Security Architect - Cloud Security + Zscaler Platform

Colt Technology Services Group Ltd.

Greater London

On-site

GBP 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Flexible working hours
Work from home option

Job summary

Colt Technology Services Group Ltd is seeking a Security Architect specialising in Cloud Security and Secure Access to join the Security and Resilience – Security Architecture team in London. You will drive cloud security design, Zero Trust, and Zscaler deployment across Azure and GCP, ensuring integrated identity and access controls.

The role requires strong stakeholder engagement, experience in hybrid environments, and the ability to translate complex concepts into business outcomes.

Qualifications

  • 5+ years of information security in large-scale enterprises or telecoms.
  • Strong cloud security architecture experience across Azure and GCP.
  • Expertise with Zscaler platform (ZIA/ZPA) and Zero Trust concepts.
  • Solid knowledge of Entra ID, SAML and federation-based access.
  • Experience designing secure IaaS/PaaS solutions with identity, network and workload protection.
  • Understanding of hybrid cloud environments and SaaS integrations.
  • Proven ability to conduct security design reviews and translate policy into technical controls.
  • Experience with risk assessments per recognised frameworks.
  • Fluent English with strong stakeholder communication.
  • Ability to communicate complex concepts to non-technical audiences.

Responsibilities

  • Act as the security architecture authority for cloud and secure access (Azure, GCP, Zscaler).
  • Define target architectures for cloud security and zero trust aligned with Colt principles.
  • Design secure architectures for IaaS/PaaS across networking, compute, storage and identity.
  • Lead ZIA and ZPA deployment enabling secure user-to-internet and user-to-application access.
  • Define ZTNA architectures, reducing reliance on VPN-based access.
  • Design identity-integrated access controls leveraging Entra ID and SAML.
  • Define secure access patterns for internal apps, SaaS and cloud workloads.
  • Ensure integration between Zscaler, Entra ID and cloud platforms for seamless authentication.
  • Conduct security architecture reviews and provide risk/assurance input.
  • Collaborate with cloud and network teams to implement scalable security patterns.

Skills

Cloud security architecture
ZTNA
Zscaler
Entra ID
SAML
Federation
Azure
GCP
Hybrid environments
Security reviews
Stakeholder engagement

Tools

Zscaler
Entra ID

Job description

Select how often (in days) to receive an alert:

Security Architect - Cloud Security + Zscaler Platform

Job id: 36815

Job location: London, GB Barcelona, ES

Colt provides network, voice and data centre services to thousands of businesses around the world, allowing them to focus on delivering their business goals instead of the underlying infrastructure.

Why we need this role

We are looking for a Security Architect specialising in Cloud Security and Secure Access to join the Security and Resilience – Security Architecture team.

This role acts as a subject matter expert across cloud security architecture (IaaS/PaaS) and secure access technologies, with a primary focus on Azure and GCP environments and Colt’s strategic Zscaler platform (ZIA / ZPA).

The successful candidate will work closely with Security Engineering, SOC, Threat Intelligence and Risk functions, as well as wider technology teams (Cloud Engineering, Network Engineering, Service Delivery), to design and implement secure, scalable and Zero Trust-aligned architectures.

The role combines:

  • Security architecture and design across cloud platforms and access layers
  • Security assurance, governance and integration
  • Strategic engagement across Colt’s hybrid technology estate

You will play a critical role in driving:

  • Secure cloud adoption across Azure and GCP environments
  • Zero Trust Network Access (ZTNA) via Zscaler (ZIA / ZPA)
  • Integration of identity, access and network security controls
  • Consistent, secure access to applications, services and data across a distributed enterprise
What you will do
  • Act as the security architecture authority for cloud and secure access solutions, with a focus on Azure, GCP and Zscaler platforms
  • Define and maintain the target architecture for cloud security and secure access, aligned to Colt’s Zero Trust principles
  • Design and implement secure architectures for IaaS and PaaS environments, ensuring appropriate controls across networking, compute, storage and identity layers
  • Lead the design and implementation of Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) solutions to enable secure user-to-internet and user-to-application access
  • Define architectures for Zero Trust Network Access (ZTNA), replacing or reducing reliance on traditional VPN-based access models
  • Design and implement identity-integrated access controls, leveraging Entra ID and federation technologies such as SAML
  • Define secure access patterns for internal applications, SaaS services and cloud-hosted workloads
  • Ensure consistent integration between Zscaler, identity providers (Entra ID) and cloud platforms, supporting seamless authentication and access control
  • Conduct security architecture reviews and provide assurance for cloud and access-related solutions, supporting formal sign-off or risk acceptance processes
  • Work with cloud and network engineering teams to ensure secure and scalable implementation of architecture patterns
  • Support the adoption of Secure by Design principles across cloud-native and access solutions
  • Ensure alignment with regulatory and compliance requirements such as TSA, DORA and ISO27001
  • Define and document standard architecture patterns for cloud security and secure access, including segmentation, identity enforcement and traffic control
  • Assess and mitigate risks associated with cloud-native architectures, including misconfiguration, over-permissioning and insecure exposure of services
  • Engage with vendors (Zscaler, Microsoft, Google) to stay aligned with roadmaps and emerging capabilities
  • Produce high-quality architecture artefacts, standards and guidance documentation
What we’re looking for

Must haves:

  • 5+ years of experience in information security within large-scale enterprise or telecommunications environments
  • Strong experience in cloud security architecture, particularly across:
  • Microsoft Azure
  • Google Cloud Platform (GCP)
  • Strong experience with Zscaler platform, including:
  • Zscaler Internet Access (ZIA)
  • Zscaler Private Access (ZPA)
  • Strong understanding of Zero Trust Network Access (ZTNA) and modern secure access architectures
  • Experience designing secure solutions across IaaS/PaaS environments, including networking, identity and workload protection
  • Good understanding of identity and authentication technologies, including Entra ID, SAML and federation-based access models
  • Experience conducting security design reviews and translating policy into enforceable technical controls
  • Experience performing risk assessments aligned to recognised frameworks
  • Strong understanding of networking and security technologies, including segmentation, routing, secure access and traffic inspection
  • Ability to translate complex technical concepts into clear business-aligned outcomes
  • Experience working in hybrid environments, integrating cloud, on-prem and SaaS services
  • Strong stakeholder engagement and communication skills (technical and non-technical)
  • Strong team player, able to lead initiatives across engineering and architecture teams
  • Fluent in English (technical and non-technical communication)

Might haves:

  • Experience with additional Zscaler capabilities, including:
  • Zscaler Digital Experience (ZDX)
  • Zscaler Deception
  • ZPA Privileged Remote Access (PRA)
  • Experience with AWS cloud platform
  • Experience integrating cloud security with SOC / SIEM platforms
  • Understanding of Telecoms Security Act (TSA) requirements and implementation patterns
  • Experience working in regulated environments such as telecommunications or critical infrastructure
  • Exposure to DevSecOps practices and cloud-native application security
What we offer you:

Looking to make a mark?

At Colt, you’ll make a difference. Because around here, we empower people. We don’t tell you what to do.

Instead, we employ people we trust, who come together across the globe to create intelligent solutions.

Our global teams are full of ambitious, driven people, all working together towards one shared purpose: to put the power of the digital universe in the hands of our customers wherever, whenever and however they want.

We give our people the opportunity to inspire and lead teams, and work on projects that connect people, cities, businesses, and ideas. We want you to help us change the world, for the better.

Diversity and inclusion

  • Inclusion and valuing diversity of thought and experience are at the heart of our culture here at Colt. From day one, you’ll be encouraged to be yourself because we believe that’s what helps our people to thrive. We welcome people with diverse backgrounds and experiences, regardless of their gender identity or expression, sexual orientation, race, religion, disability, neurodiversity, age, marital status, pregnancy status, or place of birth.

Most recently we have:

  • Signed the UN Women Empowerment Principles which guide our Gender Action Plan
  • Trained 60 (and growing) Colties to be Mental Health First Aiders
  • Please speak with a member of our recruitment team if you require adjustments to our recruitment process to support you. For more information about our Inclusion and Diversity agenda, visit our DEI pages .

Our benefits support you through all parts of life, for both physical and mental health.

  • Flexible working hours and the option to work from home.
  • Extensive induction program with experienced mentors and buddies.
  • Opportunities for further development and educational opportunities.
  • Global Family Leave Policy.
  • Employee Assistance Program.
  • Internal inclusion & diversity employee networks.

A global network

  • When you join Colt you become part of our global network. We are proud of our colleagues and the stories and experience they bring – take a look at ‘Our People’ site including our Empowered Women in Tech.


Job Segment: Developer, Network Security, Data Center, Compliance, Technology, Security, Legal

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Specialist
Security Operations Specialist

慨正橡扯 • Greater London

Hybrid
GBP 90,000 - 130,000
Flexible working hours
Work from home option
Extensive induction and development
Specialist, IT Infrastructure Engineering
Specialist, IT Infrastructure Engineering

慨正橡扯 • Greater London

Hybrid
GBP 60,000 - 80,000
Flexible working hours
Extensive induction program
Employee Assistance Program
+1
Zero Trust Security Architect - London
Zero Trust Security Architect - London

Accenture UK & Ireland • Greater London

Hybrid
GBP 105,000 - 135,000
Competitive salary
30 days vacation
Private medical insurance
+1
Senior Specialist Sales Engineer - Data Security
Senior Specialist Sales Engineer - Data Security

Zscaler • United Kingdom

Remote
GBP 70,000 - 110,000
Health plans
Time off plans
Parental leave options
+3
Lead IT Security Engineer (Zscaler)
Lead IT Security Engineer (Zscaler)

The Depository Trust & Clearing Corporation (DTCC) • London

Hybrid
GBP 60,000 - 70,000
Competitive compensation
Comprehensive health and life insurance
Pension
+2
Senior Zscaler Administrator
Senior Zscaler Administrator

KBR, Inc. • Leatherhead

On-site
GBP 75,000 - 95,000
Security Engineer
Security Engineer

OpticoreIT Limited • Greater London

On-site
GBP 83,000 - 120,000
Security Architect (Zero Trust) - DV Cleared
Security Architect (Zero Trust) - DV Cleared

Sanderson Government & Defence • Farnborough

Hybrid
GBP 70,000 - 85,000
Flexible and hybrid working options
Comprehensive benefits package
Senior Security Analyst
Senior Security Analyst

Brookfield Asset Management, Inc. • City Of London

On-site
GBP 70,000 - 110,000
Zscaler Technical Architect
Zscaler Technical Architect

TieTalent • London

Hybrid
GBP 70,000 - 100,000
Competitive salary
Flexible working hours
Professional development opportunities