This is a part-time 1099 engagement to start, with potential for full-time. The roadmap covers the next 12 to 18 months.
We need a senior, hands-on Zscaler engineer to take ownership of the Zscaler platform on one of the more advanced Zero Trust programs in the defense industrial base. Not a greenfield deployment and not a rescue. This is a funded, executive-sponsored program several years in, with ZIA, ZPA, and ZDX in production enterprise-wide, a ratified identity architecture behind it, and a committed roadmap of advanced work in front of it. You'd be the dedicated Zscaler lead, working alongside the program's Identity Architect and embedded with the client's engineering teams.
If you've deployed Zscaler and wished you could go further than "VPN replacement," this is the further.
The client is well past the starting line. Zscaler Client Connector is deployed enterprise-wide. ZIA, ZPA, and ZDX are in production. Browser Access is live for unmanaged and third-party access. The environment runs on Microsoft Entra ID with SCIM and SAML integration into Zscaler, and the architecture formally designates Entra Conditional Access as the policy decision point with Zscaler as the enforcement point. That decision is ratified through a standing governance council, not a slide.
This means you won't spend your first six months arguing about whether Zscaler belongs. You'll spend it advancing a roadmap the client's leadership has already committed to.
You'll partner directly with the program's lead architect, who has been on this account from the original Zscaler implementation through an enterprise Zero Trust strategy engagement and into the current identity architecture program. You'll inherit strong relationships, an executive sponsor who protects the work, and engineering counterparts on the client side who are sharp and engaged. You won't be parachuting in cold.
You'll drive the Zscaler workstream of a multi-year roadmap, recently re-committed with the client's IT leadership. The work ahead includes:
App segmentation at depth. Moving from broad application segments to a granular, inventory-driven segment model tied to the client's application and entitlement catalog. This is design work and build work, in that order.
Clientless and third-party access. Expanding Browser Access and Cloud Browser Isolation so external collaboration with contractors and partners scales without security exceptions.
Branch Connector. Extending Zero Trust to labs and legacy environments full of devices that will never run a client agent.
Cloud Connector and workload security. Bringing cloud workloads (AWS and Azure) under consistent policy, including east-west traffic and the beginnings of a microsegmentation strategy.
Identity-driven enforcement. Tightening the integration between Entra Conditional Access and Zscaler: posture profiles, per-user tunnel architecture for virtual desktop scenarios, and enforcement patterns for new access types such as AI application traffic.
Operational maturity. ZDX-driven experience monitoring, policy hygiene, documentation, and knowledge transfer to the client's engineers. We do the work with their team, not around them.
You'll also be a second set of expert eyes on the broader architecture. The client asks hard questions and rewards people who can answer them at the whiteboard.
7+ years in network security, security engineering, or infrastructure engineering, with deep hands-on Zscaler experience at enterprise scale. ZIA and ZPA are required. ZDX, Browser Access, CBI, Branch Connector, or Cloud Connector experience is a strong plus.
Real fluency in identity integration: Entra ID, Conditional Access, SAML, SCIM, and how identity signals drive access policy. You should be able to explain why the IdP and the enforcement layer are complementary, not competing.
Experience in regulated or defense environments. CMMC, NIST 800-171, GCC High, or FedRAMP familiarity means you'll ramp faster. U.S. citizenship is required because this environment handles CUI. No clearance is needed.
Consulting presence. You'll be client-facing from day one, leading working sessions and writing things people actually read.
Ownership instinct. Small team, no layers. When you see a problem, you name it and bring a fix.
Nice to have: microsegmentation tooling (Illumio or similar), Windows 365 / AVD experience, automation and infrastructure-as-code habits, or prior work as a subcontracted consultant.
MassiveScale.AI is a boutique consultancy focused on secure AI enablement, built on a Zero Trust strategy. It's founded and led by a former enterprise CIO and CISO. We're small by design: senior people, no passengers. Your work ships to production at organizations where it counts, and you'll have a direct hand in shaping the company as we grow. We don't do checkbox security, and we don't do work we're not proud of.
This engagement is steady, well-sponsored, and technically meaty. It's also a front-row seat to where the industry is heading: identity-governed access for humans and AI agents alike, built in one of the most demanding compliance environments there is.
Fill out the form below and attach your resume. We read every application personally and move fast with strong candidates.