Zscaler ZPA Deployment Engineer

GeekSoft Consulting•Sacramento, CA

About The Position

Help design, build and continuously improve the clients online platform. Research, suggest and implement new technology solutions following best practices/standards. Take responsibility for the resiliency and availability of different products. Be a productive member of the team. Requirements Zscaler ZPA Deployment Engineer for an enterprise network modernization and Zero Trust transformation initiative. End-to-end deployment, architecture, configuration, and migration from a legacy VPN environment to Zscaler Private Access (ZPA), combining hands-on engineering expertise with strong executive communication skills.

Requirements

  • Zscaler Certified Cloud Professional (ZCCP) – ZPA track, or equivalent enterprise-scale ZPA deployment experience.
  • At least 3 hands-on, end-to-end ZPA deployments, covering architecture, design, implementation, and production cutover.
  • Strong technical expertise in App Connector architecture, HA clustering, and multi-site deployments.
  • Strong understanding of application segmentation and ZTNA frameworks.
  • Proven experience migrating enterprise VPN environments, including FortiClient and Cisco AnyConnect, to ZPA.
  • Hands-on experience configuring SMB and mapped drive access over ZPA tunnels.
  • Strong experience integrating Microsoft Entra ID (Azure AD) with hybrid Active Directory environments.
  • Excellent verbal and written communication skills, with strong executive presence in high-visibility environments.

Nice To Haves

  • Hands-on experience with Zscaler Internet Access (ZIA) and integration with existing Zscaler tenants.
  • Experience deploying Zscaler Client Connector through Microsoft Intune or enterprise MDM solutions.
  • Experience delivering network and security migrations within manufacturing or industrial environments.
  • Familiarity with Fortinet firewalls and architecture for migration discovery and planning.

Responsibilities

  • Lead the end-to-end deployment and production cutover of Zscaler Private Access (ZPA).
  • Design and deploy resilient App Connector architectures, including HA configurations across multi-site enterprise environments.
  • Lead the migration from legacy VPN solutions such as FortiClient and Cisco AnyConnect to ZPA.
  • Configure application segmentation policies aligned with Zero Trust Network Access (ZTNA) principles.
  • Ensure seamless access to internal file shares, SMB, and mapped drives through ZPA.
  • Integrate ZPA connectors and design access policies with Microsoft Entra ID in hybrid Active Directory environments.
  • Participate in discovery and architecture workshops and present technical design decisions to senior IT leadership and executive stakeholders.

Benefits

  • A challenging, innovating environment.
  • Opportunities for learning where needed.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service