This is what Zscaler is doing. I know because my company was (unfortunately) using this.
Awful company with 0 protections against being abused. They can't handle stopping a DDoS originating from their service I can't imagine them being trustworthy for a full MiTM.
This is what Zscaler is doing. I know because my company was (unfortunately) using this.