Role :- Senior Network Security Engineer ZTNA (Zscaler, Axis/SSE Focus)
Location :- Houston, TX(Onsite)
Note: Client is not willing to sponsor any visa.
=Note :- ZTNA (Zscaler, Axis/SSE Focus) experience is must==
Client is an innovative, dynamic company with a rich past and promising future. Company has continuously reinvented itself. Today, Client is one of the world's leading technology companies providing networking, cloud, and security solutions for next-generation IT infrastructure.
Key Responsibilities
Translate strategic business objectives into enterprise security architecture and Zero Trust access designs.
Develop and support solutions aligned with global Zero Trust and Secure Access Service Edge (SASE) strategy.
Drive multi-year roadmap for secure remote access, application access transformation, and perimeter-less security architecture.
Lead architecture and deployment of enterprise-scale ZTNA solutions across global environments (on-prem, cloud, hybrid).
ZTNA & Zero Trust Responsibilities (Primary Focus)
Architect, design, and implement Zero Trust Network Access (ZTNA)solutions using:
Replace legacy VPN architectures with identity-aware, application-level secure access.
Design and enforce least-privilege access modelsbased on:
User identity
Device posture
Application context
Integrate ZTNA with:
Identity providers (Azure AD, Okta, etc.)
Endpoint security tools (EDR/XDR)
SIEM/SOAR platforms
Enable secure access for:
Remote workforce
Third-party vendors
Privileged users
Drive application segmentation and access policiesaligned with Zero Trust principles.
Collaborate with application and infrastructure teams to onboard applications into ZTNA platforms.
Design secure access for internet-bound (ZIA) and private application access (ZPA/Axis)use cases.
Implement policy tuning, traffic steering, and user experience optimizationfor ZTNA environments.
Lead migration programs from VPN ZTNA, ensuring minimal disruption and improved security posture.
Core Network Security Responsibilities
Participate in architecture reviews ensuring alignment with enterprise security standards.
Design and secure data center, campus, cloud, and edge environments.
Provide risk reporting, telemetry analysis, and security posture visibilityacross network and ZTNA platforms.
Conduct and support security audits and compliance initiatives.
Stay updated with emerging threats and continuously improve security frameworks.
Manage and optimize SIEM systemsfor enhanced visibility and threat detection.
Collaborate with global cybersecurity, infrastructure, and business stakeholders.
Technical Qualifications
ZTNA / SASE / SSE Expertise (Mandatory)
Hands-on experience implementing and managing:
Zscaler Internet Access (ZIA)
Zscaler Private Access (ZPA)
Axis Security / Aruba SSE platform
Strong understanding of:
Experience with:
Application onboarding in ZTNA platforms
Policy creation (user/app/device-based)
Traffic forwarding (PAC files, GRE/IPSec tunnels, client connectors)
Expertise in:
Secure web gateway (SWG)
Cloud-delivered firewall
CASB/DLP integrations
Experience in identity integration(Azure AD, SAML, OAuth, MFA enforcement).
Strong knowledge of user experience optimization in cloud security platforms.
Network Security & Infrastructure
Networking & Protocol Expertise
Strong knowledge of:
Experience with:
QoS, NetFlow, ACLs, NAT, IP traffic management
Wireless networking (802.11 a/b/g/n/ac/ax)
Cloud & Modern Security Integration
Experience in securing workloads in:
Integration of ZTNA with:
Understanding of application access patterns in hybrid cloud.
Data Center & Enterprise Networking
Operations & Lifecycle
Lead migration initiatives from:
Manage secure connectivity with third parties using ZTNA.
Plan and execute infrastructure upgrades and transformations.
Work within ITIL frameworksfor change and incident management.
Education & Certifications
Bachelor s Degree in Computer Science, Network Engineering, or related field (or equivalent experience).
10+ years in enterprise network security roles.
Preferred certifications:
CCNP / CCIE / JNCIE
Zscaler certifications (ZCCA, ZCTA, ZDX, etc.)
Security certifications (CISSP, CISM)
Key Differentiators (What This JD Emphasizes)
Transitions role from network security identity-driven access security
Positions ZTNA as a core transformation pillar (VPN replacement, SASE adoption)
Aligns with enterprise initiatives like:
Strong balance of: