Serve as a Senior Network Engineer enabling the Department of Homeland Security (DHS) mission and enterprise network infrastructure. The applicant will serve as the primary technical authority for designing, deploying, administering, upgrading and optimizing enterprise-wide Secure Access Service Edge (SASE) solutions using the Zscaler cloud security platform. This role leads the operational architecture across Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zscaler Digital Experience (ZDX), driving modern Zero Trust initiatives
Required Skills
- The Senior network engineer will be the technical lead performing the following:
Architecture & Engineering: Design, implement, and maintain enterprise Zscaler deployments (ZIA, ZPA, ZDX, and Zscaler Client Connector) across multi-cloud and hybrid corporate environments.
- Policy & Governance: Create, audit, and tune security policies, including URL filtering, Cloud Application Control, SSL/TLS deep packet inspection, Data Loss Prevention (DLP), and sandbox policies.
- Zero Trust Deployment: Formulate and execute access policies within ZPA to enable least-privilege direct access to internal applications in private clouds (AWS, Azure, GCP) and on-premises data centers without traditional VPN overhead.
- Operational Troubleshooting: Serve as Tier-3/Tier-4 escalation support for complex proxy routing, PAC (Proxy Auto-Configuration) file debugging, identity integration, authentication drops, and application latency issues.
- Agent Lifecycle Management: Manage enterprise distribution, health checks, profile tuning, and version upgrades of Zscaler Client Connector (ZCC) across macOS, Windows, iOS, and Android platforms.
- Observability & Analytics: Leverage ZDX and cloud analytics to isolate user experience degradation across endpoint, network ISP, and application levels; configure automated alerting and SIEM log integration (Splunk, Cribl).
- Cross-Functional Integration: Partner with Identity and Access Management (IAM) teams to configure SAML/SCIM attributes with IdPs such as Okta, Microsoft Entra ID (Azure AD), or Ping Identity.
- Troubleshooting & Incident Management: Provide Tier 2/Tier 3 escalation support for network outages, circuit degradations, and performance issues; conduct root cause analyses (RCA) and coordinate vendor support.
- Documentation & Asset Management: Maintain accurate network diagrams (Visio), topology maps, inventory databases, standard operating procedures (SOPs), and change control tickets (ServiceNow/Remedy).
- Support On-Call & Escalation Management: support 24/7/365 on-call rotation readiness to respond to Tier 3 critical network incidents within SLA limits and coordinating cross-functional escalation pathways. When needed to restore services, the Senior Network Engineer will provide a solution and implement an Emergency Change Request (ECR), Emergency Break Fix (EBF), or Change Request.
- Root Cause Analysis (RCA) or Post Incident Reporting: Participate in the Root Cause Analysis (RCA) or post incident analysis of problems for mission critical applications, mission essential applications, and mission essential network infrastructure as well as recurring issues on the enterprise IT infrastructure.
- Project Support: Partner with program and project managers to align network engineering deliverables, milestone schedules, and resource planning with enterprise project objectives.
- Excellent problem-solving and analytical skills, with the ability to troubleshoot complex network issues.
- Scheduled and Adhoc Travel: Ability to travel within the United States either on short notice or scheduled, up to 20% of the time.
Preferred Skills
- The Senior network engineer will be the technical lead performing the following:
Architecture & Engineering: Design, implement, and maintain enterprise Zscaler deployments (ZIA, ZPA, ZDX, and Zscaler Client Connector) across multi-cloud and hybrid corporate environments.
- Policy & Governance: Create, audit, and tune security policies, including URL filtering, Cloud Application Control, SSL/TLS deep packet inspection, Data Loss Prevention (DLP), and sandbox policies.
- Zero Trust Deployment: Formulate and execute access policies within ZPA to enable least-privilege direct access to internal applications in private clouds (AWS, Azure, GCP) and on-premises data centers without traditional VPN overhead.
- Operational Troubleshooting: Serve as Tier-3/Tier-4 escalation support for complex proxy routing, PAC (Proxy Auto-Configuration) file debugging, identity integration, authentication drops, and application latency issues.
- Agent Lifecycle Management: Manage enterprise distribution, health checks, profile tuning, and version upgrades of Zscaler Client Connector (ZCC) across macOS, Windows, iOS, and Android platforms.
- Observability & Analytics: Leverage ZDX and cloud analytics to isolate user experience degradation across endpoint, network ISP, and application levels; configure automated alerting and SIEM log integration (Splunk, Cribl).
- Cross-Functional Integration: Partner with Identity and Access Management (IAM) teams to configure SAML/SCIM attributes with IdPs such as Okta, Microsoft Entra ID (Azure AD), or Ping Identity.
- Troubleshooting & Incident Management: Provide Tier 2/Tier 3 escalation support for network outages, circuit degradations, and performance issues; conduct root cause analyses (RCA) and coordinate vendor support.
- Documentation & Asset Management: Maintain accurate network diagrams (Visio), topology maps, inventory databases, standard operating procedures (SOPs), and change control tickets (ServiceNow/Remedy).
- Support On-Call & Escalation Management: support 24/7/365 on-call rotation readiness to respond to Tier 3 critical network incidents within SLA limits and coordinating cross-functional escalation pathways. When needed to restore services, the Senior Network Engineer will provide a solution and implement an Emergency Change Request (ECR), Emergency Break Fix (EBF), or Change Request.
- Root Cause Analysis (RCA) or Post Incident Reporting: Participate in the Root Cause Analysis (RCA) or post incident analysis of problems for mission critical applications, mission essential applications, and mission essential network infrastructure as well as recurring issues on the enterprise IT infrastructure.
- Project Support: Partner with program and project managers to align network engineering deliverables, milestone schedules, and resource planning with enterprise project objectives.
- Excellent problem-solving and analytical skills, with the ability to troubleshoot complex network issues.
- Scheduled and Adhoc Travel: Ability to travel within the United States either on short notice or scheduled, up to 20% of the time.

