Apply now »

Zscaler Network Security Engineer

Location:  Bengaluru
Other locations:  Primary Location Only
Salary: Competitive
Date:  Sep 4, 2026

Job description

Requisition ID:  1739753

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

Security Technology Services – Network Security Technology

 

Senior Associate – Network Security Engineer | India

 

EY Technology

Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organizaƟon the size of ours working efficiently and securely. We have more than 400,000 people in over 150 countries, all of whom rely on secure technology to perform their jobs every day.

Everything we use as a firm depends on our security-first mindset. Our users, applicaƟons, cloud plaƞorms, data centers, AI services, and business-criƟcal systems all rely on modern security technologies to enable secure access, protect sensiƟve informaƟon, and reduce cyber risk.

Within Security Technology Services, our mission is to deliver world-class security engineering capabiliƟes that enable Zero Trust, cloud transformaƟon, aƩack surface reducƟon, and secure digital experiences. If you are passionate about building and engineering security soluƟons at global scale, we want to hear from you.

 

The Opportunity

We are looking for a Senior Associate – Network Security Engineer to join Security Technology Services as a hands-on engineering specialist focused on Zscaler Private Access, Zero Trust Network Access, private applicaƟon onboarding, App Connectors, Private Service Edges, Client Connector integraƟon, and least-privilege user-to-applicaƟon access.

This role will report to the Assistant Director and will be responsible for detailed engineering, deployment, configuraƟon, tesƟng, troubleshooƟng, opƟmizaƟon and operaƟonal transiƟon of ZPA services used to securely connect users, devices and applicaƟons without exposing private applicaƟons to the internet.

The successful candidate must be able to explain and demonstrate hands-on experience across ZPA applicaƟon segments, segment groups, server groups, App Connector groups, Private Service Edge deployments, authenƟcaƟon and idenƟty integraƟons, DNS, rouƟng, TLS, SAML, SCIM, device posture, Client Connector behavior, live logs, diagnosƟcs, and end-to-end traffic flow troubleshooƟng.

 

This role will support engineering iniƟaƟves focused on:

  • Zscaler Private Access engineering for secure private applicaƟon access Design and implementaƟon of granular ZPA applicaƟon segments, segment groups and access policies  
  • Deployment and support of App Connectors, Private Service Edges and connector groups across cloud and data center environments
  • Least-privilege user-to-applicaƟon access and migraƟon from VPN-style network access to applicaƟon-level access
  • ZPA diagnosƟcs, policy validaƟon, operaƟonal readiness and producƟon troubleshooƟng

The role will work closely with Network Security Technology, Cloud Engineering, IdenƟty, Endpoint, Infrastructure, ApplicaƟon and Architecture teams to deploy scalable ZPA capabiliƟes across global enterprise environments.

 

Your Key ResponsibiliƟes

The Senior Associate – Network Security Engineer, Zscaler/ZPA will work under the direcƟon of the Assistant Director and provide hands-on engineering support for ZPA deployment, integraƟon, opƟmizaƟon, troubleshooƟng and conƟnuous improvement.

Zscaler Private Access Engineering

  • Build, configure and troubleshoot ZPA constructs including applicaƟon segments, segment groups, server groups, servers, access policies, connector groups, App Connectors and Private Service Edges.
  • Translate applicaƟon details such as FQDNs, IPs, TCP/UDP ports, protocols, users, groups and source condiƟons into secure ZPA applicaƟon access policies.
  • Validate end-to-end traffic flows from Client Connector to ZPA Service Edge or Private Service Edge, App Connector, server group and target applicaƟon.
  • Support onboarding of internal applicaƟons, administrator services, developer plaƞorms, privileged access services and business workloads into ZPA.
  • Validate DNS, rouƟng, TLS, IdP, SAML, SCIM, device posture, Client Connector and authenƟcaƟon integraƟons required for successful ZPA deployments.
  • Produce low-level implementaƟon steps, test evidence, troubleshooƟng notes, rollback consideraƟons and operaƟonal handover material.

App Connector and Private Service Edge Deployment

  • Deploy and support App Connectors and Private Service Edges across Azure, VMware and data center environments.
  • Design connector placement, connector groups, resiliency, capacity, plaƞorm sizing and outbound connecƟvity requirements.
  • Troubleshoot connector health, registraƟon, provisioning keys, soŌware updates, service edge connecƟvity and tunnel establishment issues.
  • Validate required outbound connecƟvity, DNS resoluƟon, cerƟficate handling, NTP, firewall allowlists and rouƟng paths for ZPA components.  
  • Work with infrastructure teams to ensure high availability, service resilience and operaƟ supportability for producƟon ZPA deploymentsonal

Least-Privilege Access and ApplicaƟon SegmentaƟon

  • Create granular applicaƟon segments and access policies aligned to least-privilege principles for employees, administrators, vendors, service accounts and support groups.
  • Use ZPA applicaƟon discovery, policy insights, access logs and diagnosƟcs to validate user- toapplicaƟon access paƩerns.
  • Review exisƟng access models, idenƟfy over-permissive access and support migraƟon from VPN or network-level access to ZPA applicaƟon-level access.
  • Partner with applicaƟon, idenƟty and infrastructure teams to confirm business access requirements before policy enforcement.
  • ConƟnuously improve policy quality using logs, dashboards, diagnosƟcs, access review outputs and producƟon support findings.

ZPA TroubleshooƟng, DiagnosƟcs and OperaƟons

  • Troubleshoot ZPA issues using a structured approach across endpoint, Client Connector, idenƟty provider, ZPA policy, Service Edge, App Connector, DNS, rouƟng, firewall and target applicaƟon layers.
  • Use ZPA live logs, user acƟvity diagnosƟcs, user status diagnosƟcs, applicaƟon diagnosƟcs, connector status, Private Service Edge status, service edge health and audit logs to idenƟfy root cause.
  • Diagnose common scenarios including policy mismatch, unauthenƟcated users, failed SAML claims, missing SCIM groups, connector offline state, DNS resoluƟon failure, cerƟficate errors, port mismatch, asymmetric rouƟng and applicaƟon unavailability.
  • Develop structured test plans for applicaƟon onboarding, policy changes, connector changes, Private Service Edge rollout and producƟon migraƟon waves.
  • Document known issues, operaƟonal procedures, support steps, log locaƟons, escalaƟon evidence and rollback consideraƟons for producƟon deployments.
  • Drive conƟnuous plaƞorm improvement through problem management, automaƟon opportuniƟes and implementaƟon lessons learned.

Engineering AutomaƟon and Plaƞorm OpƟmizaƟon

  • Build and maintain automaƟon soluƟons to improve security engineering efficiency.
  • Automate deployment, configuraƟon validaƟon and policy management acƟviƟes.
  • UƟlize Terraform, Python, PowerShell, APIs and Infrastructure-as-Code approaches.
  • Improve plaƞorm scalability, consistency and operaƟonal effecƟveness through automaƟon. •
  • Contribute engineering inputs, deployment feedback and technical validaƟon to future-state security engineering plans.  

Engineering ExecuƟon and CollaboraƟon

  • Work under the direcƟon of the Assistant Director to implement approved ZPA engineering paƩerns and deployment standards.
  • Act as a hands-on escalaƟon point for Zscaler, ZPA, DNS, TLS, rouƟng, Client Connector and authenƟcaƟon issues.
  • Collaborate with cloud, data center, idenƟty, applicaƟon and infrastructure teams during design validaƟon, pilot and producƟon rollout.
  • Provide technical guidance to engineers and support teams involved in onboarding applicaƟons and workloads.
  • Communicate implementaƟon risks, dependencies and progress clearly to the Assistant Director and project stakeholders.

 

Technical Interview Focus Areas

Candidates should be prepared to discuss real implementaƟ troubleshooƟng on examples and demonstrate pracƟcal depth in the following areas:

  • Explain the ZPA connecƟon flow from user device and Client Connector to Service Edge or Private Service Edge, App Connector and target private applicaƟon.
  • Design an applicaƟon segment for a private web applicaƟon, SSH service, RDP service or administrator portal using FQDNs, ports, server groups, connector groups and access policy rules.
  • Troubleshoot a user who is authenƟcated but unable to access one ZPA applicaƟon while other applicaƟons work successfully.
  • Troubleshoot an App Connector or Private Service Edge that is registered but unhealthy, disconnected or unable to reach the target applicaƟon.
  • Explain how SAML aƩributes, SCIM groups, idenƟty provider claims, device posture and condiƟonal access inputs influence ZPA access policy decisions.
  • Describe DNS resoluƟon requirements for ZPA, including internal DNS dependencies, splithorizon DNS paƩerns and Browser Access consideraƟons.
  • Explain connector placement and resiliency strategy for Azure, VMware and data center environments.
  • Interpret ZPA logs and diagnosƟcs to idenƟfy whether a failure is caused by policy, idenƟty, connector, rouƟng, DNS, TLS, endpoint or target applicaƟon issues.
  • Explain how to migrate an applicaƟon from VPN-based network access to ZPA applicaƟon-level access with tesƟng, rollback and operaƟonal readiness steps.
  • Discuss automaƟon opportuniƟes using APIs, Terraform, Python or PowerShell for repeatable
  • ZPA configuraƟon, validaƟon and reporƟng.

 

Skills and AƩributes for Success 

We are interested in candidates who bring deep hands-on ZPA engineering experience from large global enterprise environments and can combine technical execuƟon with strong implementaƟon discipline.

As a successful candidate, you will demonstrate:

  • Strong hands-on engineering experƟse in Zscaler Private Access and Zero Trust Network Access. Deep troubleshooƟng capability across DNS, rouƟng, TLS, SAML, SCIM, device posture, Client Connector, App Connectors and Private Service Edges.
  • Ability to deploy and validate ZPA soluƟons at enterprise scale in partnership with plaƞorm architecture and operaƟons teams.
  • Strong understanding of Azure and data center networking paƩerns relevant to ZPA deployment.
  • Experience working across global teams and mulƟple technology disciplines.
  • Strong technical communicaƟon skills with the ability to explain implementaƟon risks, dependencies and engineering decisions clearly.
  • Passion for automaƟon, repeatable engineering standards and conƟnuous improvement. Ability to operate effecƟvely in fast-paced and highly complex enterprise environments.

 

To Qualify for the Role, You Must Have

  • Bachelor’s degree in Computer Science, InformaƟon Technology, Engineering or equivalent experience.
  • 4-7 years of hands-on experience in network security, cloud security, infrastructure security or security engineering.
  • 3-5 years of pracƟcal Zscaler experience, including hands-on ZPA deployment, configuraƟon, troubleshooƟng or operaƟons.
  • Strong working knowledge of ZPA applicaƟon segments, segment groups, server groups, access policies, App Connectors, connector groups, provisioning keys and Private Service Edges.
  • Ability to troubleshoot live ZPA issues using logs, diagnosƟcs, packet-level reasoning, DNS checks, rouƟng validaƟon, TLS/cerƟficate checks and endpoint-side observaƟons.
  • Experience integraƟng ZPA with MicrosoŌ Entra ID or equivalent idenƟty providers using SAML, SCIM, user groups, device posture and condiƟonal access signals.
  • Working knowledge of Azure networking and hybrid connecƟvity, including VNets, subnets, rouƟng, Private Link, Private Endpoint, ExpressRoute, Azure Firewall and ApplicaƟon Gateway.
  • Experience deploying or supporƟng ZPA components in VMware-based data center environments and Azure cloud environments.
  • Strong understanding of TCP/IP, DNS, TLS, PKI, rouƟng, proxy concepts, idenƟty federaƟon, firewall policy and enterprise networking fundamentals.
  • Experience with automaƟon or scripƟng using Python, PowerShell, Terraform, APIs or similar tools is preferred.
  • Strong English communicaƟon skills with the ability to explain troubleshooƟng logic, root cause and implementaƟon decisions clearly.  

 

Ideally, You’ll Also Have

  • Hands-on experience with ZPA autonomous user-to-app segmentaƟon, policy insights, applicaƟon discovery workflows or AI-generated policy recommendaƟons.
  • Experience with ZPA Private Service Edge reference architectures and deployments for onpremises and cloud-hosted private applicaƟons.
  • Experience migraƟng users and applicaƟons from VPN or legacy remote access to ZPA-based applicaƟon access.
  • Experience securing Azure-hosted private applicaƟons, administrator interfaces, developer services and internal plaƞorms through ZPA.
  • Experience integraƟng ZPA with MicrosoŌ Entra ID, CondiƟonal Access, SCIM, SAML and endpoint posture signals.
  • Strong understanding of SASE, SSE, ZTNA, Zero Trust segmentaƟon and private applicaƟon protecƟon paƩerns.
  • Zscaler cerƟficaƟons focused on ZPA, Client Connector, Private Service Edge or equivalent hands-on credenƟals.
  • Azure Network Engineer Associate or Azure Security Engineer cerƟficaƟon.
  • CISSP, CCSP, CCNP Security or equivalent cerƟficaƟons.

 

What We Look For

  • We are looking for a highly technical, hands-on Zscaler/ZPA engineer who can execute complex private access deployments, solve implementaƟon issues and support reliable producƟon adopƟon of ZPA across global enterprise environments.
  • The ideal candidate has successfully deployed ZPA least-privilege access, applicaƟon segments, App Connectors, Private Service Edges, Client Connector integraƟons and idenƟty-based access controls across Azure, enterprise data centers and VMware-based infrastructure.  

 

What working at EY offers

At EY, we offer a compeƟƟve remuneraƟon package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working, career development and benefits that support your personal and professional prioriƟes.

Plus, we offer:

  • Support, coaching and feedback from engaging colleagues.
  • OpportuniƟes to develop new skills and progress your career.
  • Exposure to large-scale global technology and cybersecurity transformaƟon programs. The freedom and flexibility to handle your role in a way that’s right for you.

 

EY | Building a better working world 


 
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  


 
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  


 
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Apply now »