Overview
In this role you will define and deliver cloud security and secure access architectures across Azure and GCP, aligning with Colt’s Zero Trust strategy. You’ll lead Zscaler implementations (ZIA/ZPA) and integrate identity, access and network controls across hybrid environments. You work with Security Engineering, SOC, Risk and Cloud/Network teams to enable secure, scalable adoption of cloud services. Your work shapes secure, resilient access for a distributed enterprise, with a clear focus on governance and assurance.
Pay / Benefits
- flexible working hours
- work from home option
- extensive induction with mentors
- opportunities for further development
- Global Family Leave Policy
- Employee Assistance Program
Responsibilities
- Act as architecture authority for cloud and secure access (Azure, GCP, Zscaler)
- Define target cloud security and secure access architecture aligned to Zero Trust
- Design secure IaaS/PaaS solutions across networking, compute, storage and identity
- Lead ZIA and ZPA design and implementation for secure user-to-internet and user-to-app access
- Define Zero Trust Network Access patterns replacing traditional VPN models
- Design identity-integrated access controls using Entra ID and SAML/federation
- Ensure integration between Zscaler, identity providers and cloud platforms
- Conduct security architecture reviews and support risk sign-off
- Collaborate with cloud/network teams to implement scalable architecture patterns
- Promote Secure by Design across cloud-native and access solutions
- Align with regulatory/compliance requirements (TSA, DORA, ISO27001)
- Produce architecture artefacts, standards and guidance
Key requirements
- 5+ years of information security in large-scale enterprise or telecoms
- Strong cloud security architecture experience (Azure, GCP)
- Strong Zscaler experience (ZIA, ZPA)
- Strong understanding of ZTNA and modern secure access architectures
- Experience designing IaaS/PaaS security across networking/identity/workloads
- Knowledge of Entra ID, SAML, federation-based access
- Experience security design reviews and translating policy to controls
- Experience risk assessments per recognised frameworks
- Strong networking/security knowledge (segmentation, routing, traffic inspection)
- Ability to translate complex tech into business outcomes
- Experience in hybrid environments integrating cloud/on-prem/SaaS
- Strong stakeholder engagement and communication; team leadership
- Fluent English
- stakeholder engagement
- communication (technical and non-technical)
- team player / cross-functional collaboration
- Azure
- Google Cloud Platform (GCP)
- Zscaler Internet Access (ZIA)
…
