Position Title: ZPA Network Engineer
Location: Harrisburg, PA (Hybrid)
Interview Process: Video Only
Position Type: Full-Time (37.5 hours/week)
Important Requirements
- Hybrid schedule required 2 days onsite at CTC in Harrisburg
- Local candidates only
Key Responsibilities
- Collaborate with enterprise network, security, and identity teams to design and support ZPA-based access solutions
- Design, configure, and maintain:
- App Connectors
- Server Groups
- Application Segments
- Access Policies
- Analyze legacy VPN and network access models and convert them into Zero Trust (ZTNA) access patterns
- Support onboarding of applications into ZPA by validating:
- Network paths
- Ports and protocols
- Application dependencies
- Configure and enforce least-privilege access policies
- Troubleshoot ZPA-related issues, including:
- User access failures
- Application connectivity issues
- Connector health and routing problems
- Support migration of users and applications from legacy VPN to ZPA
- Ensure configurations are secure, auditable, and compliant
- Develop and maintain:
- Technical documentation
- Configuration standards
- Network diagrams
- Operational runbooks
- Work with vendors and Zscaler support for issue resolution and optimization
Required Qualifications
- Strong experience in enterprise networking:
- Routing & Switching
- Firewalls
- DNS
- Traffic flow analysis
- Hands-on experience with:
- Zscaler Private Access (ZPA) or similar Zero Trust platforms
- Strong understanding of:
- Zero Trust Network Access (ZTNA)
- Application-level segmentation
- Experience modernizing legacy VPN/network environments
- Experience in regulated/compliance-driven environments
- Strong communication and documentation skills
Preferred Qualifications
- Zscaler Certifications:
- Zscaler Digital Transformation Administrator
- Zscaler Digital Transformation Engineer
- Industry certifications:
- CCNP, Security+, CySA+ or equivalent
- Experience in:
- Public sector or multi-agency environments
- Large enterprise network transformations
- Familiarity with:
- NIST 800-53, CJIS, or similar frameworks
- Experience supporting Zero Trust initiatives