Zscaler Subject Matter Expert
NexThreat · Washington, DC, US
Apply directly on NexThreat’s careers site — no account needed.
About the role
Zscaler Subject Matter Expert – Zero Trust & Identity Security
Location: Washington, D.C.
Employment Type: Full-Time
Work Arrangement: On-Site
Security Clearance: Active Top Secret clearance required; candidates must be CI polygraph eligible
Position Overview
Our partner is seeking an experienced Zscaler Subject Matter Expert (SME) to lead the design, implementation, integration, optimization, and operational support of enterprise Zero Trust and Identity, Credential, and Access Management solutions.
This position will serve as the primary technical authority for Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zscaler Digital Experience (ZDX). The Zscaler SME will work closely with identity, endpoint, cloud, network, and cybersecurity teams to modernize enterprise access architectures and advance federal Zero Trust initiatives.
Ideal Candidate
The ideal candidate is a hands-on security engineer and technical leader with deep experience in Zscaler technologies, Zero Trust Network Access, Microsoft Entra ID, Conditional Access, enterprise application integration, cloud security, endpoint management, and identity-driven security. This individual will be capable of leading solution design while also performing hands-on implementation, troubleshooting, and operational support. The successful candidate will understand federal cybersecurity requirements and be able to deliver secure, scalable Zero Trust and identity solutions across complex enterprise environments. Experience supporting federal government, defense, or classified environments is strongly preferred.
Key Responsibilities Zscaler Architecture and Engineering
· Serve as the primary technical SME for Zscaler ZIA, ZPA, and ZDX.
· Design, implement, optimize, and sustain enterprise Zscaler deployments supporting Zero Trust access strategies.
· Configure identity-based policy enforcement, application segmentation, secure access controls, traffic forwarding, and routing policies.
· Develop and maintain Zscaler security policies aligned with enterprise and federal cybersecurity standards.
· Troubleshoot complex authentication, connectivity, application access, performance, and policy-enforcement issues.
· Support migration from legacy VPN and perimeter-based security architectures to modern Zero Trust Network Access solutions.
· Provide technical guidance, architecture documentation, operational procedures, and implementation recommendations.
Identity, Credential, and Access Management
· Lead the configuration, integration, troubleshooting, and sustainment of enterprise ICAM platforms.
· Support identity-modernization initiatives aligned with:
o NIST SP 800-53
o NIST SP 800-63
o DoD Zero Trust Strategy
o Federal Identity, Credential, and Access Management architecture
o Federal Zero Trust directives, including OMB M-22-09
· Design and support identity governance, authentication hardening, privileged access management, access reviews, and identity lifecycle processes.
· Configure and maintain Microsoft Entra ID capabilities, including:
o Conditional Access
o Authentication Method Policies
o Identity Protection
o Privileged Identity Management
o Access Reviews
o Identity Governance controls
Enterprise Applications and Authentication
· Configure, integrate, and support Enterprise Applications within Microsoft Entra ID.
· Design secure application integrations using:
o SAML 2.0
o OAuth 2.0
o OpenID Connect
o SCIM
o REST APIs
· Support application onboarding, application registrations, connector configurations, service principals, and access-policy development.
· Integrate identity providers, device signals, and access controls with Zscaler policies and application-access workflows.
· Support authentication-modernization initiatives involving:
o Multifactor authentication
o Passwordless authentication
o PKI
o CAC/PIV
o FIDO2
o Certificate-based authentication
Cloud and Enterprise Integration
· Integrate ICAM and Zero Trust services across cloud, hybrid, SaaS, and multi-domain environments.
· Support secure deployments within:
o Microsoft Azure
o Amazon Web Services
o Microsoft 365 GCC and GCC High
o Impact Level 5 and Impact Level 6 environments
o Classified environments, as applicable
· Design identity-driven access solutions for enterprise SaaS and internally hosted applications.
· Collaborate with cloud, network, endpoint, application, and cybersecurity teams to implement enterprise Zero Trust architectures.
Endpoint Security and Device Management
· Support engineering and policy development for Microsoft Intune and other modern endpoint-management solutions.
· Configure and maintain:
o Device compliance policies
o Configuration profiles
o Security baselines
o Application deployments
o Certificate trust architectures
· Integrate device-compliance signals with Microsoft Entra Conditional Access and Zscaler policy enforcement.
· Support SCEP and PKCS certificate deployments and enterprise certificate lifecycle management.
Automation and Operational Excellence
· Develop and maintain automation solutions using:
o PowerShell
o Microsoft Graph API
o Azure Automation
o Power Automate
o Power Apps
· Automate provisioning, deprovisioning, identity lifecycle workflows, reporting, compliance monitoring, and access reviews.
· Develop dashboards, health-monitoring solutions, technical documentation, standard operating procedures, and operational runbooks.
· Establish repeatable engineering and sustainment processes that improve operational efficiency, security, and governance.
Required Qualifications
· Active Top Secret security clearance.
· Must be eligible to obtain a Counterintelligence polygraph.
· Ability to work full-time on-site in Washington, D.C.
· Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Engineering, or a related discipline perferred. Equivalent professional experience may be considered.
· Experience supporting enterprise identity, cybersecurity, cloud, network security, or related technical environments.
· Hands-on experience with:
o Zscaler Internet Access
o Zscaler Private Access
o Microsoft Entra ID
o Conditional Access
o Enterprise Application integrations
· Strong understanding of:
o Zero Trust architecture
o Zero Trust Network Access
o Identity and Access Management
o Authentication and authorization protocols
o SaaS security architectures
o Cloud security best practices
· Experience configuring and troubleshooting SAML, OAuth, OIDC, SCIM, PKI, and certificate services.
· Demonstrated ability to diagnose complex identity, access, network, application, and security-policy issues.
· Strong written and verbal communication skills.
Preferred Qualifications
· Hands-on experience with Zscaler Digital Experience.
· Experience supporting federal government, Department of Defense, Intelligence Community, or other classified environments.
· Familiarity with NIST SP 800-53, NIST SP 800-63, DoD Zero Trust guidance, FICAM, and federal ICAM modernization initiatives.
· Experience with:
o Microsoft Entra Application Proxy
o Microsoft Defender for Identity
o Microsoft Defender for Cloud Apps
o Microsoft Intune
o Azure Automation
o Microsoft Graph API
o Microsoft Power Platform
· Experience supporting GCC, GCC High, IL5, or IL6 environments.
· Experience integrating device posture, identity risk, and authentication signals into access-control decisions.
· One or more relevant certifications, such as:
o Zscaler Certified Cloud Administrator
o Zscaler Certified Cloud Professional
o Zscaler Certified Sales Professional
o Microsoft Certified: Identity and Access Administrator Associate (SC-300)
o Microsoft Certified: Azure Security Engineer Associate (AZ-500)
o Microsoft 365 Certified: Endpoint Administrator Associate (MD-102)
o Certified Information Systems Security Professional
o Certified Cloud Security Professional
Key Competencies
· Advanced expertise with Zscaler ZIA, ZPA, and ZDX.
· Strong knowledge of Zero Trust principles and enterprise security architectures.
· Advanced knowledge of Microsoft Entra ID and Conditional Access.
· Experience modernizing enterprise identity and authentication environments.
· Strong PowerShell and Microsoft Graph API automation skills.
· Excellent troubleshooting, analytical, and problem-solving abilities.
· Ability to communicate effectively with engineers, security teams, program leadership, customers, and other stakeholders.
· Ability to develop architecture diagrams, engineering documentation, implementation plans, operational procedures, and technical guidance.
Our partner is an equal opportunity employer. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law.
Pay: $140.00 - $170.00 per hour
Benefits:
- 401(k)
- Dental insurance
- Health insurance
- Vision insurance
Work Location: In person
Description sourced from the public Indeed listing — this role isn't indexed from the company's career page yet.
Never be applicant #200 again
Every job here is indexed straight from company career pages — often hours after it opens, before it reaches the big boards. Create a free account and get your best matches in a twice-daily digest.
- Your best matches, twice a day
- No duplicates, no ghost jobs, no recruiter spam
- Every job free to browse — pay only when you apply
Free account — no card required
93 160 live jobs · 17 643 companies tracked · 6 168 added today