Type of Requisition:
IncumbentClearance Level Must Currently Possess:
NoneClearance Level Must Be Able to Obtain:
NonePublic Trust/Other Required:
NACI (T1)Job Family:
Cyber and IT Risk ManagementJob Qualifications:
Skills:
Cloud Network Architecture, Network Architecture, SCIM (Inactive), Security Assertion Markup Language (SAML), Zscaler ArchitectureCertifications:
NoneExperience:
10 + years of related experienceUS Citizenship Required:
NoJob Description:
We are seeking a highly skilled Senior Zscaler Engineer / Secure Access Service Edge (SASE) Subject Matter Expert (SME) to support the Health Resources and Services Administration (HRSA). This role will lead the design, implementation, and operational support of Zscaler Internet Access (ZIA), Single Sign-On (SSO), and other SASE technologies, ensuring HRSA’s cloud and network security posture is aligned with federal security mandates and best practices.
Key Responsibilities:
- Serve as the SME for SASE technologies; provide architectural guidance for new initiatives and support existing infrastructure.
- Perform upgrades and updates (major and minor) for Zscaler solutions; generate reports and implement security blocks as needed.
- Troubleshoot complex issues within the SASE solution stack, including hardware, software, and network-related problems.
- Configure and maintain Single Sign-On (SSO) integration with HRSA’s Identity Provider (Okta) for Zscaler Internet Access (ZIA), ensuring proper SAML attribute and SCIM configuration.
- Develop troubleshooting playbooks for endpoint Zscaler client application issues; support HRSA server and desktop support teams.
- Conduct Best Practices Assessments and Security Lifecycle Reviews for Zscaler technologies.
- Provide recommendations to strengthen HRSA’s security posture and assist in implementing new rulesets based on evolving security and networking requirements.
- Create and maintain ZIA security policies (SSL inspection, URL filtering, DLP, app control, threat protection) in collaboration with the Office of Information Security and Privacy (OISP).
- Develop and deliver ad-hoc Zscaler reports for leadership and stakeholders.
- Ensure all changes and updates follow HRSA’s Change Management Process with full documentation.
- Meet SLA commitments by responding to change requests/tickets within two (2) business days.
- Implement and support RSA SecurID / RSA Authentication Manager solutions, including integration with VPNs, RADIUS, and enterprise authentication systems
Design, implement, and troubleshoot IPv4 and IPv6 network architectures, ensuring seamless integration and scalability across environments
Provides innovative methods and technical solutions using the engineering design process.
Collaborate closely with Project Managers, engineers, and stakeholders to deliver complex network projects on time and within scope
Analyze customer and business requirements to develop technical solutions for complex networking challenges
Required Qualifications:
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field (or equivalent experience).
- 10+ years of hands-on experience administering and engineering Zscaler platforms (ZIA, ZPA, ZDX).
- Strong knowledge of Secure Access Service Edge (SASE) concepts and architecture.
- Experience integrating Okta (or other IDPs) with Zscaler using SAML/SCIM.
- Proven expertise in policy creation: SSL inspection, URL filtering, DLP, CASB, and advanced threat protection.
- Strong background in networking (TCP/IP, DNS, VPNs, firewalls) and troubleshooting end-to-end connectivity.
- Experience in federal or enterprise-scale IT environments with strict compliance and uptime requirements (99.9%+).
- Familiarity with federal security standards (NIST 800-53, TIC 3.0, CISA BODs).
- Excellent communication, documentation, and collaboration skills.
Preferred Qualifications:
- Zscaler Certified Cloud Professional (ZCCP) or Zscaler Certified Cloud Administrator (ZCCA).
- Okta Certified Professional or higher.
- Experience supporting federal agencies or healthcare IT environments.
- Prior experience in Security Lifecycle Review (SLR) workshops with Zscaler.
- Knowledge of automation and reporting tools (e.g., APIs, Splunk, PowerShell, or Python).
Why Join:
This position offers the opportunity to be the lead SASE and Zero Trust security engineer for a federal health agency, shaping cloud security strategies that directly support HRSA’s mission to improve access to healthcare nationwide.
Location: Onsite: Rockville, MD
Clearance:
Ability to obtain a Public Trust: candidate must have lived in the United States for at least three (3) out of the last five (5) years and pass a public trust background investigation.
What GDIT can offer you:
- Full-flex work week.
- 401K with company match.
- Customizable health benefits packages.
- Collaborative teams of highly motivated critical thinkers and innovators.
- Internal mobility team dedicated to helping you own your career.
- Rewards program for high-performing employees.
Scheduled Weekly Hours:
40Travel Required:
NoneTelecommuting Options:
OnsiteWork Location:
USA MD RockvilleAdditional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.
Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.
About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.Join our Talent Community to stay up to date on our career opportunities and events atgdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected VeteransLearn more about this Employer on their Career Site
