Zscaler Network Security-Principal engineer- Associate director
About this role
The Opportunity
We are looking for a Principal Engineer – Associate Director to join Security Technology Services as a senior hands-on engineering leader focused on Zscaler, Zero Trust and secure cloud networking integration.
This role is responsible for engineering, deployment, integration, automation, optimization and technical leadership of EY’s global Zscaler platform and associated network security capabilities.
The successful candidate will operate as a deeply technical, hands-on subject matter expert across core Zscaler cloud capabilities, ZPA, Zscaler Client Connector, workload segmentation, Azure secure networking concepts, hybrid data center connectivity, Zscaler AI Firewall, AI Guard and Zero Trust access patterns.
This role will lead strategic engineering initiatives focused on:
- Azure secure networking integration
- Hybrid cloud security
- VMware data center segmentation
- Enterprise AI security using Zscaler AI Firewall and AI Guard
- Secure access transformation
The role will work closely with Network Security, Cloud Engineering, Application Security, Identity, Infrastructure, Architecture, and Product teams to engineer and deploy scalable enterprise security solutions globally.
Your Key Responsibilities
The Zscaler and Zero Trust Engineering Lead will provide senior technical leadership for the deployment, integration, optimization and continuous improvement of EY’s global secure access and Zero Trust engineering platforms.
Zscaler Engineering Leadership
- Serve as the senior hands-on engineering lead for core Zscaler cloud capabilities, including ZIA, ZPA, Zscaler Client Connector, App Connectors, Private Service Edges, Workload Communications, Microsegmentation, Zscaler AI Firewall and AI Guard.
- Engineer, deploy, configure and optimize large-scale Zscaler solutions supporting global business operations.
- Lead onboarding of enterprise applications, cloud services and business workloads into Zero Trust architectures.
- Drive adoption of new Zscaler capabilities and engineering best practices.
- Develop reference configurations, reusable engineering patterns and deployment standards.
Azure Secure Networking Integration
- Bring deep working knowledge of Azure secure networking patterns to support Zscaler integration across EY Azure environments.
- Understand, validate and troubleshoot Azure networking components including Virtual WAN, ExpressRoute, Azure Firewall, Application Gateway, Front Door, Private Link and Private Endpoint.
- Work with EY Azure architects to integrate Zscaler capabilities with Azure-hosted applications, workloads, AI platforms and infrastructure services.
- Translate Azure secure networking requirements into Zscaler engineering patterns, connectivity models and deployment standards.
- Partner closely with EY Azure architecture and cloud engineering teams to drive secure Zscaler product integration across Azure environments.
Zero Trust and Application Access Engineering
- Lead migration of applications from traditional VPN and internet-facing architectures to Zero Trust models using ZPA.
- Engineer secure access models for internal users, external users, vendors, contractors and developers.
- Implement identity-aware access controls integrated with Entra ID, Conditional Access and device posture solutions.
- Engineer secure connectivity solutions for hybrid cloud and multi-cloud environments.
- Engineer application segmentation patterns that reduce attack surface and minimize lateral movement risk.
Workload Segmentation Engineering
- Implement workload segmentation solutions across Azure and hybrid environments.
- Deploy and manage Zscaler Workload Communications capabilities.
- Engineer workload-to-workload and application-to-application segmentation policies.
- Secure east-west traffic between business-critical applications and services.
- Develop segmentation models for production, non-production, shared services and management environments.
Data Center and VMware Security Engineering
- Engineer secure connectivity solutions across traditional data center environments.
- Deploy App Connectors and Private Service Edges in VMware-based infrastructure.
- Integrate Zscaler technologies with enterprise data center environments.
- Support migration of legacy applications into Zero Trust architectures.
- Support secure connectivity integration between on-premises data centers, Zscaler platforms and Azure cloud environments.
Engineering Automation and Platform Optimization
- Build and maintain automation solutions to improve security engineering efficiency.
- Automate deployment, configuration validation and policy management activities.
- Utilize Terraform, Python, PowerShell, APIs and Infrastructure-as-Code approaches.
- Improve platform scalability, consistency and operational effectiveness through automation.
- Participate in development of future-state security engineering roadmaps.
Technical Leadership
- Serve as the highest level engineering escalation point for complex technical issues.
- Lead troubleshooting of networking, routing, DNS, TLS, authentication and connectivity challenges.
- Mentor and coach engineers across Network Security Technology.
- Participate in architecture reviews, engineering governance and major transformation programs.
- Communicate complex technical concepts to engineering, architecture and executive stakeholders.
Skills and Attributes for Success
We are interested in candidates who bring deep engineering experience from large global enterprise environments and can combine hands-on technical execution with practical leadership.
As a successful candidate, you will demonstrate:
- Strong hands-on engineering expertise across network security, cloud security and Zero Trust technologies.
- Deep troubleshooting and problem-solving capabilities.
- Ability to engineer and deploy security solutions at enterprise scale in partnership with platform architecture teams.
- Strong understanding of Azure secure networking, hybrid connectivity and cloud security integration patterns.
- Experience working across global teams and multiple technology disciplines.
- Strong communication and stakeholder management skills.
- Passion for automation, innovation and continuous improvement.
- Ability to operate effectively in fast-paced and highly complex environments.
To Qualify for the Role, You Must Have
- Bachelor’s degree in computer science, Information Technology, Engineering or equivalent experience.
- 15-20 years of Network Security and Security Engineering experience.
- 12-15 years of experience engineering, deploying or integrating cloud security and Zscaler technologies.
- 8-10 years leading engineering teams or large engineering initiatives.
- Expert-level experience with Zscaler technologies including ZIA and ZPA.
- Experience deploying and supporting enterprise-scale Zscaler environments.
- Experience implementing Zero Trust solutions and secure access architectures.
- Experience onboarding cloud-hosted and on-premises applications into ZPA.