Apply now »

Security Engineer

Location:  Hoboken
Other locations:  Anywhere in Country
Salary: Competitive
Date:  Sep 9, 2026

Job description

Requisition ID:  1739771

At EY, we’re all in to shape your future with confidence. 

 

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.  Join EY and help to build a better working world.

 

Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organization the size of ours working efficiently and securely. We have more than 400,000 people in over 150 countries, all of whom rely on secure technology to perform their jobs every day. 

 

Everything we use as a firm depends on our security-first mindset. Our users, applications, cloud  platforms, data centers, Al services, and business-critical systems all rely on modern security 
technologies to enable secure access, protect sensitive information, and reduce cyber risk. 

 

Within Security Technology Services, our mission is to deliver world-class security engineering 
capabilities that enable Zero Trust, cloud transformation, attack surface reduction, and secure digital  experiences. lf you are passionate about building and engineering security solutions at global scale, we  want to hear from you. 

 

The Opportunity 

We are looking for a Network Security Engineer - Assistant Director to join Security Technology  Services as a hands-on engineering specialist focused on Zscaler Cloud, Zscaler Private Access (ZPA),  autonomous user-to-application segmentation, least-privilege access, and workload segmentation  across data center and cloud environments. 

 

This role will be responsible for detailed engineering, deployment, configuration, testing,  troubleshooting and optimization of Zscaler-based Zero Trust access and segmentation capabilities. 

 

The successful candidate will operate as a deeply technical, hands-on engineer across Zscaler Cloud,  ZPA, App Connectors, Private Service Edges, Zscaler Client Connector, autonomous user-to-app  segmentation, least-privilege access policies, cloud workload segmentation and data center workload segmentation. 

 

This role will support engineering initiatives focused on: 

  • Zscaler Cloud and ZPA engineering for private application access
  • ZPA autonomous user-to-application segmentation and policy recommendations
  • Least-privilege access design and enforcement for users, groups and applications
  • Data center, VMware and cloud workload segmentation
  • Reduction of lateral movement and public/private application attack surface

 

The role will work closely with the Associate Director, Network Security Technology teams, Cloud  Engineering, Application Security, ldentity, lnfrastructure and Architecture teams to deploy scalable enterprise Zero Trust segmentation solutions globally. 

 

Your Key Responsibilities 

The Network Security Engineer - Assistant Director will provide hands-on engineering support for the  deployment, integration, optimization and continuous improvement of Zscaler Cloud, ZPA and workload segmentation capabilities. 

 

Zscaler Cloud and ZPA Engineering 

  • Deploy, configure and troubleshoot Zscaler Cloud and ZPA components including App 
  • Connectors, Private Service Edges, application segments, access policies and connector groups. 
  • lmplement ZPA access models that provide application-level access without extending broad network access to users. 
  • Support onboarding of internal applications, developer services, administrative tools and business workloads into ZPA. 
  • Validate routing, DNS, TLS, SAML, SClM, identity provider and device posture integrations required for successful ZPA deployments. 
  • Maintain engineering documentation, implementation standards, test evidence and operational handover materials. 

 

Azure Secure Networking Integration 

  • Bring deep working knowledge of Azure secure networking patterns to support Zscaler integration across EY Azure environments. 
  • Understand, validate and troubleshoot Azure networking components including Virtual WAN, 
  • ExpressRoute, Azure Firewall, Application Gateway, Front Door, Private Link and Private Endpoint. 
  • Work with EY Azure architects to integrate Zscaler capabilities with Azure-hosted applications, workloads, Al platforms and infrastructure services. 
  • Translate Azure secure networking requirements into Zscaler engineering patterns, connectivity models and deployment standards. 
  • Partner closely with EY Azure architecture and cloud engineering teams to drive secure Zscaler product integration across Azure environments. 

 

ZPA Autonomous Segmentation and Least-Privilege Access 

  • lmplement ZPA autonomous user-to-application segmentation using discovery data, traffic analysis and policy recommendations. 
  • Use ZPA Policy lnsights, application discovery outputs and segmentation recommendations to validate user-to-application access patterns. 
  • Create granular application segments and access policies aligned to least-privilege principles for users, groups, vendors, contractors and administrators. 
  • Review application-to-user relationships, validate access requirements and remove over-permissive access patterns. 
  • Support migration from VPN and broad network access models to precise ZPA application access policies. 
  • Use ZPA dashboards, logs and diagnostics to monitor segmentation effectiveness and continuously improve policy quality. 

 

Workload Segmentation Engineering 

  • Engineer workload segmentation solutions across Azure, data center and hybrid environments. 
  • Deploy and support Zscaler workload and microsegmentation capabilities for workload-to-workload and application-to-application controls. 
  • Define and validate segmentation policies for production, non-production, shared services, management networks and privileged access paths. 
  • Analyze east-west traffic flows and support policy creation to reduce lateral movement risk. 
  • Develop and execute segmentation test plans, validation steps and rollback considerations before production rollout. 
  • Troubleshoot enforcement, connector, routing, certificate, agent and policy issues during segmentation rollout. 

 

Data Center and VMware Security Engineering 

  • Deploy Zscaler App Connectors, Private Service Edges and related components in VMware-based data center environments. 
  • Support secure access and segmentation for applications hosted in traditional data centers and private cloud platforms. 
  • Validate connectivity between on-premises applications, Zscaler services, identity platforms and Azure-hosted workloads. 
  • Assist with migration of legacy applications from network-level access to application-level Zero Trust access. 
  • Work with infrastructure and application teams to test segmentation policies before production rollout. 

 

Engineering Automation and Platform Optimization 

  • Build and maintain automation solutions to improve security engineering efficiency.
  • Automate deployment, configuration validation and policy management activities.
  • Utilize Terraform, Python, PowerShell, APls and lnfrastructure-as-Code approaches.
  • lmprove platform scalability, consistency and operational effectiveness through automation.
  • Contribute engineering inputs, deployment feedback and technical validation to future-state security engineering plans.

 

Engineering Execution and Collaboration

  • Work under the direction of the Associate Director to implement approved engineering patterns and deployment standards. 
  • Act as a senior hands-on escalation point for Zscaler, ZPA, segmentation, DNS, TLS, routing and authentication issues. 
  • Collaborate with cloud, data center, identity, application and infrastructure teams during design validation, pilot and production rollout. 
  • Provide technical guidance to engineers and support teams involved in onboarding applications and workloads. 
  • Communicate implementation risks, dependencies and progress clearly to the Associate Director and project stakeholders. 

 

Skills and Attributes for Success 

We are interested in candidates who bring deep engineering experience from large global enterprise  environments and can combine hands-on technical execution with strong implementation discipline. 

  • As a successful candidate, you will demonstrate: 
  • Strong hands-on engineering expertise across network security, cloud security and Zero Trust technologies. 
  • Deep troubleshooting and problem-solving capabilities. 
  • Ability to engineer, deploy and validate security solutions at enterprise scale in partnership with platform architecture teams. 
  • Strong understanding of Azure secure networking, hybrid connectivity and cloud security integration patterns. 
  • Experience working across global teams and multiple technology disciplines.
  • Strong technical communication skills with the ability to explain implementation risks,
  • dependencies and engineering decisions clearly.
  • Passion for automation, innovation and continuous improvement.
  • Ability to operate effectively in fast-paced and highly complex environments.

 

To Qualify for the Role, You Must Have

  • Bachelor's degree in Computer Science, lnformation Technology, Engineering or equivalent experience. 
  • 10-15 years of experience in network security, cloud security or security engineering.
  • 8-12 years of hands-on experience deploying, configuring or supporting Zscaler technologies.
  • Strong hands-on experience with Zscaler Private Access, application segments, App Connectors,
  • Private Service Edges and access policies. 
  • Experience implementing least-privilege access models and user-to-application segmentation using ZPA. 
  • Experience supporting workload segmentation or microsegmentation across cloud, data center or hybrid environments. 
  • Working knowledge of Azure networking, including VNets, routing, Private Link, Private 
  • Endpoint, ExpressRoute, Azure Firewall and Application Gateway. 
  • Experience deploying security solutions in VMware-based data center environments. 
  • Strong understanding of TCP/lP, DNS, TLS, routing, PKl, identity federation and enterprise networking concepts. 
  • Experience troubleshooting complex connectivity, authentication, policy enforcement and application access issues. 
  • Experience with automation or scripting using Python, PowerShell, Terraform, APls or similar tools. 
  • Strong English communication skills, both written and verbal. 

 

Ideally, You'll Also Have 

  • Hands-on experience with ZPA autonomous user-to-app segmentation, ZPA Policy lnsights, Al-
  • generated policy recommendations or application discovery workflows. 
  • Experience with Zscaler workload communications, workload segmentation or microsegmentation products. 
  • Experience designing, testing or validating workload-to-workload access control policies.
  • Experience reducing lateral movement risk and public/private application attack surface through Zero Trust access models.
  • Experience securing Azure laaS, PaaS, AKS and hybrid application environments.
  • Experience integrating Zscaler with Microsoft Entra lD, Conditional Access, SClM, SAML and endpoint posture signals.
  • Strong understanding of SASE, SSE, ZTNA and Zero Trust segmentation architecture.
  • Zscaler certifications focused on ZPA, ZlA, Client Connector, Private Service Edge, workload segmentation or equivalent hands-on credentials.
  • Azure Network Engineer Associate or Azure Security Engineer certification.
  • ClSSP, CCSP, CCNP Security or equivalent certifications.

 

What We Look For 

We are looking for a highly technical, hands-on Network Security Engineer who can execute complex  Zscaler Cloud, ZPA and segmentation deployments while working under the direction of the Associate  Director. 

 

The ideal candidate has successfully deployed ZPA least-privilege access, autonomous user-to- application segmentation, App Connectors, Private Service Edges, and workload segmentation patterns across Azure, enterprise data centers and VMware-based infrastructure.  

 

What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business.  The base salary range for this job in all geographic locations in the US is $131,900 to $246,600.  The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $158,200 to $280,200.  Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography.  In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

 

Are you ready to shape your future with confidence? Apply today. 
EY accepts applications for this position on an on-going basis.  

 

For those living in California, please click here for additional information.

 

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

 

EY  |  Building a better working world

 

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

 

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

 

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

 

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.  

 

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process,  please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com.


Nearest Major Market: New York City
Nearest Secondary Market: Newark

Apply now »