Point your AI agent at freehire and let it find you a job.

Get the CLI →

Syensqo

New

ZScaler Architect

Discussion

Syensqo is all about chemistry. We’re not just referring to chemical reactions here, but also to the magic that occurs when the brightest minds get to work together. This is where our true strength lies. In you. In your future colleagues and in all your differences. And of course, in your ideas to improve lives while preserving our planet’s beauty for the generations to come.

Job Title: Zscaler Senior Architect

Location: Pune, India

Department: IT / Cybersecurity

Job Purpose

As a SSE Zscaler Architect, you own the end-to-end architecture and design of Syensqo’s Secure Service Edge (SSE) capabilities built on Zscaler, ensuring solutions are secure by design, scalable, resilient, and operable globally.
In addition to architecture leadership, you provide hands-on Run support with a focus on P1 incidents (major outages / critical degradations), acting as a senior escalation point to restore service quickly and drive long-term fixes.

Key Responsibilities

1) Domain Architecture & Solution Design (primary focus)

  • Define and maintain the SSE domain target architecture and reference designs across Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) (and related components within scope, e.g., Client Connector, forwarding methods, policy frameworks).

  • Produce and govern architecture deliverables: HLD/LLD, decision records (ADRs), design patterns, security standards, and operational runbooks (architecture-owned sections).

  • Lead architecture decisions covering: traffic forwarding (PAC, tunnels), identity and access flows, segmentation and application publishing (ZPA), TLS inspection strategy, DNS strategies, logging/telemetry, resiliency and capacity.

  • Ensure designs align with Zero Trust principles, Syensqo security policies, enterprise network/cloud strategy, and user experience requirements.

  • Run architecture reviews for new use cases, new application onboarding, major changes, and complex projects; validate designs delivered by engineering teams and partners.

2) Governance, Risk & Compliance

  • Define and enforce security policy design principles and guardrails (least privilege, segmentation, change control, secure defaults).

  • Support risk assessments and audits: provide evidence, explain architecture choices, and drive remediation plans where gaps are identified.

  • Maintain configuration and policy consistency across regions/tenants/environments through standardization and review processes.

3) Integration Architecture (ecosystem ownership)

  • Architect integrations with:

  • IAM/SSO (Entra ID/Azure AD, MFA, Conditional Access),

  • Endpoint posture/device trust (MDM, EDR where applicable),

  • SIEM/SOC (logging, alerting, correlation use cases),

  • Network (DNS, SD-WAN, firewalls, proxies) and cloud platforms (Azure/AWS/GCP).

  • Define onboarding patterns for applications into ZPA (App Connectors placement, segmentation model, naming conventions, health checks, connectivity dependencies).

4) Run / Operations (with P1 ticket intervention)

  • Act as senior escalation for major incidents (P1/P2) related to Zscaler SSE services; coordinate troubleshooting across network, endpoint, IAM, and SOC teams.

  • Perform deep technical analysis (packet/path reasoning, DNS/TLS/auth flows, policy evaluation) to restore service and minimize business impact.

  • Lead or contribute to root cause analysis (RCA), document findings, and own corrective/preventive actions (CAPA) including architectural improvements.

  • Establish and track key operability KPIs/SLOs (availability, latency, auth failures, tunnel health, connector health, policy deployment errors).

  • Improve operational readiness: create/maintain runbooks, escalation paths, monitoring requirements, and “known errors” documentation.

5) Continuous Improvement & Enablement

  • Keep up to date with Zscaler roadmap/features and SSE threat landscape; propose improvements to security posture, performance, and operational efficiency.

  • Coach L2/L3 teams and contribute to knowledge transfer sessions (architecture intent + operational practices).

  • Promote automation/standardization where feasible (templates, repeatable onboarding patterns, controlled change processes).

Qualifications & Experience

  • Bachelor’s or Master’s degree in Computer Science, Information Security, Networking, or equivalent experience.

  • 8+ years in network/security engineering, including 3+ years on Zscaler and/or SSE/ZTNA at enterprise scale.

  • Demonstrated experience in domain architecture: reference architectures, design governance, HLD/LLD production, and technical decision-making.

  • Strong hands-on troubleshooting skills across TCP/IP, DNS, TLS, proxies, VPNs, routing, and identity flows.

  • Cloud familiarity (Azure/AWS/GCP) and hybrid enterprise networking experience.

  • Certifications preferred: Zscaler (ZCCP / ZCSE), CCNP Security (or equivalent).

  • Strong documentation, communication, and stakeholder management skills in a global environment.

Key Competencies

  • Architecture mindset: system thinking, standardization, scalability, resiliency, operability-by-design

  • Incident leadership: calm under pressure, structured troubleshooting, decisive prioritization (P1 focus)

  • Risk-based decision making and pragmatic trade-off management

  • Collaboration and influence across Network, IAM, Endpoint, SOC, and Application teams

  • Clear technical writing and ability to explain complex topics to mixed audiences

About us
Syensqo is a science company developing groundbreaking solutions that enhance the way we live, work, travel and play. Inspired by the scientific councils which Ernest Solvay initiated in 1911, we bring great minds together to push the limits of science and innovation for the benefit of our customers, with a diverse, global team of more than 13,000 associates. Our solutions contribute to safer, cleaner, and more sustainable products found in homes, food and consumer goods, planes, cars, batteries, smart devices and health care applications. Our innovation power enables us to deliver on the ambition of a circular economy and explore breakthrough technologies that advance humanity. At Syensqo, we seek to promote unity and not uniformity. We value the diversity that individuals bring and we invite you to consider a future with us, regardless of background, age, gender, national origin, ethnicity, religion, sexual orientation, ability or identity. We encourage individuals who may require any assistance or accommodations to let us know to ensure a seamless application experience. We are here to support you throughout the application journey and want to ensure all candidates are treated equally. If you are unsure whether you meet all the criteria or qualifications listed in the job description, we still encourage you to apply

#LI-Hybrid

Skills

See also

Architecture jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available