Cloud Security Engineer (SASE & Zero Trust)Only w2

Astir IT Solutions, Inc. - New Jersey, United States

Hiring: Cloud Security Engineer (SASE & Zero Trust)Only w2 Company: Astir IT Solutions, Inc. Location: New Jersey, United States Job Posted Time: 2026-09-16 16:18:42 Employment Type: Remote Target Skills & Keywords : Azure AD, Bash, DNS, Okta, PKI, PowerShell, Python, SAML, SSL, TCP/IP, TLS, Zero Trust About the job Experience: •10+ Years of Experience required. •3+ years of deep engineering experience explicitly administering Zscaler (ZIA, ZPA, ZDX, and ZCC). Required Skills: •Deployment & Endpoint Orchestration: Package, distribute, and upgrade the Zscaler Client Connector (.msi, .pkg, .deb) silently across thousands of global endpoints utilizing Unified Endpoint Management platforms. •Policy Architecture & Configuration: Configure Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) profiles, including forwarding rules, PAC files, SSL/TLS inspection exclusions, and application segments. •Identity & Authentication Integration: Maintain seamless Single Sign-On (SSO) workflows by configuring Zscaler authentication against Cloud Identity Providers using SAML and SCIM protocols. •L3 Escalation & Troubleshooting: Act as the Tier-3 engineering lead for client connectivity anomalies, certificate chain errors, posture-check failures, and zero-trust routing loop mitigations. •Performance & Performance Optimization: Partner with Network Operations to audit and tune tunnel bypass strategies for performance-critical or latency-sensitive applications. •SASE Platforms: 3+ years of deep engineering experience explicitly administering Zscaler (ZIA, ZPA, ZDX, and ZCC). •Endpoint Management: Proven success scripting deployment strings and managing software delivery packages within Microsoft Intune, Jamf Pro, Tanium, or SCCM. •Scripting & Automation: Strong command of PowerShell, Bash, or Python to interact with administrative CLI tools and pre-configure enterprise policy tokens. Qualifications: •Core Networking: Absolute mastery of DNS architecture, Proxy Auto-Configuration (PAC) file syntax, TCP/IP, routing rules, and packet analysis via Wireshark. Compensation: •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!