Powered by pgvector · cosine kNN
RONIN Dynamics
About the role
Senior Security Engineer, Zero Trust Access (Zscaler ZPA)
Sydney or Melbourne - Hybrid (1-3 days per week)
If your Zscaler experience is URL filtering, SSL inspection and cloud app control, this is not your role.
We are looking for the other kind of Zscaler person. The one who has stood up App Connectors, built application segments, written access policy from a blank page, and lived through the part of a VPN decommissioning where the last forty legacy applications refuse to move.
The organisationA large Australian enterprise with a complex hybrid estate, thousands of staff and contractors, and an internal application landscape that has accumulated over decades. Zscaler is already in place. What is missing is a single owner for the private access side of it.
What you will ownYou are the person accountable for Zscaler Private Access end to end. Not a ticket queue, and not one work stream inside someone else's programme.
Application discovery across the estate, including the systems nobody documented and the ones a business unit stood up quietly six years agoThe access policy model itself: who reaches what, from which devices, in what posture, and how employees, contractors and third parties are treated differentlyApp Connector architecture, placement and resilience across on-premises and cloud environmentsSegment groups, server groups, client forwarding policy and posture profiles, designed as a coherent standard rather than assembled case by caseThe onboarding standard that application owners follow, and the exception and change process that sits around itOngoing access review, reporting and the evidence trail that stands up to auditDriving the retirement of legacy remote access, and holding the line when someone senior asks for a bypass
What we are looking forDemonstrable hands-on ownership of Zscaler Private Access at enterprise scale, not exposure to it inside a wider platform roleEvidence you designed the policy rather than executed someone else's designA network security lineage. Firewalls, routing, traffic inspection and segmentation thinking, rather than a purely Microsoft security backgroundExperience taking applications off a VPN and the political reality that comes with itThe ability to write it down properly. Design documentation, configuration standards, runbooks and operational handover material that other engineers can actually work fromConfidence holding a technical position in front of application owners and senior stakeholders who want an exceptionZscaler certification (ZCCA-PA or above) is a strong signal, though delivery evidence matters more than the certificate
Adjacent micro-segmentation experience will be viewed favourably. The disciplines are close relatives.
What this role is notWorth being direct, because it saves everyone time.Not a secure web gateway or proxy administration roleNot a governance, risk and compliance role. This is technical policy ownership, not framework and audit workNot a broad platform engineering role covering endpoint, email and mobile device management. The scope here is deliberately narrow and deep
Why it is worth a conversationSingle-platform ownership roles at this scale are rare. Most organisations either spread the work across four engineers who each own a slice, or hand it to an integrator who builds it and leaves.
This one is yours to own, with the mandate and the seniority to make decisions rather than recommend them.
ApplyingApply through this advert, or contact Will at RONIN directly for a confidential conversation. Happy to talk through the detail before you decide whether it is worth your time.
Your match
See how you fit
Scored against this job in seconds
Your account
Sign in to apply
Your profile and your match for this job appear right here.
By continuing you agree to our Terms and Privacy Policy.
Next step
Apply for this role
via LinkedIn — opens their site
Applications via LinkedIn
Your job hunt, handled
Ask about any role and get a straight answer on your fit. Then stop searching: new matches land in your WhatsApp the moment they’re listed.
Free for jobseekers
N2S.Global
We are seeking an experienced Security Architect with deep expertise in Citrix Secure Private Access (SPA), Zero Trust Network Access (ZTNA), and modern secure access architectures. This role will be responsible for d…
Showtime Consulting
Company Description Showtime Consulting is a leading provider of Shielded Cloud and Digital Solutions across Australia and New Zealand. We specialise in delivering secure, enterprise-scale technology solutions across …
N2S.Global
Job SummaryWe are seeking a skilled Security Architect with a strong background in Citrix technologies and Zero Trust Network Access (ZTNA) solutions. The ideal candidate will be responsible for designing and implemen…
3Columns
Company Description 3Columns is a cyber security services provider focused on helping businesses defend against evolving digital threats through innovative, customer-centric solutions. The company is recognised for se…
XPT Software Australia Pty
Key Responsibilities: Design, implement, and manage Microsoft Zero Trust solutions including Conditional Access, Defender for Identity, Microsoft Entra, and related technologies. Support and optimize ZTNA policies acr…
Tribus
About the Company We're working with a leading global quantitative investment firm looking to add hands-on Security Engineers across Sydney and Hong Kong About the Role This is not a traditional SOC, GRC or purely app…