Apply now »

GMS-Senior-Zero Trust Network Access

Location:  Bengaluru
Other locations:  Primary Location Only
Salary: Competitive
Date:  Oct 1, 2026

Job description

Requisition ID:  1744119

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

Job Description: Senior Zero Trust Network Access (ZTNA) Engineer

Experience Level: 3–5 Years

Role Type: Full-Time

 

Role Overview

We are seeking a Senior Zero Trust Network Access (ZTNA) Engineer to architect, deploy, and manage our modern identity-centric perimeter security solutions. Spanning the complete service delivery lifecycle—Assess, Build, Transition, and Operations—this role is pivotal in replacing legacy VPN architectures with least-privilege, context-aware access controls. The ideal candidate will have hands-on experience integrating ZTNA platforms with enterprise Identity Providers (IdP), enforcing device posture checks, and securing hybrid enterprise applications.

 

Key Responsibilities

Assess (Architecture Review & Posture Analysis)

  • Conduct comprehensive audits of existing remote access models, legacy VPN concentrators, and internal application exposure.
  • Analyze user access patterns, application dependencies, and data flows to map out micro-segmentation and least-privilege policies.
  • Evaluate current Identity Provider (IdP) readiness, multi-factor authentication (MFA) enforcement, and endpoint device posture compliance mechanisms.

Build (Deployment & Policy Engineering)

  • Deploy, configure, and manage enterprise ZTNA solutions (e.g., Zscaler ZPA, Palo Alto Prisma Access, Cloudflare One, or Cisco Secure Access).
  • Design and implement context-aware access policies combining user identity, device health, location, and risk scores.
  • Provision and configure ZTNA connectors (gateways/brokers) across on-premise data centers, AWS, Azure, and GCP environments.
  • Integrate ZTNA platforms with enterprise Single Sign-On (SSO) and Directory Services (e.g., Entra ID/Azure AD, Okta).

Transition (Migration, Testing & Handover)

  • Drive the phased migration roadmap from legacy VPN solutions to ZTNA with minimal disruption to business units.
  • Coordinate User Acceptance Testing (UAT) with business application owners to validate seamless context-based access.
  • Develop "As-Built" architecture diagrams, policy migration runbooks, and troubleshooting guides for support desks.
  • Conduct enablement sessions for IT helpdesks and operations teams on ZTNA client troubleshooting and policy management.

Operations & Continuous Management

  • Serve as the senior escalation point for complex ZTNA connectivity, identity assertion, and connector health issues.
  • Perform continuous policy lifecycle management, reviewing access rules, removing stale policies, and refining posture checks.
  • Monitor ZTNA tunnel performance, broker throughput, and client app stability across global endpoints.
  • Ensure real-time security telemetry and access logs stream successfully into the SIEM for threat hunting and compliance monitoring.
  • Understanding of  ITIL-based Change Management, managing end-to-end change lifecycle activities, CAB coordination, and compliant implementation of infrastructure and application changes

Required Skills & Qualifications

  • Experience: 3–5 years of dedicated experience in network security, identity and access management (IAM), or zero trust architecture implementation.
  • Core Technologies: Hands-on expertise with market-leading ZTNA platforms (e.g., Zscaler Private Access, Palo Alto Prisma Access, Cloudflare One, or Microsoft Global Secure Access).
  • Identity & Networking: Strong grasp of IAM principles, SAML/OIDC authentication protocols, Active Directory/Entra ID, and foundational networking (DNS, TCP/IP, routing, firewalls).
  • Zero Trust Principles: Deep understanding of "Never Trust, Always Verify" paradigms, micro-segmentation, and device posture validation frameworks.
  • Certifications: Relevant vendor or cloud security certifications (e.g., Zscaler Certified Cloud Security Professional, PCNSE, AWS/Azure Security, or CISSP/CCSP) are highly preferred.
  • Soft Skills: Strong cross-functional collaboration skills, ability to manage enterprise-wide change initiatives, and excellent technical documentation capabilities.

 

EY | Building a better working world 


 
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  


 
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  


 
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Apply now »