Zero Trust Security Engineer
The job description
Tech stack. ZTNA platforms (Zscaler, Cloudflare Access), identity-aware proxies, Okta or Entra ID conditional access, device posture (CrowdStrike, Jamf), microsegmentation, Python, policy simulation tools
About the role
You will drive the zero trust transformation at a technology company migrating away from perimeter-based VPN security toward identity-centric access for everyone. The team builds identity-aware access where every request is authenticated, authorized, and encrypted regardless of network location or device ownership. You will migrate applications, define access policy, and prove to skeptical application owners that the new model is both safer and smoother. This role matters because the network perimeter is gone for good; identity and device posture are the new boundary, and you are building the system every employee and service will depend on daily. You will also define the metrics proving risk reduction, from VPN elimination percentages to mean time to revoke access, and report them monthly.
What you will achieve
- Migrate 70 percent of internal applications to identity-aware proxy access, retiring legacy VPN dependencies application by application with zero user-facing outages.
- Enforce device posture checks on every access decision, automatically blocking non-compliant or unknown endpoints before they can connect.
- Design microsegmentation policies limiting east-west traffic to explicitly authorized service pairs, verified continuously by automated testing.
- Cut standing privileged access 60 percent by pairing just-in-time elevation with comprehensive session recording and review.
- Publish zero trust reference architectures and migration playbooks that product teams adopt without requiring custom security reviews.
What you will bring
Must-haves
- 2 to 5 years in network security, identity engineering, or infrastructure security roles.
- Hands-on experience with ZTNA, SDP, or identity-aware proxy technologies deployed in production.
- Strong understanding of SSO protocols: SAML, OIDC, and OAuth2 flows including their real-world failure modes.
- Experience designing conditional access policies and enforcing device compliance at organizational scale.
- Networking fundamentals solid enough to design segmentation and access policy correctly.
- Ability to drive adoption with application owners who never asked for a migration, through patience, evidence, and proof.
- Troubleshooting skill spanning identity, network, and endpoint layers when access breaks.
Nice-to-haves
- Zscaler, Cloudflare, or identity vendor certifications.
- Experience applying NIST SP 800-207 zero trust architecture principles.
- Familiarity with service mesh identity such as SPIFFE/SPIRE or Istio.
- Background in change management for large infrastructure migrations.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta