decisions through to resolution. This opportunity is well suited to an experienced security engineer who enjoys deep technical ownership and enterprise-scale transformation. Design, deploy, configure, and optimize Zscaler Internet Access (ZIA) policies, including URL filtering, SSL inspection, DLP, and cloud application controls. Build and manage Zscaler Private Access (ZPA) application segments, access policies, App Connector architecture, and Private Service Edge deployments. Deploy and maintain App Connectors and Private Service Edges, ensuring appropriate sizing, high availability, and placement across data center and cloud environments. Integrate Zscaler with identity platforms such as Okta using SAML and SCIM, while implementing device posture and Device Assurance requirements. Collaborate with IT Security, Network, Identity, and Endpoint teams to align Zscaler configurations with enterprise access-control and security models. Partner with endpoint teams using Jamf and Intune to package, deploy, and troubleshoot Zscaler Client Connector across Windows and macOS environments. Support BYOD and mobile application management decisions where Zscaler solutions intersect with mobile access requirements. Troubleshoot user, application, and network connectivity issues using ZIA/ZPA diagnostics, log streaming, packet captures, and other technical analysis tools. Lead cutover and migration activities associated with replacing legacy GlobalProtect VPN infrastructure, including pilot deployments, application testing, and rollback planning. Identify security and architecture gaps between the current environment and the target Zero Trust model, and implement appropriate remediation strategies. Produce configuration standards, technical documentation, and compliance materials, including documentation supporting Cyber Essentials Plus requirements. Provide clear technical progress updates, communicate risks and dependencies, and escalate significant blockers to project leadership. Requirements 5+ years of hands-on experience in enterprise network or security engineering, including at least 2 years deploying and operating Zscaler solutions. Deep practical expertise with both Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA), including architecture, policy configuration, connector deployment, and troubleshooting. Experience implementing SSL inspection, including certificate distribution and bypass management, as well as DLP policies and Zero Trust access models. Strong understanding of enterprise networking fundamentals, including DNS, GRE/IPSec tunneling, routing, proxy behavior, TLS, and client connectivity. Experience working with identity providers, preferably Okta, and familiarity with SAML, SCIM provisioning, device posture, and conditional access concepts. Experience with endpoint management technologies such as Jamf and Microsoft Intune across Windows and macOS environments. Strong analytical and troubleshooting abilities, with the capacity to investigate complex security, application, and connectivity issues through to
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.