02 Sep
|
RONIN Dynamics
|
Sydney
02 Sep
RONIN Dynamics
Sydney
Senior Security Engineer, Zero Trust Access (Zscaler ZPA)
Sydney or Melbourne - Hybrid (1-3 days per week)
If your Zscaler experience is URL filtering, SSL inspection and cloud app control, this is not your role.
We are looking for the other kind of Zscaler person. The one who has stood up App Connectors, built application segments, written access policy from a blank page, and lived through the part of a VPN decommissioning where the last forty legacy applications refuse to move.
The organisation A large Australian enterprise with a complex hybrid estate, thousands of staff and contractors, and an internal application landscape that has accumulated over decades. Zscaler is already in place. What is missing is a single owner for the private access side of it.
What you will own
You are the person accountable for Zscaler Private Access end to end. Not a ticket queue, and not one work stream inside someone else's programme.
- Application discovery across the estate, including the systems nobody documented and the ones a business unit stood up quietly six years ago
- The access policy model itself: who reaches what, from which devices, in what posture, and how employees, contractors and third parties are treated differently
- App Connector architecture, placement and resilience across on-premises and cloud environments
- Segment groups, server groups, client forwarding policy and posture profiles, designed as a coherent standard rather than assembled case by case
- The onboarding standard that application owners follow, and the exception and change process that sits around it
- Ongoing access review, reporting and the evidence trail that stands up to audit
- Driving the retirement of legacy remote access, and holding the line when someone senior asks for a bypass
What we are looking for
- Demonstrable hands-on ownership of Zscaler Private Access at enterprise scale, not exposure to it inside a wider platform role
- Evidence you designed the policy rather than executed someone else's design
- A network security lineage. Firewalls, routing, traffic inspection and segmentation thinking, rather than a purely Microsoft security background
- Experience taking applications off a VPN and the political reality that comes with it
- The ability to write it down properly. Design documentation, configuration standards, runbooks and operational handover material that other engineers can actually work from
- Confidence holding a technical position in front of application owners and senior stakeholders who want an exception
- Zscaler certification (ZCCA-PA or above) is a solid signal, though delivery evidence matters more than the certificate
Adjacent micro-segmentation experience will be viewed favourably. The disciplines are close relatives.
What this role is not
Worth being direct, because it saves everyone time.
- Not a secure web gateway or proxy administration role
- Not a governance, risk and compliance role. This is technical policy ownership, not framework and audit work
- Not a broad platform engineering role covering endpoint, email and mobile device management. The scope here is deliberately narrow and deep
Why it is worth a conversation
Single-platform ownership roles at this scale are rare. Most organisations either spread the work across four engineers who each own a slice, or hand it to an integrator who builds it and leaves.
This one is yours to own, with the mandate and the seniority to make decisions rather than recommend them.
Applying
Apply through this advert, or contact Will at RONIN directly for a confidential conversation. Happy to talk through the detail before you decide whether it is worth your time.
📌 Senior Security Engineer (Sydney)
🏢 RONIN Dynamics
📍 Sydney