Zscaler Integration Engineer - Mid
- Koniag Government Services
- Washington, United States
- $100,000 – $130,000
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Zscaler Integration Engineer (Mid) to support enterprise network security operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site and approved remote/telework locations.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
This role serves as an important technical function responsible for the engineering, implementation, administration, and operational support of enterprise Zscaler security platform capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, and hybrid network environments.
The ideal candidate is a technically proficient and security-focused cloud security engineer with solid, hands-on experience across key Zscaler platforms—including Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA)—combined with a strong understanding of Secure Access Service Edge (SASE) architecture, Zero Trust Network Access (ZTNA) principles, enterprise networking concepts, and Federal cybersecurity compliance requirements. This individual must possess the technical depth, operational discipline, and collaborative mindset required to contribute meaningfully to the engineering and sustained operation of enterprise-grade Zscaler security capabilities under the guidance of senior engineers while demonstrating the initiative and growing expertise needed to take on increasing technical responsibility over time.
The Zscaler Integration Engineer (Mid) will serve as a contributing technical engineer within the program's network security team, supporting the engineering, implementation, administration, and continuous improvement of enterprise Zscaler security infrastructure under the technical leadership of the Senior Zscaler Integration Engineer. This individual works closely with network engineers, security engineers, cloud operations teams, identity and access management specialists, and Government stakeholders to ensure Zscaler platforms are properly configured, reliably operated, and continuously improved in alignment with enterprise security requirements, Federal cybersecurity frameworks, and Zero Trust Architecture objectives.
Principal responsibilities will include but are not limited to:
Zscaler Internet Access (ZIA) Engineering & Administration
• Assist in and independently execute the engineering, implementation, and administration of ZIA internet security policies and configurations under the technical guidance of the Senior Zscaler Integration Engineer, including URL filtering policies, application control rules, SSL/TLS inspection policies, and advanced threat protection configurations.
• Configure and maintain ZIA traffic forwarding configurations, including Zscaler Client Connector forwarding profiles, GRE and IPsec tunnel maintenance, and PAC file management, ensuring reliable and consistent forwarding of internet-bound traffic to ZIA for policy enforcement.
• Assist in the implementation and maintenance of ZIA Data Loss Prevention (DLP) policies and Cloud Access Security Broker (CASB) configurations, supporting the protection of sensitive data across internet and cloud application access scenarios.
• Monitor ZIA platform health, traffic processing performance, and policy enforcement effectiveness, identifying and escalating platform issues, policy gaps, and emerging threat patterns to senior engineers.
• Assist in ZIA SSL/TLS inspection policy management, including certificate trust configuration, bypass exception management, and performance impact assessment under the guidance of the Senior Zscaler Integration Engineer.
• Support ZIA policy lifecycle management activities, including regular policy review cycles, rule optimization, exception management, and policy documentation updates.
• Generate and analyze ZIA traffic logs, threat prevention reports, and URL filtering activity reports to support security monitoring, incident investigation, and operational performance analysis.
• Troubleshoot ZIA connectivity, policy enforcement, and performance issues, conducting root cause analysis and implementing corrective actions within defined SLA requirements under the guidance of senior engineers.
Zscaler Private Access (ZPA) Engineering & Administration
• Assist in and support the engineering, implementation, and administration of ZPA Zero Trust private application access configurations, including application segment definition, access policy development, and App Connector management under senior engineer guidance.
• Configure and maintain ZPA application segments and server groups, defining granular, application-specific access scopes that enforce least-privilege access principles across all protected private applications.
• Support the deployment and maintenance of ZPA App Connectors across on-premises and cloud environments, assisting in connector installation, configuration, health monitoring, and troubleshooting activities.
• Assist in the implementation and maintenance of ZPA access policies, including identity-based policy configurations, device posture conditions, and MFA enforcement requirements, ensuring access controls continuously evaluate user and device trust.
• Support the integration and maintenance of ZPA with enterprise identity providers, including Microsoft Entra ID and Okta, assisting in SAML and SCIM configuration and troubleshooting activities under senior engineer guidance.
• Monitor ZPA platform health, App Connector availability, and user access session data, identifying and escalating connectivity issues, policy enforcement gaps, and performance problems to senior engineers for resolution.
• Troubleshoot ZPA user access issues, App Connector connectivity failures, and policy enforcement problems, gathering relevant log data and diagnostic information to support root cause analysis and resolution activities.
• Generate and analyze ZPA access logs and policy enforcement reports, supporting security monitoring, compliance reporting, and access pattern analysis activities.
Zscaler Client Connector Administration
• Support the administration and maintenance of the Zscaler Client Connector agent across managed enterprise endpoints, assisting in agent deployment, configuration management, and health monitoring activities under senior engineer guidance.
• Monitor Zscaler Client Connector deployment coverage and agent health across the managed endpoint population, identifying and escalating deployment gaps, agent connectivity failures, and configuration drift issues for remediation.
• Assist in the configuration and maintenance of Zscaler Client Connector forwarding profiles, app profiles, and policy configurations, ensuring consistent ZIA, ZPA, and ZDX service delivery across all managed endpoint platforms.
• Support the integration of Zscaler Client Connector with enterprise endpoint management platforms, assisting in deployment package development, configuration profile management, and agent health reporting activities.
• Troubleshoot Zscaler Client Connector connectivity and functionality issues, analyzing client logs and platform diagnostic data to identify root causes and implement corrective actions under senior engineer guidance.
Zscaler Digital Experience (ZDX) Support
• Assist in the administration and monitoring of the Zscaler Digital Experience (ZDX) platform, supporting the monitoring of user digital experience quality, application performance, and network path health across the enterprise environment.
• Monitor ZDX dashboards and alerting outputs, identifying user experience degradation, application performance issues, and network path problems requiring escalation to senior engineers and relevant infrastructure or network teams.
• Assist in the development and maintenance of ZDX monitoring configurations, including application performance probe setup and user experience alerting threshold configuration under senior engineer guidance.
• Support the generation and distribution of ZDX performance reports, providing program leadership and Government stakeholders with accurate visibility into digital experience trends and identified performance issues.
Identity & Access Management Integration Support
• Support the implementation and maintenance of Zscaler platform integrations with enterprise identity and access management platforms, assisting senior engineers in configuring and troubleshooting SAML, OIDC, and SCIM-based authentication and directory synchronization integrations.
• Assist in the configuration and maintenance of identity provider integrations between Zscaler ZIA and ZPA platforms and enterprise IdPs, including Microsoft Entra ID and Okta, ensuring seamless and secure user authentication to Zscaler services.
• Monitor identity provider integration health and SCIM directory synchronization status, identifying and escalating authentication failures, synchronization errors, and policy enforcement inconsistencies to senior engineers for resolution.
• Support MFA enforcement configuration and maintenance across Zscaler platform access scenarios, assisting in the implementation and troubleshooting of strong authentication requirements in coordination with identity platform teams.
Security Operations & Threat Intelligence Support
• Monitor Zscaler platform security event logs, threat prevention alerts, and DLP policy violation reports, triaging alerts and escalating confirmed or suspected security events to senior analysts and the incident response team in accordance with defined monitoring procedures and escalation thresholds.
• Assist in the development and maintenance of Zscaler-specific SIEM detection content, supporting senior engineers in developing correlation rules and alerting configurations that leverage Zscaler telemetry for threat detection.
• Support the integration and maintenance of threat intelligence configurations within Zscaler platforms, assisting in the management of custom URL categories, IP reputation blocking, and threat intelligence-driven policy rules.
• Support incident response activities involving Zscaler platforms, providing platform-level log analysis and configuration support to senior engineers during investigation, containment, and remediation efforts.
• Assist in the analysis of Zscaler platform security event data, identifying emerging threat patterns, false positive alert sources, and policy tuning opportunities under the guidance of senior engineers.
Change Management & Documentation
• Prepare and submit Zscaler change requests for Change Advisory Board (CAB) review, developing implementation plans, technical impact assessments, rollback procedures, and test plans for assigned platform changes under senior engineer guidance.
• Coordinate with the change management process to ensure all assigned Zscaler platform changes are properly reviewed, approved, scheduled, and implemented without degradation to security posture or service availability.
• Conduct post-implementation reviews for assigned platform changes, documenting outcomes and lessons learned to support continuous improvement of change execution practices.
• Develop and maintain Zscaler operational documentation, including configuration runbooks, troubleshooting guides, policy documentation, and standard operating procedures, ensuring documentation is current and accurately reflects platform configurations.
• Maintain accurate and current Zscaler platform configuration records, change logs, and operational documentation in the program's knowledge management and documentation repositories.
Compliance & ATO Support
• Ensure Zscaler platforms are configured and maintained in compliance with applicable Federal cybersecurity frameworks and requirements, including NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, and client-specific cybersecurity policies.
• Assist in ATO activities for Zscaler platforms, including security control implementation documentation, system security plan (SSP) contribution, continuous monitoring evidence collection, and audit artifact preparation under senior engineer guidance.
• Support regular Zscaler platform configuration compliance assessments, assisting in the identification and remediation of configuration deviations from applicable security baselines and Federal compliance requirements.
• Support vulnerability management activities for Zscaler platforms, tracking platform vulnerabilities identified through vendor advisories and assisting in coordinating remediation activities under senior engineer guidance.
Education and Experience:
Required:
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered.
• Minimum of 3–5 years of hands-on experience in network security engineering, cloud security, or a closely related discipline, with at least 2–3 years of demonstrated hands-on experience engineering and administering Zscaler ZIA and/or ZPA platforms in an enterprise environment.
• Demonstrated hands-on experience configuring and administering Zscaler ZIA security policies, including URL filtering, SSL inspection, application control, and threat prevention configurations.
• Demonstrated experience supporting ZPA application access configuration, including application segment definition, App Connector management, and access policy development.
• Familiarity with enterprise identity provider integration concepts, including SAML, OIDC, and SCIM, as applied to Zscaler platform authentication and directory synchronization.
• Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of offer.
Preferred:
• Prior experience supporting Zscaler platform engineering and administration on a federal IT program.
• Hands-on experience with Zscaler Digital Experience (ZDX) platform monitoring and administration.
• Familiarity with Federal cybersecurity compliance frameworks, including NIST SP 800-53, FISMA, and FedRAMP, as applied to cloud security platform administration and ATO documentation.
Required Skills and Competencies:
• Solid technical proficiency with Zscaler ZIA platform administration, including URL filtering policy management, SSL/TLS inspection configuration, application control policy development, DLP rule management, and advanced threat protection tuning.
• Demonstrated experience with ZPA platform administration, including application segment configuration, App Connector deployment and management, access policy development, and identity provider integration.
• Strong understanding of SASE and Zero Trust Network Access (ZTNA) principles and their practical application to enterprise internet security, private application access, and cloud-delivered security policy enforcement.
• Familiarity with Zscaler Client Connector deployment and management across enterprise endpoint platforms, including Windows, macOS, and mobile device environments.
• Knowledge of enterprise identity and access management platform integration concepts, including SAML, OIDC, and SCIM-based directory synchronization, as applied to Zscaler platform authentication configuration.
• Solid understanding of enterprise networking concepts, including TCP/IP, DNS, routing fundamentals, GRE and IPsec tunneling, and traffic forwarding architectures as they relate to Zscaler ZIA and ZPA platform integration and troubleshooting.
• Knowledge of Federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, and applicable security standards.
• Understanding of Zero Trust Architecture principles and their practical application to cloud-delivered security policy enforcement, private application access control, and identity-aware security using Zscaler platform capabilities.
• Experience preparing and executing platform change requests, including implementation plan development, rollback procedure documentation, and CAB submission in accordance with enterprise change management processes.
• Strong analytical and troubleshooting skills with demonstrated ability to diagnose and resolve ZIA and ZPA connectivity, performance, and policy enforcement issues in a production enterprise environment.
• Excellent written and verbal communication skills with demonstrated ability to develop clear operational documentation, change request packages, and technical status reports for both technical and non-technical audiences.
Desired Skills and Competencies:
• Zscaler Certified Cloud Professional (ZCCP) – ZIA certification — strongly preferred.
• Zscaler Certified Cloud Professional (ZCCP) – ZPA certification — strongly preferred.
• Zscaler Certified Cloud Administrator (ZCCA) – ZIA or ZPA certification or active pursuit as a near-term professional development objective.
• CompTIA Security+, CompTIA Network+, or equivalent foundational cybersecurity or networking certification.
• Certified Information Systems Security Professional (CISSP) or equivalent senior cybersecurity certification.
• Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) or Microsoft Certified: Identity and Access Administrator Associate (SC-300), or equivalent Microsoft identity platform certification demonstrating familiarity with Entra ID integration concepts.
• Experience with Microsoft Entra ID and/or Okta identity platform administration, including SAML application configuration, conditional access policy development, and SCIM provisioning.
• Familiarity with Zscaler Digital Experience (ZDX) platform monitoring capabilities, including application performance probe configuration and digital experience reporting.
• Familiarity with Zscaler Posture Control cloud security posture management platform capabilities and configuration.
• Experience with SIEM platform integration for Zscaler log forwarding, including syslog and Cloud NSS feed configuration and Zscaler-specific log source onboarding.
• Basic scripting proficiency in Python, PowerShell, or Bash for Zscaler API integration, operational task automation, and configuration management activities.
• Experience with cloud security operations in AWS and/or Microsoft Azure Government environments, including familiarity with cloud networking concepts relevant to ZPA App Connector deployment and Zscaler cloud platform integration.
• Familiarity with the MITRE ATT&CK framework and its application to Zscaler threat prevention policy development, detection content support, and security posture assessment activities.
• Experience supporting security incident response activities involving cloud security platforms, including Zscaler platform log analysis and policy-level investigation support.
• Familiarity with FedRAMP continuous monitoring requirements and ATO documentation activities as they relate to cloud security platform administration and compliance evidence collection.
• Familiarity with Section 508 compliance requirements for security dashboards and reporting tools delivered under federal contracts.
Our Equal Employment Opportunity Policy:
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Skills
- Zscaler Internet Access (ZIA)
- Zscaler Private Access (ZPA)
- Secure Access Service Edge (SASE)
- Network Security
- Cloud Security
- IT Administration
- Security Clearance


