Hiring.Camp

Senior Zero Trust Network Access (ZTNA) Engineer- Arlington, VA

Costar

·

Today

Salary
$118k – $176k
Location
US-VA Arlington, United States of America
Workplace
Remote, Onsite
Type
Full-time
Department
Engineering
Seniority
Senior
Visa
Not sponsored
Source
Workday

Description

Senior Zero Trust Network Access (ZTNA) Engineer- Arlington, VA


Job Description


 Overview 

CoStar Group (CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces.  Included in the S&P 500 Index, CoStar Group is on a mission to digitize the world’s real estate, empowering all people to discover properties, insights, and connections that improve their businesses and lives.  


We have been living and breathing the world of real estate information and online marketplaces for over 35 years, giving us the perspective to create truly unique and valuable offerings to our customers.  We’ve continually refined, transformed and perfected our approach to our business, creating a language that has become standard in our industry, for our customers, and even our competitors.  We continue that effort today and are always working to improve and drive innovation.  This is how we deliver for our customers, our employees, and investors.  By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate.  

  

This Senior Zero Trust Network Access (ZTNA) Engineer role will augment CoStar’s zero-trust engineering teams, providing expertise in the architecture, implementation, operation, and continuous improvement of the company’s cloud-delivered ZTNA and Security Service Edge (SSE) platforms. This role will directly support CoStar’s global population of 9,000+ employees by helping to provide secure, reliable, and high-performing access to enterprise resources. 

Our team is seeking a Senior Zero Trust Network Access Engineer who combines deep expertise in modern secure access technologies with advanced network troubleshooting skills. This is not solely a ZTNA platform administration role. The successful candidate must understand end-to-end network behavior and independently diagnose complex connectivity, authentication, routing, DNS, performance, and application-access issues across endpoints, enterprise networks, cloud security platforms, identity providers, and applications. This engineer will be a hands-on technical leader who owns critical services from design through production operations, leads difficult troubleshooting efforts, and drives solutions that help the company scale. 

 

This position is in Arlington, VA and  offers a schedule of Monday through Thursday in office, with the option to work from home on Friday. 

 

Responsibilities  

  • Design, deploy, configure, operate, and optimize enterprise Zero Trust Network Access (ZTNA) and Security Service Edge (SSE) platforms, such as Zscaler, Netskope, Cloudflare, Palo Alto Prisma Access, or Cisco Secure Access. 
  • Design and manage ZTNA security and access policies, including traffic steering, application segmentation, policy evaluation, access controls, and performance optimization. 
  • Lead migrations from traditional VPN, on-premises security architectures, and other ZTNA or SaaS solutions to modern cloud-delivered ZTNA platforms while maintaining secure and reliable access. 
  • Serve as a senior technical escalation point for complex connectivity, authentication, routing, application-access, and performance issues. 
  • Lead cross-domain troubleshooting across endpoints, DNS, routing, NAT, proxies, firewalls, identity providers, ZTNA and SSE services, cloud networks, and enterprise applications. 
  • Perform packet-level and session-level analysis using tools such as Wireshark, TCPDump, platform logs, flow records, endpoint telemetry, and digital experience monitoring data. 
  • Diagnose TCP/IP, DNS, DHCP, TLS, MTU and MSS, fragmentation, asymmetric routing, proxy, firewall-session, tunnel, and application-performance issues across end-to-end traffic paths. 
  • Troubleshoot advanced ZTNA and SSE components and features, including PAC files, GRE and IPsec tunnels, App Connectors, Client Connectors, Branch Connectors, private access, internet access, log streaming services, digital experience monitoring, and platform configurations. 
  • Lead technical response during high-impact incidents, coordinating troubleshooting across network, security, endpoint, identity, cloud, and application teams. 
  • Monitor platform health, performance, availability, logs, security events, and user experience; proactively identify issues and drive remediation. 
  • Integrate ZTNA platforms with enterprise identity providers and security platforms, including Entra ID, Okta, multifactor authentication services, and SIEM solutions. 
  • Own technical designs and implementation standards for ZTNA connectivity, traffic steering, private application access, internet access, branch connectivity, and service resilience. 
  • Lead architecture reviews, proofs of concept, technical evaluations, technology refreshes, security migrations, root-cause analyses, and corrective-action planning. 
  • Create and maintain architecture diagrams, engineering standards, standard operating procedures, deployment guides, runbooks, and incident and change records. 
  • Automate operational, monitoring, and reporting tasks using PowerShell, Python, and other infrastructure automation tools. 
  • Collaborate with network, security, systems, cloud, operations, and compliance teams to strengthen the organization’s security posture and service reliability. 
  • Provide technical guidance, design reviews, and troubleshooting mentorship to other engineers while staying current with ZTNA, SSE, networking, identity, and cloud security technologies. 

 

Basic Qualifications 

  • Bachelor’s Degree required from an accredited, not-for-profit, in-person university or college. 
  • A track record of commitment to prior employers. 
  • 7+ years of progressive experience in enterprise networking, network security engineering, or related infrastructure engineering roles. 
  • 3+ years of hands-on experience implementing, operating, and supporting one or more enterprise ZTNA or SSE platforms, such as Zscaler, Netskope, Cloudflare, Palo Alto Prisma Access, or Cisco Secure Access. 
  • Strong experience supporting globally distributed endpoints, users, applications, and networks within a large enterprise. 
  • Expert-level knowledge of TCP/IP, DNS, DHCP, routing, NAT, TLS, proxies, VPN technologies, firewalls, and application traffic flows. 
  • Proven ability to use packet captures, flow data, routing tables, firewall sessions, endpoint telemetry, and platform logs to isolate complex connectivity and performance problems. 
  • Experience troubleshooting across networking, identity, endpoint, cloud, security-platform, and application domains. 
  • Experience leading Tier-3 incident response and root-cause analysis for business-critical services. 
  • Experience independently designing and implementing highly available enterprise network or security services. 
  • Strong analytical, problem-solving, documentation, and communication skills. 
  • Ability to clearly communicate technical findings, risk, and remediation plans to engineering teams and technology leadership. 
  • Ability to independently own services and projects from technical design through implementation, production support, and continuous improvement. 

 

Preferred Qualifications and Skills 

  • Subject matter expertise in one or more enterprise ZTNA or SSE platforms, including Zscaler, Netskope, Cloudflare, Palo Alto Prisma Access, or Cisco Secure Access. 
  • Hands-on experience leading enterprise-scale migrations between ZTNA or SSE platforms or from legacy VPN and on-premises solutions. 
  • Experience integrating ZTNA platforms with Entra ID, Okta, multifactor authentication services, SIEM solutions, and other enterprise security tooling. 
  • Strong proficiency in scripting and automation using PowerShell or Python. 
  • Experience supporting cloud networking environments in Azure, AWS, or Google Cloud Platform. 
  • Experience leading major-incident root-cause analysis and remediation efforts. 
  • Ability to create clear architecture diagrams, operational procedures, technical standards, incident analyses, and recommendations for engineering and leadership audiences. 
  • Relevant industry or vendor certifications, such as Zscaler ZCCA or ZCCP, Netskope NCCSA or NCCSP, Palo Alto PCNSE, Cisco CCNP Enterprise or CCNP Security, or Microsoft Certified: Azure Network Engineer Associate. 

 

What’s in it for You 

When you join CoStar Group, you’ll experience a collaborative and innovative culture working alongside the best and brightest to empower our people and customers to succeed.  We offer you generous compensation and performance-based incentives. CoStar Group also invests in your professional and academic growth with internal training, and tuition reimbursement.


Our benefits package includes (but is not limited to):  

  • Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug  
  • Life, legal, and supplementary insurance  
  • Virtual and in person mental health counseling services for individuals and family  
  • Commuter and parking benefits  
  • 401(K) retirement plan with matching contributions  
  • Employee stock purchase plan  
  • Paid time off  
  • Tuition reimbursement  
  • On-site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes 
  • Access to CoStar Group’s Employee Resource Groups  
  • Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks  

The final salary or hourly rate offered for this role will fall within the range set forth below based on a variety of factors, including but not limited to, geographic location, skills, and competencies. 

Base Compensation: $118,000-$176,000 Annually

 

We welcome all qualified candidates who are currently eligible to work full-time in the United States to apply.  However, please note that CoStar Group is not able to provide visa sponsorship for this position.  


#LI-MC5


CoStar Group is an Equal Employment Opportunity Employer; we maintain a drug-free workplace and perform pre-employment substance abuse testing

Skills

PythonAWSAzureSIEMTCP/IPCompliance

Similar Jobs

15

Director / Senior Director of Engineering, Zero Trust Network Access

Alkira·San Jose, California

2d ago

Senior Zero Trust Security Architect – Special Projects

Etelligentgroup·Bethesda, Maryland +1·Remote

6d ago

Senior Software Engineer, Zero Trust Client

Cloudflare·Hybrid +1·Hybrid

2w ago

Senior Zero Trust Architect / Engineer

Legendcareers·Bridgewater, New Jersey·Hybrid

2w ago

Senior Director, Software Engineering - SSE/SASE & Zero Trust

SonicWall·Pune, Maharashtra·Remote, Hybrid

3w ago

Senior Network Engineer (Security & Zero Trust)

CGM Career·Iasi, Bdul. Chimiei

1mo ago

Senior Zero Trust Systems Engineer

Markon·Fort Meade, MD

2mo ago

Senior Product Marketing Manager, Zero Trust for Agentic AI

Zscaler·San Jose, California·Hybrid

2mo ago

Senior Product Marketing Manager, Zero Trust Cloud

Zscaler·San Jose, California·Hybrid, Onsite

4mo ago

NS-Cloud Network Architect, Senior (Tactical / Hybrid Cloud / Zero Trust)

NETSEA Technologies·APG, US·Remote

5mo ago

Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard·Malvern, PA +1

5mo ago

Senior Specialist, Lead Zero Trust Identity Security Engineering

Vanguard·Malvern, PA +1

5mo ago

Security Architecture / Zero Trust – (Senior) Consultant / Manager 80-100%

Eraneos·Zurich, Switzerland +2

5mo ago

Data Security Engineer (DRM Specialist) – Senior, Zero Trust Program (USSOCOM)

Athenix Solutions Group·MacDill Air Force Base, FL·Hybrid

6mo ago

Senior Midmarket Account Executive: Zero Trust

Antigen Security

1y+ ago