安全工程师 - Zscaler
Security Engineer - Zscaler
Overview/ Job Responsibilities
美国网络安全和基础设施安全局(CISA)的使命是领导国家努力保护并增强国家物理和网络基础设施的韧性。CISA包括CISA任务支持办公室(MEO)以及六个部门:网络安全部(CSD)、应急通信部(ECD)、综合运营部(IOD)、基础设施安全部(ISD)、利益相关者参与部(SED),以及总部位于国家首都地区(NCR)的国家风险管理中心(NRMC)。
CISA的信息技术(IT)环境历史上由各个部门以及MEO分别独立管理和维护网络和系统。此任务订单旨在为CISA/OCIO提供企业工程和运维支持服务(EEOSS),以建立企业IT能力。这些企业IT能力将支持CISA持续构建现代IT基础设施;开展各种计划以评估和实施新兴技术;迁移到云端;支持移动和协作平台;并持续提升企业IT服务的性能、安全性和可用性。
与支持我们联邦客户的 enterprise 网络架构、工程和实施团队一起工作,安全工程岗位将专注于提供 Zscaler 工程支持,并负责实施 ZScaler 解决方案,以管理 CISA 用户与云环境之间的连接,应用 IT 安全治理政策以防止数据泄露,确保 SaaS 应用程序的合规性,并推动不同任务和 IT 组之间的管理、功能和报告方面的创新。
主要职责:
- Zscaler 工程师负责 ZScaler 互联网(TIC)和私有访问(VPN 替代)解决方案的工程、设计、测试和实施。
- 在过渡到运营之前,支持制定与相关功能需求文档和 DDD 一致的网络架构技术需求文档和详细设计文档(DDD)。
- 开发和维护支持 24/7/365 网络运营中心(NOC)的监控流程和程序。
- 当网络设计发生变化时,支持所有文档的更新。
查看英文原文
Overview/ Job Responsibilities
The U.S. Cybersecurity and Infrastructure Security (CISA) mission is to lead the national effort to protect and enhance the resilience of the nation’s physical and cyber infrastructure. CISA includes the CISA Mission Enabling Offices (MEOs) and six Divisions: the Cybersecurity Division (CSD), the Emergency Communications Division (ECD), the Integrated Operations Division (IOD), Infrastructure Security Division (ISD), the Stakeholder Engagement Division (SED), as well as, the National Risk Management Center (NRMC), which are headquartered within the National Capital Region (NCR).
CISA’s information technology (IT) landscape has historically produced networks and systems individually managed and maintained within each of its Divisions as well as its MEOs. This task order is to provide Enterprise Engineering and Operations Support Services (EEOSS) to CISA/OCIO to establish enterprise IT capabilities. These enterprise IT capabilities shall support CISA’s ability to continue establishing a modern IT infrastructure; engaging in various initiatives to evaluate and implement emerging technologies; migrating to the cloud; supporting mobility and collaboration platforms; and continually improving the performance, security, and availability of enterprise IT services.
Working with an enterprise network architecture, engineering, and implementation team supporting our Federal customer, the Security Engineering role will focus on providing Zscaler Engineering support and will be responsible for implementing the ZScaler solutions to manage connections between CISA users and cloud environments, applying IT Security Governance policies to prevent data exposure, ensure compliance across SaaS applications, and drive innovation for management, functionality, and reporting between disparate mission and IT groups.
Primary Responsibilities:
- The Zscaler Engineer is responsible for the engineering, design, test, and implementation of ZScaler internet (TIC) and private access (VPN replacement) solution.
- Support of the development of the Technical Requirements Document and a Detailed Design Document (DDD) for the network architecture, consistent with the associated Functional Requirements Document and DDD, before transitioning to Operations.
- Development and maintenance of monitoring processes and procedures supporting a 24/7/365 Network Operations Center (NOC).
- Support of all updates to all documents when there is change in the network design and/or technologies and collaborating with all stakeholders to test all related systems and application migration processes to verify that the systems meet requirements and can host applications with no degradation to performance or security.
- Preparation of test reports and Implementation Plans for each change impacting the network environment
- Implements the ZScaler solution across an enterprise.
- Implements Data Loss Prevention (DLP) practices and policies.
- Managing user access controls in cloud environments.
- Serves as a Subject Matter Expert in the advanced CASB, DLP, API, SD-WAN, and location implementation and best practices around those implementations.
- Provides internal consulting, technical guidance, information and support to application developers, computer operations, company management and departmental clients. Assists in internal training programs
- Must be able to work with minimal supervision and possess excellent written and verbal communication skills
Minimum Qualifications
Bachelors AND 5 years' experience OR 9 years' experience in lieu of a degree.
- Requires hands-on experience in Network Design, Network Engineering, Network Operational Support, and cloud engineering experience of Medium to Large enterprise network environments.
- Experience implementing the ZScaler CASB solution in an enterprise.
- Experience with Zscaler or related Data Loss Prevention (DLP) practices and policies.
- Experience with managing user access controls in cloud environments.
- Experience with ServiceNow, Jira, VMware vCenter, cloud computing concepts
- Experience with cloud reporting with preparation for both internal and executive stakeholders
- Experience migrating from legacy on-prem networking to the cloud networking
- Experience with traditional on-premises proxies
- Experience with cloud-based proxy concepts
- Experience with Cloud Identity and Access Management
- Experience deploying and managing virtual servers on premise and in the cloud
- Experience with concepts and operations of cloud-based on physical load balancers
- Experience with implementing and exporting audit trails
- Experience with cloud-based monitoring solutions
Must be eligible to obtain a Department of Homeland Security EOD clearance (Requirements 1. US Citizenship, 2. Favorable Background Investigation)
Other Duties: Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
Desired Qualifications
Clearance Preference:
- DHS EOD - 1st priority
- Any DHS badge + DoD Top Secret or Secret - 2nd choice
- DoD Secret or Top Secret + willingness to get EOD clearance - 3rd choice (it can take 45 days to obtain EOD clearance – work can only begin once the clearance is fully adjudicated)
About Us
Formed through the strategic union of Sev1Tech and ERT, Entarian is a premier provider of mission-critical engineering and technology solutions. Founded on a legacy of excellence dating back to 1993, Entarian is a product of an evolved and fully diversified engineering and federal technology leader. From deep space to defense and civilian missions, Entarian delivers secure, mission-aligned digital solutions that drive national resilience and operational effectiveness. We don't just support modernization; we define it.
Join the Mission and Start your Career Journey: Apply Directly via our Careers Portal Connect,Referrals & Inquiries?Email the team:
Entarian is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
Originally posted on Himalayas