Principal ZTNA Network Engineer – Employee Remote Access
FidelityPrincipal ZTNA Network Engineer – Employee Remote Access
FidelityLocation
Durham, NC
Type
Full-time
Posted
6/24/2026
Compensation
Not listed
Job description
The Senior ZTNA Network Engineer will lead the engineering, deployment, and optimization of secure remote access solutions across the enterprise, focusing on transitioning from legacy VPN technologies to modern Zero Trust architectures. This role is part of the Enterprise Cloud, Infrastructure, and Operations organization, which is dedicated to enhancing the enterprise's remote access strategy. The team operates in a global, 24x7 environment and collaborates closely with security, infrastructure, and business stakeholders to ensure secure access for a distributed workforce. The main focus is on Zscaler-driven Zero Trust transformation and legacy VPN decommissioning.
Requirements
- 6–10 years of network/security engineering experience, including 4+ years in ZTNA or remote access transformations
- Bachelor’s degree in Computer Science, Information Technology, or related field
- Hands-on experience with Zscaler (ZPA/ZIA) or comparable Zero Trust platforms
- Proven success migrating legacy VPNs to Zero Trust, cloud-delivered access solutions
- Deep expertise in ZTNA design, implementation, and Zero Trust principles
- Experience designing application segmentation and identity-based access policies
- Strong knowledge of traffic steering, split tunneling, and secure access routing
- Experience with load balancing, gateways, and access control layers
- Advanced troubleshooting across network layers (L3–L7)
- Familiarity with hybrid environments (on-prem, cloud, SaaS)
- Ability to optimize latency, performance, and user experience in ZTNA environments
- Experience with high availability, disaster recovery, and failover strategies
- Experience with network automation tools (Python, Ansible, APIs)
- Familiarity with endpoint management and deployment tools (Intune, SCCM)
- Strong understanding of identity providers (Azure AD / Entra ID), SSO, and conditional access
- Knowledge of PKI, certificates, and modern authentication methods
- Experience integrating with SIEM, EDR, and security monitoring platforms
- Strong ownership mindset with a focus on execution and delivery
- Ability to thrive in fast-paced, ambiguous environments with competing priorities
- Excellent communication skills across technical and business stakeholders
- Proven ability to lead incident response and drive resolution under pressure
- Preferred certifications: Zscaler (ZCCA / ZCCP / ZCSE), CCNP/CCIE (Security or Enterprise), CISSP (or equivalent), ITIL Foundation
Responsibilities
- Lead design and implementation of ZTNA solutions to replace legacy VPN technologies
- Define and deliver modern Zero Trust architecture patterns, including application-level segmentation and identity-based access
- Drive legacy VPN decommissioning and migration to ZTNA platforms
- Develop and execute engineering roadmaps aligned to enterprise remote access strategy
- Partner with security, infrastructure, and business units to ensure coordinated rollout and adoption
- Document architecture, operational models, and implementation standards
- Evaluate emerging ZTNA and secure access technologies and provide data-driven recommendations
- Lead pilots and phased deployments, including testing, validation, and performance benchmarking
- Act as a Tier-3 escalation lead for complex remote access and connectivity issues
- Ensure high availability and resilience of remote access infrastructure in a 24x7 global environment
- Assess and mitigate risks related to latency, scale, and user experience during migrations
Benefits
- Fidelity offers competitive compensation, annual bonuses, retirement contributions, comprehensive healthcare coverage, parental leave, tuition assistance, wellness programs, and extensive professional development opportunities.
Is this posting expired or inaccurate?
