Zscaler Integration Engineer, MID
Zscaler Integration Engineer, MID
Location: Washington, DC
Work Schedule: Full-Time, On-Site – Daily Commute Required
Employment Type: Full-Time
Clearance: Active security clearance
Salary Range: $100,000 – $125,000 annually
Position Summary
Digital Global Connectors (DGC) is seeking a Zscaler Integration Engineer, MID to support the engineering, implementation, administration, and continuous improvement of enterprise Zscaler security infrastructure within a Federal Government IT environment.
This is a local, on-site position requiring a daily commute to the customer site in the Washington, DC area. Only candidates who currently reside within a reasonable daily commuting distance of the worksite will be considered. This position is not remote or hybrid, and candidates planning to relocate to the area at a later date will not be considered for this opening.
The Zscaler Integration Engineer will work as part of a network and cybersecurity engineering team supporting Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Client Connector, Zscaler Digital Experience (ZDX), and associated security and identity technologies.
The engineer will collaborate with network engineers, cybersecurity engineers, cloud operations teams, identity and access management specialists, and Government stakeholders to deliver secure, reliable, and compliant cloud-delivered security capabilities.
The ideal candidate has hands-on Zscaler experience, strong networking fundamentals, knowledge of SASE and Zero Trust Network Access (ZTNA), and experience supporting cybersecurity operations within enterprise or Federal IT environments.
Key Responsibilities
Zscaler Internet Access (ZIA)
- Engineer, configure, administer, and troubleshoot Zscaler Internet Access (ZIA) capabilities.
- Configure and maintain URL filtering, application control, SSL/TLS inspection, and advanced threat-protection policies.
- Configure and support ZIA traffic forwarding using Zscaler Client Connector, GRE tunnels, IPsec tunnels, and PAC files.
- Assist with implementation and maintenance of Data Loss Prevention (DLP) and Cloud Access Security Broker (CASB) capabilities.
- Manage SSL/TLS inspection configurations, certificate trust, and policy exceptions.
- Monitor ZIA platform health, traffic processing, security-policy enforcement, and performance.
- Perform policy reviews, rule optimization, and exception management.
- Analyze ZIA traffic, security, threat-prevention, and URL-filtering logs.
- Troubleshoot connectivity, policy-enforcement, and performance issues.
Zscaler Private Access (ZPA)
- Engineer, configure, and administer Zscaler Private Access (ZPA) capabilities.
- Configure application segments, server groups, and application-specific access controls.
- Deploy, configure, monitor, and troubleshoot ZPA App Connectors across on-premises and cloud environments.
- Develop and maintain ZPA access policies using identity, device posture, MFA, and other contextual access controls.
- Support integration with identity providers including Microsoft Entra ID and Okta.
- Configure and troubleshoot SAML and SCIM integrations.
- Monitor ZPA availability, App Connector health, access sessions, and policy enforcement.
- Troubleshoot user-access, connectivity, and policy issues.
- Analyze ZPA access logs and reports to support security monitoring and compliance activities.
Zscaler Client Connector
- Administer and maintain Zscaler Client Connector across enterprise endpoints.
- Support Client Connector deployment, configuration, and health monitoring.
- Configure and maintain forwarding profiles, application profiles, and security-policy configurations.
- Monitor endpoint deployment coverage and identify agent connectivity or configuration issues.
- Support integration with enterprise endpoint-management technologies.
- Troubleshoot Client Connector connectivity and functionality issues.
Zscaler Digital Experience (ZDX)
- Support administration and monitoring of Zscaler Digital Experience (ZDX).
- Monitor application performance, user digital experience, and network-path health.
- Identify and troubleshoot user-experience and application-performance issues.
- Assist with configuration of application-performance probes and alert thresholds.
- Develop ZDX operational and performance reports.
Identity & Access Management Integration
- Support integration of Zscaler technologies with enterprise identity and access management platforms.
- Configure and troubleshoot SAML, OIDC, and SCIM integrations.
- Support Microsoft Entra ID and/or Okta integrations.
- Monitor identity-provider and directory-synchronization health.
- Support implementation and troubleshooting of MFA requirements.
- Assist with identity-aware Zero Trust access-policy enforcement.
Security Operations
- Monitor Zscaler security events, threat-prevention alerts, and DLP policy violations.
- Perform initial analysis and triage of security events.
- Support integration of Zscaler telemetry with enterprise SIEM capabilities.
- Assist with development and tuning of Zscaler-specific security detections.
- Support threat-intelligence-driven URL, IP reputation, and security-policy configurations.
- Assist incident-response teams with Zscaler log analysis, investigation, containment, and remediation.
- Identify false positives, emerging threat patterns, and security-policy tuning opportunities.
Change Management & Documentation
- Prepare Zscaler change requests for Change Advisory Board (CAB) review.
- Develop implementation plans, technical impact assessments, testing procedures, and rollback plans.
- Execute approved configuration changes in accordance with established change-management procedures.
- Conduct post-implementation testing and document results.
- Develop and maintain Zscaler runbooks, troubleshooting guides, security-policy documentation, and Standard Operating Procedures (SOPs).
- Maintain accurate configuration records, change logs, and operational documentation.
Federal Cybersecurity Compliance & ATO
- Support operation of Zscaler technologies in accordance with applicable Federal cybersecurity requirements.
- Support compliance with NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, applicable OMB requirements, and customer-specific cybersecurity requirements.
- Assist with ATO activities, including security-control implementation documentation, SSP contributions, continuous-monitoring evidence, and audit artifacts.
- Support configuration-compliance assessments.
- Identify and assist with remediation of configuration deviations and security gaps.
- Support vulnerability tracking and remediation activities associated with Zscaler technologies.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related field. An equivalent combination of education and directly relevant professional experience may be considered.
- 3–5 years of hands-on experience in network security engineering, cloud security, cybersecurity engineering, or a closely related discipline.
- At least 2–3 years of hands-on experience engineering and administering Zscaler ZIA and/or ZPA in an enterprise environment.
- Demonstrated experience configuring and administering ZIA security policies, including:
- URL filtering
- SSL/TLS inspection
- Application control
- Threat prevention
- Demonstrated experience with ZPA, including:
- Application segments
- App Connectors
- Access-policy development
- Strong understanding of Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) principles.
- Familiarity with Zscaler Client Connector deployment and administration.
- Knowledge of identity-provider integration using SAML, OIDC, and SCIM.
- Solid enterprise networking knowledge, including:
- TCP/IP
- DNS
- Routing
- GRE tunneling
- IPsec
- Traffic-forwarding architectures
- Strong troubleshooting and root-cause-analysis skills.
- Experience working within formal enterprise change-management processes.
- Strong written and verbal communication skills.
- Ability to develop clear technical documentation and communicate effectively with technical and non-technical stakeholders.
- Active security clearance or ability to obtain and maintain the Government background investigation, clearance, and IT access required for the position.
- Must currently reside within reasonable daily commuting distance of the Washington, DC/Northern Virginia customer worksite and be available to report on-site each workday.
- Candidates requiring relocation, remote work, or a hybrid work arrangement will not be considered for this position.
Preferred Qualifications
- Previous Zscaler engineering or administration experience supporting a Federal Government contract or Federal IT program.
- Experience with Zscaler Digital Experience (ZDX).
- Experience with Zscaler DLP and CASB capabilities.
- Experience with Microsoft Entra ID and/or Okta.
- Experience configuring SAML applications, Conditional Access, and SCIM provisioning.
- Experience integrating Zscaler telemetry with SIEM platforms.
- Experience with Cloud NSS feeds and Zscaler log-source onboarding.
- Experience supporting AWS and/or Microsoft Azure Government environments.
- Familiarity with Zscaler Posture Control.
- Familiarity with MITRE ATT&CK.
- Experience supporting cybersecurity incident response.
- Experience supporting ATO and FedRAMP continuous-monitoring activities.
- Basic scripting experience using Python, PowerShell, or Bash.
- Experience using Zscaler APIs for automation or configuration management.
Preferred Certifications
One or more of the following certifications is preferred:
- Zscaler Certified Cloud Professional (ZCCP) – ZIA
- Zscaler Certified Cloud Professional (ZCCP) – ZPA
- Zscaler Certified Cloud Administrator (ZCCA) – ZIA or ZPA
- CompTIA Security+
- CompTIA Network+
- CISSP
- Microsoft SC-900
- Microsoft SC-300
- Other relevant Zscaler, cybersecurity, networking, cloud-security, or identity certifications
Core Competencies
Successful candidates will demonstrate:
- Strong hands-on Zscaler technical proficiency
- SASE and Zero Trust knowledge
- Enterprise networking knowledge
- Identity and access management integration knowledge
- Strong analytical and troubleshooting ability
- Security-focused decision making
- Attention to configuration and documentation accuracy
- Ability to work within structured Federal change-management and compliance environments
- Strong collaboration across network, security, cloud, and identity teams
- Ability to work independently while appropriately escalating complex technical issues
Compensation
DGC anticipates a base salary range of $100,000 – $125,000 annually for this position. Actual compensation will be determined based on Zscaler expertise, years and depth of relevant experience, Federal contracting experience, certifications, clearance status, identity and cloud-security experience, education, and other job-related qualifications.
Equal Employment Opportunity
Digital Global Connectors, LLC is an Equal Opportunity Employer. DGC provides equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable Federal, state, or local law.