Network Security Engineer
Listed on 2026-05-16
-
IT/Tech
Systems Engineer, Cybersecurity, Network Security, Cloud Computing
Overview
Your Job (Sr. Network Security Engineer – Zscaler Specialist) is part of a global infrastructure organization responsible for designing, implementing, and delivering enterprise-grade secure access solutions using cloud-delivered security, particularly the Zscaler platform. This role designs, implements, and manages secure access solutions that protect enterprise users, applications, and data in modern cloud and on-prem environments. The engineer collaborates with architecture, security, operations, and vendors to ensure high-quality, scalable, and secure access.
OurTeam
The KOCH Technologies Infrastructure team provides reliable, flexible, and secure connectivity solutions to enable business solutions and transformation. We manage network and network security infrastructure, including WAN/LAN, wireless, firewalls, data center networking, load balancing, endpoint security, and proxies. We provide enterprise infrastructure monitoring across the enterprise and focus on talent, proactive management, process optimization and automation, security by design, and a service-focused organization.
This role can be based in Wichita, KS / Plano, TX / Atlanta, GA / Green Bay, WI and requires in-office presence with flexibility. This role is not eligible for VISA sponsorship.
What You Will Do- Design, implement, and manage Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zscaler Digital Experience (ZDX) in alignment with Zero Trust Architecture (ZTA) principles.
- Define and enforce Zero Trust policies based on user identity, device posture, application context, and risk signals.
- Architect least-privileged access models ensuring users are granted access only to specific applications—not entire networks.
- Implement and optimize application segmentation and user-to-app access policies using ZPA.
- Continuously evaluate and improve trust evaluation mechanisms, including device compliance, user behaviour, and session context.
- Deploy and optimize SSL/TLS inspection, secure web gateway policies, CASB controls, and DLP frameworks within ZIA as part of Zero Trust data protection strategy.
- Monitor user experience and performance using ZDX and troubleshoot connectivity or latency issues.
- Collaborate with network, security, and vendor teams to ensure seamless and secure connectivity.
- Perform log analysis, incident response, and threat mitigation using Zscaler logs and SIEM tools.
- Ensure compliance with security standards and best practices.
- Stay updated with evolving Zero Trust frameworks and industry best practices.
- Document architecture, configurations, and operational procedures.
- Contribute to automation and standardization efforts (Ansible, Terraform, APIs).
- Identify inefficiencies and drive process, quality, and documentation improvements.
- Participate in design reviews, quality checks, and peer mentoring.
- Work directly with internal customers, project managers, and global stakeholders.
- Coordinate with OEMs and system integrators for implementation and issue resolution.
- Provide clear communication on project status, risks, and dependencies.
- Participate in on-call rotations as part of a global team, including availability for planned weekend or off-hours work during major implementations or migrations.
- Demonstrated experience in an enterprise network security field.
- Hands-on experience with Zscaler ZIA and ZPA, proxy technologies, VPN alternatives and secure remote access.
- Strong understanding of Zero Trust Network Access (ZTNA).
- Experience with TCP/IP, DNS, HTTP/HTTPS, SSL/TLS inspection.
- Experience with firewall and routing concepts.
- Exposure to cloud platforms such as AWS, Microsoft Azure, or Google Cloud Platform (GCP).
- Understanding of cloud security principles and secure workload access.
- Familiarity with SIEM/Observability tools (e.g., Splunk, Grafana, Logic Monitor).
- Zscaler certifications (e.g., ZCCA, ZCCP, ZCSP).
- Exposure to network automation (Python, Ansible, Dev Net concepts).
- Experience with Branch/Cloud Connector deployments.
- Experience with other security platforms (CASB, SWG, EDR/XDR).
- Knowledge of cloud platforms such as AWS, Azure, or GCP.
- An open-minded…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).