Location: London, with travel to client sites as required
A leading global consultancy is looking for an experienced Zero Trust Security Architect to design, deliver and optimise enterprise-scale Zero Trust security architectures for major clients.
You'll work hands-on with leading platforms such as Zscaler and alongside cross-functional teams to shape secure architectures, define strategic roadmaps and support secure transformation across networks, applications and endpoints. This is a client-facing role that combines architecture, hands-on engineering and security leadership, with the chance to deepen your expertise in modern identity-centric, cloud-first security models.
Key responsibilities
Architecture and design
- Lead the design and implementation of Zero Trust architectures for enterprise environments, covering users, devices, applications and data
- Establish secure access patterns using cloud-based security and Zero Trust platforms (e.g. Zscaler ZIA, ZPA, ZDX)
- Create enterprise-wide security blueprints and reference architectures aligned with Zero Trust principles (NIST SP 800-207, CISA)
- Design scalable, identity-centric security controls using SSO, MFA, device posture and least-privilege access models
- Work with networking teams to modernise WAN and remote access using cloud security and SASE frameworks
Implementation and engineering
- Deploy, configure and optimise Zero Trust technologies, including:
- Policy creation and tuning (URL filtering, DLP, CASB, FWaaS)
- App segmentation and connector deployment
- Client Connector configuration and rollout
- Integrate Zero Trust solutions with identity providers (Microsoft Entra ID, Okta), SIEM/SOAR platforms and endpoint tools such as CrowdStrike
- Partner with infrastructure teams to migrate legacy VPN, proxy and firewall solutions to cloud-native Zero Trust models
- Run proof-of-concept evaluations and technical validation sessions
Essential skills and experience
Technical
- 5–10+ years' experience in cyber security architecture or senior engineering roles
- Strong hands-on expertise with:
- Zscaler ZIA, ZPA and ZDX (or similar)
- App Connectors, Cloud Firewall, Cloud Sandbox, DLP and CASB
- Deep understanding of:
- Zero Trust frameworks (NIST SP 800-207, SASE, SSE)
- Identity and access management (Microsoft Entra ID / Azure AD, Okta, Ping)
- Endpoint security (EDR/XDR, device posture assessment)
- Strong communication and stakeholder management
- Ability to translate complex security concepts into business-friendly language
- Experience working within large, matrixed enterprises
- Proven ability to lead cross-functional initiatives
- Zscaler certifications (ZCCA-IA, ZCCA-PA, ZCCP)
- CISSP, CCSP or similar security credentials
- Cloud certifications in Azure, AWS or GCP (highly desirable)
- Certifications from other leading SASE/SSE vendors, such as Palo Alto Networks Prisma or Netskope
- Networking certification such as CCNA or equivalent
What's on offer
- 25 days' annual leave
- Private medical insurance
- Hands-on experience with leading Zero Trust platforms on large-scale enterprise transformation programmes