{"id":1776279,"url":"https://alion.io/job/ernst-young-zscaler-network-security-engineer","title":"Zscaler Network Security Engineer","company":{"id":2859,"name":"Ernst & Young","domain":"ey.com","url":"https://alion.io/company/ey-com","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":21000,"max_usd":47000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":9},"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Azure","optional":false},{"name":"DNS","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"PKI","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"TCP/IP","optional":false},{"name":"Terraform","optional":false},{"name":"VMWare","optional":false},{"name":"VPN","optional":false},{"name":"Zero Trust","optional":false},{"name":"Zscaler","optional":false}],"status":"live","first_seen_at":"2026-10-03T02:00:00Z","employer_posted_date":"2026-10-03","last_verified_at":"2026-10-11T01:38:51Z","board_verified":true,"closed_at":null,"days_open":8,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":8},"description":"At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.\nSecurity Technology Services - Network Security Technology\nSenior Associate - Network Security Engineer | India\nEY Technology\nTechnology has always been at the heart of what we do and deliver at EY. We need technology to keep an organizaƟon the size of ours working eﬃciently and securely. We have more than 400,000 people in over 150 countries, all of whom rely on secure technology to perform their jobs every day.\nEverything we use as a ﬁrm depends on our security-ﬁrst mindset. Our users, applicaƟons, cloud plaƞorms, data centers, AI services, and business-criƟcal systems all rely on modern security technologies to enable secure access, protect sensiƟve informaƟon, and reduce cyber risk.\nWithin Security Technology Services, our mission is to deliver world-class security engineering capabiliƟes that enable Zero Trust, cloud transformaƟon, aƩack surface reducƟon, and secure digital experiences. If you are passionate about building and engineering security soluƟons at global scale, we want to hear from you.\nThe Opportunity\nWe are looking for a Senior Associate - Network Security Engineer to join Security Technology Services as a hands-on engineering specialist focused on Zscaler Private Access, Zero Trust Network Access, private applicaƟon onboarding, App Connectors, Private Service Edges, Client Connector integraƟon, and least-privilege user-to-applicaƟon access.\nThis role will report to the Assistant Director and will be responsible for detailed engineering, deployment, conﬁguraƟon, tesƟng, troubleshooƟng, opƟmizaƟon and operaƟonal transiƟon of ZPA services used to securely connect users, devices and applicaƟons without exposing private applicaƟons to the internet.\nThe successful candidate must be able to explain and demonstrate hands-on experience across ZPA applicaƟon segments, segment groups, server groups, App Connector groups, Private Service Edge deployments, authenƟcaƟon and idenƟty integraƟons, DNS, rouƟng, TLS, SAML, SCIM, device posture, Client Connector behavior, live logs, diagnosƟcs, and end-to-end traﬃc ﬂow troubleshooƟng.\nThis role will support engineering iniƟaƟves focused on:\nZscaler Private Access engineering for secure private applicaƟon access Design and implementaƟon of granular ZPA applicaƟon segments, segment groups and access policies \nDeployment and support of App Connectors, Private Service Edges and connector groups across cloud and data center environments\nLeast-privilege user-to-applicaƟon access and migraƟon from VPN-style network access to applicaƟon-level access\nZPA diagnosƟcs, policy validaƟon, operaƟonal readiness and producƟon troubleshooƟng\nThe role will work closely with Network Security Technology, Cloud Engineering, IdenƟty, Endpoint, Infrastructure, ApplicaƟon and Architecture teams to deploy scalable ZPA capabiliƟes across global enterprise environments.\nYour Key ResponsibiliƟes\nThe Senior Associate - Network Security Engineer, Zscaler/ZPA will work under the direcƟon of the Assistant Director and provide hands-on engineering support for ZPA deployment, integraƟon, opƟmizaƟon, troubleshooƟng and conƟnuous improvement.\nZscaler Private Access Engineering\nBuild, conﬁgure and troubleshoot ZPA constructs including applicaƟon segments, segment groups, server groups, servers, access policies, connector groups, App Connectors and Private Service Edges.\nTranslate applicaƟon details such as FQDNs, IPs, TCP/UDP ports, protocols, users, groups and source condiƟons into secure ZPA applicaƟon access policies.\nValidate end-to-end traﬃc ﬂows from Client Connector to ZPA Service Edge or Private Service Edge, App Connector, server group and target applicaƟon.\nSupport onboarding of internal applicaƟons, administrator services, developer plaƞorms, privileged access services and business workloads into ZPA.\nValidate DNS, rouƟng, TLS, IdP, SAML, SCIM, device posture, Client Connector and authenƟcaƟon integraƟons required for successful ZPA deployments.\nProduce low-level implementaƟon steps, test evidence, troubleshooƟng notes, rollback consideraƟons and operaƟonal handover material.\nApp Connector and Private Service Edge Deployment\nDeploy and support App Connectors and Private Service Edges across Azure, VMware and data center environments.\nDesign connector placement, connector groups, resiliency, capacity, plaƞorm sizing and outbound connecƟvity requirements.\nTroubleshoot connector health, registraƟon, provisioning keys, soŌware updates, service edge connecƟvity and tunnel establishment issues.\nValidate required outbound connecƟvity, DNS resoluƟon, cerƟﬁcate handling, NTP, ﬁrewall allowlists and rouƟng paths for ZPA components. \nWork with infrastructure teams to ensure high availability, service resilience and operaƟ supportability for producƟon ZPA deploymentsonal\nLeast-Privilege Access and ApplicaƟon SegmentaƟon\nCreate granular applicaƟon segments and access policies aligned to least-privilege principles for employees, administrators, vendors, service accounts and support groups.\nUse ZPA applicaƟon discovery, policy insights, access logs and diagnosƟcs to validate user- toapplicaƟon access paƩerns.\nReview exisƟng access models, idenƟfy over-permissive access and support migraƟon from VPN or network-level access to ZPA applicaƟon-level access.\nPartner with applicaƟon, idenƟty and infrastructure teams to conﬁrm business access requirements before policy enforcement.\nConƟnuously improve policy quality using logs, dashboards, diagnosƟcs, access review outputs and producƟon support ﬁndings.\nZPA TroubleshooƟng, DiagnosƟcs and OperaƟons\nTroubleshoot ZPA issues using a structured approach across endpoint, Client Connector, idenƟty provider, ZPA policy, Service Edge, App Connector, DNS, rouƟng, ﬁrewall and target applicaƟon layers.\nUse ZPA live logs, user acƟvity diagnosƟcs, user status diagnosƟcs, applicaƟon diagnosƟcs, connector status, Private Service Edge status, service edge health and audit logs to idenƟfy root cause.\nDiagnose common scenarios including policy mismatch, unauthenƟcated users, failed SAML claims, missing SCIM groups, connector oﬄine state, DNS resoluƟon failure, cerƟﬁcate errors, port mismatch, asymmetric rouƟng and applicaƟon unavailability.\nDevelop structured test plans for applicaƟon onboarding, policy changes, connector changes, Private Service Edge rollout and producƟon migraƟon waves.\nDocument known issues, operaƟonal procedures, support steps, log locaƟons, escalaƟon evidence and rollback consideraƟons for producƟon deployments.\nDrive conƟnuous plaƞorm improvement through problem management, automaƟon opportuniƟes and implementaƟon lessons learned.\nEngineering AutomaƟon and Plaƞorm OpƟmizaƟon\nBuild and maintain automaƟon soluƟons to improve security engineering eﬃciency.\nAutomate deployment, conﬁguraƟon validaƟon and policy management acƟviƟes.\nUƟlize Terraform, Python, PowerShell, APIs and Infrastructure-as-Code approaches.\nImprove plaƞorm scalability, consistency and operaƟonal eﬀecƟveness through automaƟon. •\nContribute engineering inputs, deployment feedback and technical validaƟon to future-state security engineering plans. \nEngineering ExecuƟon and CollaboraƟon\nWork under the direcƟon of the Assistant Director to implement approved ZPA engineering paƩerns and deployment standards.\nAct as a hands-on escalaƟon point for Zscaler, ZPA, DNS, TLS, rouƟng, Client Connector and authenƟcaƟon issues.\nCollaborate with cloud, data center, idenƟty, applicaƟon and infrastructure teams during design validaƟon, pilot and producƟon rollout.\nProvide technical guidance to engineers and support teams involved in onboarding applicaƟons and workloads.\nCommunicate implementaƟon risks, dependencies and progress clearly to the Assistant Director and project stakeholders.\nTechnical Interview Focus Areas\nCandidates should be prepared to discuss real implementaƟ troubleshooƟng on examples and demonstrate pracƟcal depth in the following areas:\nExplain the ZPA connecƟon ﬂow from user device and Client Connector to Service Edge or Private Service Edge, App Connector and target private applicaƟon.\nDesign an applicaƟon segment for a private web applicaƟon, SSH service, RDP service or administrator portal using FQDNs, ports, server groups, connector groups and access policy rules.\nTroubleshoot a user who is authenƟcated but unable to access one ZPA applicaƟon while other applicaƟons work successfully.\nTroubleshoot an App Connector or Private Service Edge that is registered but unhealthy, disconnected or unable to reach the target applicaƟon.\nExplain how SAML aƩributes, SCIM groups, idenƟty provider claims, device posture and condiƟonal access inputs inﬂuence ZPA access policy decisions.\nDescribe DNS resoluƟon requirements for ZPA, including internal DNS dependencies, splithorizon DNS paƩerns and Browser Access consideraƟons.\nExplain connector placement and resiliency strategy for Azure, VMware and data center environments.\nInterpret ZPA logs and diagnosƟcs to idenƟfy whether a failure is caused by policy, idenƟty, connector, rouƟng, DNS, TLS, endpoint or target applicaƟon issues.\nExplain how to migrate an applicaƟon from VPN-based network access to ZPA applicaƟon-level access with tesƟng, rollback and operaƟonal readiness steps.\nDiscuss automaƟon opportuniƟes using APIs, Terraform, Python or PowerShell for repeatable\nZPA conﬁguraƟon, validaƟon and reporƟng.\nSkills and AƩributes for Success\nWe are interested in candidates who bring deep hands-on ZPA engineering experience from large global enterprise environments and can combine technical execuƟon with strong implementaƟon discipline.\nAs a successful candidate, you will demonstrate:\nStrong hands-on engineering experƟse in Zscaler Private Access and Zero Trust Network Access. Deep troubleshooƟng capability across DNS, rouƟng, TLS, SAML, SCIM, device posture, Client Connector, App Connectors and Private Service Edges.\nAbility to deploy and validate ZPA soluƟons at enterprise scale in partnership with plaƞorm architecture and operaƟons teams.\nStrong understanding of Azure and data center networking paƩerns relevant to ZPA deployment.\nExperience working across global teams and mulƟple technology disciplines.\nStrong technical communicaƟon skills with the ability to explain implementaƟon risks, dependencies and engineering decisions clearly.\nPassion for automaƟon, repeatable engineering standards and conƟnuous improvement. Ability to operate eﬀecƟvely in fast-paced and highly complex enterprise environments.\nTo Qualify for the Role, You Must Have\nBachelor’s degree in Computer Science, InformaƟon Technology, Engineering or equivalent experience.\n4-7 years of hands-on experience in network security, cloud security, infrastructure security or security engineering.\n3-5 years of pracƟcal Zscaler experience, including hands-on ZPA deployment, conﬁguraƟon, troubleshooƟng or operaƟons.\nStrong working knowledge of ZPA applicaƟon segments, segment groups, server groups, access policies, App Connectors, connector groups, provisioning keys and Private Service Edges.\nAbility to troubleshoot live ZPA issues using logs, diagnosƟcs, packet-level reasoning, DNS checks, rouƟng validaƟon, TLS/cerƟﬁcate checks and endpoint-side observaƟons.\nExperience integraƟng ZPA with MicrosoŌ Entra ID or equivalent idenƟty providers using SAML, SCIM, user groups, device posture and condiƟonal access signals.\nWorking knowledge of Azure networking and hybrid connecƟvity, including VNets, subnets, rouƟng, Private Link, Private Endpoint, ExpressRoute, Azure Firewall and ApplicaƟon Gateway.\nExperience deploying or supporƟng ZPA components in VMware-based data center environments and Azure cloud environme...","description_format":"text","description_chars":15022,"description_truncated":true,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Network Security","Financial Advisory, Valuation & Restructuring","Management Consulting","Tax Advisory & Preparation"],"lifecycle":[{"event":"open","at":"2026-10-03T16:36:26Z"}],"visa":[],"liveness":{"score":88,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.88,"p_room":1,"age_days":7,"expected_fill_days":22,"reasons":["conf:3","velocity","win:early","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/ernst-young-zscaler-network-security-engineer","json_url":"https://alion.io/job/ernst-young-zscaler-network-security-engineer.json","meta":{"generated_at":"2026-10-11T03:45:36Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1785,"day_limit":5000,"remaining_today":3215,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2859},"rest":"https://alion.io/mcp/rest/get_company?id=2859"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fernst-young-zscaler-network-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fernst-young-zscaler-network-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fernst-young-zscaler-network-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/ernst-young-zscaler-network-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fernst-young-zscaler-network-security-engineer"}]}