Type of Requisition:Incumbent
Clearance Level Must Currently Possess:None
Clearance Level Must Be Able to Obtain:None
Public Trust/Other Required:NACI (T1)
Job Family:IT Infrastructure and Operations
Job Qualifications:Skills:Cisco Firewall, Network Architecture, Zscaler
Certifications:None
Experience:8 + years of related experience
US Citizenship Required:No
Job Description:We are seeking a highly skilled
Senior Zscaler Engineer / Secure Access Service Edge (SASE) Subject Matter Expert (SME) to support the Health Resources and Services Administration (HRSA). This role will lead the design, implementation, and operational support of Zscaler Internet Access (ZIA), Single Sign-On (SSO), and other SASE technologies, ensuring HRSA's cloud and network security posture is aligned with federal security mandates and best practices.
Key Responsibilities:
- Serve as the SME for SASE technologies; provide architectural guidance for new initiatives and support existing infrastructure.
- Perform upgrades and updates (major and minor) for Zscaler solutions; generate reports and implement security blocks as needed.
- Troubleshoot complex issues within the SASE solution stack, including hardware, software, and network-related problems.
- Configure and maintain Single Sign-On (SSO) integration with HRSA's Identity Provider (Okta) for Zscaler Internet Access (ZIA), ensuring proper SAML attribute and SCIM configuration.
- Develop troubleshooting playbooks for endpoint Zscaler client application issues; support HRSA server and desktop support teams.
- Conduct Best Practices Assessments and Security Lifecycle Reviews for Zscaler technologies.
- Provide recommendations to strengthen HRSA's security posture and assist in implementing new rulesets based on evolving security and networking requirements.
- Create and maintain ZIA security policies (SSL inspection, URL filtering, DLP, app control, threat protection) in collaboration with the Office of Information Security and Privacy (OISP).
- Develop and deliver ad-hoc Zscaler reports for leadership and stakeholders.
- Ensure all changes and updates follow HRSA's Change Management Process with full documentation.
- Meet SLA commitments by responding to change requests/tickets within two (2) business days.
- Implement and support RSA SecurID / RSA Authentication Manager solutions, including integration with VPNs, RADIUS, and enterprise authentication systems
- Design, implement, and troubleshoot IPv4 and IPv6 network architectures, ensuring seamless integration and scalability across environments
- Provides innovative methods and technical solutions using the engineering design process.
- Collaborate closely with Project Managers, engineers, and stakeholders to deliver complex network projects on time and within scope
- Analyze customer and business requirements to develop technical solutions for complex networking challenges
Required Qualifications:
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent experience).
- 10+ years of hands-on experience administering and engineering Zscaler platforms (ZIA, ZPA, ZDX).
- Strong knowledge of Secure Access Service Edge (SASE) concepts and architecture.
- Experience integrating Okta (or other IDPs) with Zscaler using SAML/SCIM.
- Proven expertise in policy creation: SSL inspection, URL filtering, DLP, CASB, and advanced threat protection.
- Strong background in networking (TCP/IP, DNS, VPNs, firewalls) and troubleshooting end-to-end connectivity.
- Experience in federal or enterprise-scale IT environments with strict compliance and uptime requirements (99.9%+).
- Familiarity with federal security standards (NIST 800-53, TIC 3.0, CISA BODs).
- Excellent communication, documentation, and collaboration skills.
Preferred Qualifications:
- Zscaler Certified Cloud Professional (ZCCP) or Zscaler Certified Cloud Administrator (ZCCA).
- Okta Certified Professional or higher.
- Experience supporting federal agencies or healthcare IT environments.
- Prior experience in Security Lifecycle Review (SLR) workshops with Zscaler.
- Knowledge of automation and reporting tools (e.g., APIs, Splunk, PowerShell, or Python).
Location: Onsite: Rockville, MD
Clearance:
Ability to obtain a Public Trust: candidate must have lived in the United States for at least three (3) out of the last five (5) years and pass a public trust background investigation.
What GDIT can offer you:
- Full-flex work week.
- 401K with company match.
- Customizable health benefits packages.
- Collaborative teams of highly motivated critical thinkers and innovators.
- Internal mobility team dedicated to helping you own your career.
- Rewards program for high-performing employees.
The likely salary range for this position is $142,792 - $165,600. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Scheduled Weekly Hours:40
Travel Required:None
Telecommuting Options:Onsite
Work Location:USA MD Rockville
Additional Work Locations: