Haystack
← Back to Jobs
Technology
TE

Senior Network Security Engineer ZTNA (Zscaler, Axis/SSE Focus)

Tekfortune Inc.Houston, TX🇺🇸United StatesPosted 26 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Houston, TX, United States
Posted
Yesterday
AWSMFAOAuthSAMLAzureDNSGoogle CloudLESSZero Trust

Job Description

Role :- Senior Network Security Engineer ZTNA (Zscaler, Axis/SSE Focus)
Location :- Houston, TX(Onsite)
Note: Client is not willing to sponsor any visa.

=Note :- ZTNA (Zscaler, Axis/SSE Focus) experience is must==

Client is an innovative, dynamic company with a rich past and promising future. Company has continuously reinvented itself. Today, Client is one of the world's leading technology companies providing networking, cloud, and security solutions for next-generation IT infrastructure.
Key Responsibilities
  • Translate strategic business objectives into enterprise security architecture and Zero Trust access designs.
  • Develop and support solutions aligned with global Zero Trust and Secure Access Service Edge (SASE) strategy.
  • Drive multi-year roadmap for secure remote access, application access transformation, and perimeter-less security architecture.
  • Lead architecture and deployment of enterprise-scale ZTNA solutions across global environments (on-prem, cloud, hybrid).
ZTNA & Zero Trust Responsibilities (Primary Focus)
  • Architect, design, and implement Zero Trust Network Access (ZTNA)solutions using:
    • Zscaler (ZIA, ZPA)
    • Axis Security / Aruba SSE
  • Replace legacy VPN architectures with identity-aware, application-level secure access.
  • Design and enforce least-privilege access modelsbased on:
    • User identity
    • Device posture
    • Application context
  • Integrate ZTNA with:
    • Identity providers (Azure AD, Okta, etc.)
    • Endpoint security tools (EDR/XDR)
    • SIEM/SOAR platforms
  • Enable secure access for:
    • Remote workforce
    • Third-party vendors
    • Privileged users
  • Drive application segmentation and access policiesaligned with Zero Trust principles.
  • Collaborate with application and infrastructure teams to onboard applications into ZTNA platforms.
  • Design secure access for internet-bound (ZIA) and private application access (ZPA/Axis)use cases.
  • Implement policy tuning, traffic steering, and user experience optimizationfor ZTNA environments.
  • Lead migration programs from VPN ZTNA, ensuring minimal disruption and improved security posture.
Core Network Security Responsibilities
  • Participate in architecture reviews ensuring alignment with enterprise security standards.
  • Design and secure data center, campus, cloud, and edge environments.
  • Provide risk reporting, telemetry analysis, and security posture visibilityacross network and ZTNA platforms.
  • Conduct and support security audits and compliance initiatives.
  • Stay updated with emerging threats and continuously improve security frameworks.
  • Manage and optimize SIEM systemsfor enhanced visibility and threat detection.
  • Collaborate with global cybersecurity, infrastructure, and business stakeholders.
Technical Qualifications
  • 10+ years of experience in network security architecture and engineering.
ZTNA / SASE / SSE Expertise (Mandatory)
  • Hands-on experience implementing and managing:
    • Zscaler Internet Access (ZIA)
    • Zscaler Private Access (ZPA)
    • Axis Security / Aruba SSE platform
  • Strong understanding of:
    • Zero Trust Architecture (ZTA)
    • SASE / SSE frameworks
  • Experience with:
    • Application onboarding in ZTNA platforms
    • Policy creation (user/app/device-based)
    • Traffic forwarding (PAC files, GRE/IPSec tunnels, client connectors)
  • Expertise in:
    • Secure web gateway (SWG)
    • Cloud-delivered firewall
    • CASB/DLP integrations
  • Experience in identity integration(Azure AD, SAML, OAuth, MFA enforcement).
  • Strong knowledge of user experience optimization in cloud security platforms.
Network Security & Infrastructure
  • Strong experience in:
    • Firewalls (Fortinet, Palo Alto, Juniper)
    • IDS/IPS, VPN, SIEM, NAC
  • Deep expertise in:
    • Firewall rule design, NAT, routing, application-aware policies
  • Experience in securing:
    • Hybrid environments (data centers + cloud + internet edge)
  • Design and implementation of:
    • WAAP (Web Application & API Protection)solutions
  • Experience in proxy architectures (forward/reverse).
Networking & Protocol Expertise
  • Strong knowledge of:
    • BGP, OSPF, MPLS, IP routing
    • DNS, DHCP, NTP
  • Experience with:
    • QoS, NetFlow, ACLs, NAT, IP traffic management
    • Wireless networking (802.11 a/b/g/n/ac/ax)
Cloud & Modern Security Integration
  • Experience in securing workloads in:
    • AWS, Azure, Google Cloud Platform
  • Integration of ZTNA with:
    • Cloud-native security tools
    • Identity and access frameworks
  • Understanding of application access patterns in hybrid cloud.
Data Center & Enterprise Networking
  • Experience managing:
    • Aruba, Arista, Juniper switching
    • WAN optimization, load balancers, firewalls
  • Strong understanding of enterprise-scale network design and segmentation.
Operations & Lifecycle
  • Lead migration initiatives from:
    • Legacy VPN ZTNA/SSE platforms
  • Manage secure connectivity with third parties using ZTNA.
  • Plan and execute infrastructure upgrades and transformations.
  • Work within ITIL frameworksfor change and incident management.
Education & Certifications
  • Bachelor s Degree in Computer Science, Network Engineering, or related field (or equivalent experience).
  • 10+ years in enterprise network security roles.
  • Preferred certifications:
    • CCNP / CCIE / JNCIE
    • Zscaler certifications (ZCCA, ZCTA, ZDX, etc.)
    • Security certifications (CISSP, CISM)
Key Differentiators (What This JD Emphasizes)
  • Transitions role from network security identity-driven access security
  • Positions ZTNA as a core transformation pillar (VPN replacement, SASE adoption)
  • Aligns with enterprise initiatives like:
    • Zero Trust adoption
    • User-to-app segmentation
    • Secure hybrid workforce enablement
  • Strong balance of:
    • Zscaler + Axis expertise
    • Traditional network security controls (firewalls, SIEM)

Similar jobs