Cyber Security Architect - ZTNA

The Depository Trust & Clearing Corporation (DTCC)

Jersey City (NJ)

Hybrid

USD 130,000 - 160,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Comprehensive health and life insurance
Pension / Retirement benefits
Paid Time Off and Personal/Family Care

Job summary

The Depository Trust & Clearing Corporation (DTCC) is looking for a cybersecurity architect to lead the design and implementation of Zero Trust Network Access capabilities. This role involves governance oversight and hands-on technical engagement, ensuring secure access modernization in a regulated financial environment.

Candidates must have over 8 years of experience in cybersecurity and a strong background in identity-centric access controls and security architecture. The position operates under a hybrid work model, combining onsite and remote work.

Qualifications

  • 8+ years of experience in cybersecurity architecture, network security, or security engineering roles.
  • Demonstrated experience designing and implementing Zero Trust architectures in large enterprise environments.

Responsibilities

  • Lead the design and implementation of enterprise Zero Trust Network Access capabilities.
  • Translate security, regulatory, and risk requirements into architectural guardrails.
  • Drive continuous improvement of security posture and performance.

Skills

Zero Trust Architecture
Identity-Centric Access Controls
Network Security
Cybersecurity Engineering
Vendor Management

Education

Bachelor's Degree

Tools

Zscaler
Cisco Security
Akamai Security Solutions

Job description

Are you ready to make an impact at DTCC? Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.

The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high‑quality information through activities that include development of essential building infrastructure capabilities to meet client needs and implementing data standards and governance.

Pay And Benefits
  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well‑being benefits, based on location
  • Pension / Retirement benefits
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well‑being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The Impact You Will Have In This Role

Being a member of IT Cybersecurity and Platform Strategy team, you will lead the design, governance, and implementation of enterprise Zero Trust Network Access (ZTNA) and Secure Service Edge (SSE) capabilities. This role is a hybrid of architecture leadership, governance oversight, and hands‑on technical engagement, supporting secure access modernization across a complex, regulated financial services environment.

Your Primary Responsibilities
Architecture & Strategic Design
  • Define and maintain enterprise ZTNA and SSE target‑state architectures, roadmaps, and transition strategies aligned with DTCC security principles.
  • Establish and document Zero Trust architecture standards, including identity‑centric access, least‑privilege enforcement, continuous verification, and segmentation.
  • Develop and maintain architecture artifacts, including reference architectures and solution patterns, High‑Level Designs (HLDs) and Low‑Level Designs (LLDs), Architecture Decision Records (ADRs).
  • Serve as the design authority for secure access and connectivity initiatives.
Governance, Risk & Control Alignment
  • Translate enterprise security, regulatory, and risk requirements into enforceable architectural guardrails for ZTNA/SSE platforms.
  • Ensure access architectures support policy consistency and traceability, exception management and approvals, periodic access reviews and recertification, audit and regulatory evidence requirements.
  • Participate in architecture review boards, security design reviews, and governance forums as the ZTNA/SSE subject‑matter expert.
Hands‑On Technical Leadership
  • Lead and actively participate in platform design and configuration, proof‑of‑concepts and pilot implementations, migration initiatives (including VPN modernization).
  • Architect and guide implementation of SSE capabilities, including Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Firewall‑as‑a‑Service (FWaaS) where applicable.
  • Integration with Data Loss Prevention (DLP) services.
  • Design secure access models for workforce access to internal and cloud‑hosted applications, third‑party and vendor access, privileged and high‑risk access scenarios.
Multi‑Vendor Platform Architecture
  • Design and maintain solutions across a multi‑vendor ZTNA/SSE ecosystem, including Zscaler, Cisco security and secure access platforms, Akamai enterprise access and edge security services.
  • Perform comparative technical evaluations and develop vendor‑neutral architectural decision frameworks.
  • Lead vendor engagements, technical deep dives, and roadmap assessments.
Operational Readiness & Continuous Improvement
  • Ensure operational integration with SIEM/SOAR platforms, logging, telemetry, and monitoring systems, incident detection and response workflows.
  • Define and track access‑related KPIs and metrics, including reduction in legacy VPN reliance, application onboarding progress to ZTNA, policy exception volumes, access anomaly detection and response effectiveness.
  • Drive continuous optimization of security posture, performance, and user experience.

NOTE: The Primary Responsibilities of this role are not limited to the details above.

Qualifications
  • Bachelor's Degree and/or equivalent experience.
  • 8+ years of experience in cybersecurity architecture, network security, or security engineering roles.
Talents Needed For Success
  • Demonstrated experience designing and implementing Zero Trust architectures in large enterprise environments.
  • Strong expertise in identity‑based access controls (SSO, MFA, conditional access), secure network and application connectivity concepts, hybrid and cloud‑based access architectures.
  • Experience integrating ZTNA/SSE platforms with identity providers (e.g., Entra ID, Okta, Ping), SIEM/SOAR solutions, endpoint security and posture signals.
  • Ability to operate effectively across strategy, governance, and hands‑on execution.
Preferred / Recommended Qualifications
  • Architecture and/or implementation experience with Zscaler, Cisco security and networking platforms, Akamai enterprise security and access solutions.
  • Familiarity with software‑defined perimeter and segmentation strategies, TLS inspection, certificate management, privacy considerations, SaaS governance and shadow IT risk controls.
  • Professional certifications such as CISSP, CCSP, GIAC, or relevant vendor certifications preferred.
Key Competencies
  • Enterprise security architecture and design
  • Zero Trust and identity‑centric access models
  • Governance and control alignment
  • Vendor and stakeholder management
  • Technical depth with strong documentation discipline
  • Clear communication across technical and non‑technical audiences
Working Relationships
  • Collaborates closely with Network Engineering, Identity & Access Management, Cloud Platforms, Endpoint Security, SOC, GRC, and Application teams.
  • Provides architectural leadership and guidance across technology and risk organizations.

The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Zero Trust & Network Security Manager
Zero Trust & Network Security Manager

Depository Trust & Clearing Corporation • Jersey City (NJ)

Hybrid
USD 140,000 - 190,000
Hybrid work model (3 onsite / 2 remote
Health insurance
Pension/Retirement benefits
+1
Zero Trust & Network Security Manager
Zero Trust & Network Security Manager

The Depository Trust & Clearing Corporation (DTCC) • Jersey City (NJ)

Hybrid
USD 180,000 - 240,000
Director IT Security Engineering
Director IT Security Engineering

The Depository Trust & Clearing Corporation (DTCC) • Tampa (FL)

Hybrid
USD 170,000 - 260,000
Competitive compensation
Comprehensive health and life insuance
Pension / Retirement benefits
+1
Director Cybersecurity Technical Delivery Manager
Director Cybersecurity Technical Delivery Manager

Depository Trust & Clearing Corporation • Tampa (FL)

Hybrid
USD 180,000 - 240,000
Competitive compensation
Health & wellness benefits
Pension/Retirement benefits
+2
Director Cybersecurity Technical Delivery Manager
Director Cybersecurity Technical Delivery Manager

The Depository Trust & Clearing Corporation (DTCC) • Tampa (FL)

Hybrid
USD 150,000 - 190,000
Competitive compensation
Comprehensive health and life insurance
Pension/Retirement benefits
+2
Threat & Vulnerability Senior Associate
Threat & Vulnerability Senior Associate

The Depository Trust & Clearing Corporation (DTCC) • Dallas (TX)

On-site
USD 140,000 - 200,000
Health insurance
Retirement benefits
Hybrid work model
+1
Associate Director Cloud Security Engineering
Associate Director Cloud Security Engineering

The Depository Trust & Clearing Corporation (DTCC) • Tampa (FL)

Hybrid
USD 140,000 - 180,000
Threat & Vulnerability Senior Associate
Threat & Vulnerability Senior Associate

Depository Trust & Clearing Corporation • Dallas (TX)

Hybrid
USD 100,000 - 130,000
Comprehensive health and life insurance
Pension / Retirement benefits
Paid Time Off
Threat & Vulnerability Senior Associate
Threat & Vulnerability Senior Associate

Depository Trust & Clearing Corporation • Coppell (TX)

Hybrid
USD 95,000 - 125,000
Comprehensive health insurance
Pension/Retirement benefits
Paid Time Off
+1
Associate Director Cloud Security Operations
Associate Director Cloud Security Operations

The Depository Trust & Clearing Corporation (DTCC) • Tampa (FL)

Hybrid
USD 140,000 - 200,000
Competitive compensation
Health insurance
Pension / Retirement benefits
+1