The Role
Serves as the senior technical authority for designing, deploying, administering, and optimizing enterprise Zscaler SASE solutions across hybrid and multi-cloud environments. Responsibilities include ZIA, ZPA, ZDX, Zero Trust policy implementation, security policy tuning, endpoint agent management, identity integration, observability, incident response, Tier 3/4 troubleshooting, documentation, root cause analysis, project support, and 24/7 on-call escalation. The role requires travel within the United States up to 20% of the time.
Summary Generated by Built In
About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Serve as a Senior Network Engineer enabling the Department of Homeland Security (DHS) mission and enterprise network infrastructure. The applicant will serve as the primary technical authority for designing, deploying, administering, upgrading and optimizing enterprise-wide Secure Access Service Edge (SASE) solutions using the Zscaler cloud security platform. This role leads the operational architecture across Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zscaler Digital Experience (ZDX), driving modern Zero Trust initiatives
Required Skills
- The Senior network engineer will be the technical lead performing the following:
Architecture & Engineering: Design, implement, and maintain enterprise Zscaler deployments (ZIA, ZPA, ZDX, and Zscaler Client Connector) across multi-cloud and hybrid corporate environments. - Policy & Governance: Create, audit, and tune security policies, including URL filtering, Cloud Application Control, SSL/TLS deep packet inspection, Data Loss Prevention (DLP), and sandbox policies.
- Zero Trust Deployment: Formulate and execute access policies within ZPA to enable least-privilege direct access to internal applications in private clouds (AWS, Azure, GCP) and on-premises data centers without traditional VPN overhead.
- Operational Troubleshooting: Serve as Tier-3/Tier-4 escalation support for complex proxy routing, PAC (Proxy Auto-Configuration) file debugging, identity integration, authentication drops, and application latency issues.
- Agent Lifecycle Management: Manage enterprise distribution, health checks, profile tuning, and version upgrades of Zscaler Client Connector (ZCC) across macOS, Windows, iOS, and Android platforms.
- Observability & Analytics: Leverage ZDX and cloud analytics to isolate user experience degradation across endpoint, network ISP, and application levels; configure automated alerting and SIEM log integration (Splunk, Cribl).
- Cross-Functional Integration: Partner with Identity and Access Management (IAM) teams to configure SAML/SCIM attributes with IdPs such as Okta, Microsoft Entra ID (Azure AD), or Ping Identity.
- Troubleshooting & Incident Management: Provide Tier 2/Tier 3 escalation support for network outages, circuit degradations, and performance issues; conduct root cause analyses (RCA) and coordinate vendor support.
- Documentation & Asset Management: Maintain accurate network diagrams (Visio), topology maps, inventory databases, standard operating procedures (SOPs), and change control tickets (ServiceNow/Remedy).
- Support On-Call & Escalation Management: support 24/7/365 on-call rotation readiness to respond to Tier 3 critical network incidents within SLA limits and coordinating cross-functional escalation pathways. When needed to restore services, the Senior Network Engineer will provide a solution and implement an Emergency Change Request (ECR), Emergency Break Fix (EBF), or Change Request.
- Root Cause Analysis (RCA) or Post Incident Reporting: Participate in the Root Cause Analysis (RCA) or post incident analysis of problems for mission critical applications, mission essential applications, and mission essential network infrastructure as well as recurring issues on the enterprise IT infrastructure.
- Project Support: Partner with program and project managers to align network engineering deliverables, milestone schedules, and resource planning with enterprise project objectives.
- Excellent problem-solving and analytical skills, with the ability to troubleshoot complex network issues.
- Scheduled and Adhoc Travel: Ability to travel within the United States either on short notice or scheduled, up to 20% of the time.
Preferred Skills
- The Senior network engineer will be the technical lead performing the following:
Architecture & Engineering: Design, implement, and maintain enterprise Zscaler deployments (ZIA, ZPA, ZDX, and Zscaler Client Connector) across multi-cloud and hybrid corporate environments. - Policy & Governance: Create, audit, and tune security policies, including URL filtering, Cloud Application Control, SSL/TLS deep packet inspection, Data Loss Prevention (DLP), and sandbox policies.
- Zero Trust Deployment: Formulate and execute access policies within ZPA to enable least-privilege direct access to internal applications in private clouds (AWS, Azure, GCP) and on-premises data centers without traditional VPN overhead.
- Operational Troubleshooting: Serve as Tier-3/Tier-4 escalation support for complex proxy routing, PAC (Proxy Auto-Configuration) file debugging, identity integration, authentication drops, and application latency issues.
- Agent Lifecycle Management: Manage enterprise distribution, health checks, profile tuning, and version upgrades of Zscaler Client Connector (ZCC) across macOS, Windows, iOS, and Android platforms.
- Observability & Analytics: Leverage ZDX and cloud analytics to isolate user experience degradation across endpoint, network ISP, and application levels; configure automated alerting and SIEM log integration (Splunk, Cribl).
- Cross-Functional Integration: Partner with Identity and Access Management (IAM) teams to configure SAML/SCIM attributes with IdPs such as Okta, Microsoft Entra ID (Azure AD), or Ping Identity.
- Troubleshooting & Incident Management: Provide Tier 2/Tier 3 escalation support for network outages, circuit degradations, and performance issues; conduct root cause analyses (RCA) and coordinate vendor support.
- Documentation & Asset Management: Maintain accurate network diagrams (Visio), topology maps, inventory databases, standard operating procedures (SOPs), and change control tickets (ServiceNow/Remedy).
- Support On-Call & Escalation Management: support 24/7/365 on-call rotation readiness to respond to Tier 3 critical network incidents within SLA limits and coordinating cross-functional escalation pathways. When needed to restore services, the Senior Network Engineer will provide a solution and implement an Emergency Change Request (ECR), Emergency Break Fix (EBF), or Change Request.
- Root Cause Analysis (RCA) or Post Incident Reporting: Participate in the Root Cause Analysis (RCA) or post incident analysis of problems for mission critical applications, mission essential applications, and mission essential network infrastructure as well as recurring issues on the enterprise IT infrastructure.
- Project Support: Partner with program and project managers to align network engineering deliverables, milestone schedules, and resource planning with enterprise project objectives.
- Excellent problem-solving and analytical skills, with the ability to troubleshoot complex network issues.
- Scheduled and Adhoc Travel: Ability to travel within the United States either on short notice or scheduled, up to 20% of the time.
Our Core Values
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
Skills Required
- Senior-level network engineering expertise supporting enterprise network infrastructure
- Design, implementation, administration, and optimization of Zscaler deployments, including ZIA, ZPA, ZDX, and Zscaler Client Connector
- Experience designing and maintaining Zscaler solutions across multi-cloud and hybrid environments
- Ability to create, audit, and tune URL filtering, cloud application control, SSL/TLS inspection, DLP, and sandbox policies
- Experience implementing ZPA least-privilege access policies for cloud and on-premises applications
- Tier 3/Tier 4 troubleshooting of proxy routing, PAC files, identity integration, authentication, and application latency issues
- Experience managing Zscaler Client Connector distribution, health checks, profiles, and upgrades across macOS, Windows, iOS, and Android
- Experience using ZDX and cloud analytics for endpoint, network, ISP, and application performance analysis
- Experience configuring automated alerting and SIEM log integrations with Splunk and Cribl
- Experience integrating SAML and SCIM with Okta, Microsoft Entra ID, or Ping Identity
- Tier 2/Tier 3 incident escalation, network outage troubleshooting, root cause analysis, and vendor coordination
- Ability to maintain Visio network diagrams, topology maps, inventory databases, SOPs, and ServiceNow or Remedy change tickets
- Availability for 24/7/365 on-call rotation and critical incident response
- Excellent problem-solving and analytical skills for complex network troubleshooting
- Ability to travel within the United States up to 20% of the time, including short-notice travel
- Ability to partner with program and project managers on engineering deliverables, milestones, and resource planning
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Agile Defense is a technology services company that provides advanced digital transformation, data analytics, and cybersecurity solutions to support critical national security and civilian government missions. With a global presence, the company focuses on delivering outcome-driven, AI-powered capabilities to solve complex mission challenges for federal and defense customers.








