14 Sep
|
RONIN Dynamics
|
New South Wales
14 Sep
RONIN Dynamics
New South Wales
Job Description
Senior Security Engineer, Zero Trust Access (Zscaler ZPA)
n
Sydney or Melbourne - Hybrid (1-3 days per week)
n
If your Zscaler experience is URL filtering, SSL inspection and cloud app control, this is not your role.
n
We are looking for the other kind of Zscaler person. The one who has stood up App Connectors, built application segments, written access policy from a blank page, and lived through the part of a VPN decommissioning where the last forty legacy applications refuse to move.
n
The organisation
n
A large Australian enterprise with a complex hybrid estate, thousands of staff and contractors, and an internal application landscape that has accumulated over decades. Zscaler is already in place. What is missing is a single owner for the private access side of it.
n
What you will own
n
You are the person accountable for Zscaler Private Access end to end. Not a ticket queue, and not one work stream inside someone else's programme.
n
n
- Application discovery across the estate, including the systems nobody documented and the ones a business unit stood up quietly six years ago
n
- The access policy model itself: who reaches what, from which devices, in what posture, and how employees, contractors and third parties are treated differently
n
- App Connector architecture, placement and resilience across on-premises and cloud environments
n
- Segment groups, server groups, client forwarding policy and posture profiles, designed as a coherent standard rather than assembled case by case
n
- The onboarding standard that application owners follow, and the exception and change process that sits around it
n
- Ongoing access review, reporting and the evidence trail that stands up to audit
n
- Driving the retirement of legacy remote access,
and holding the line when someone senior asks for a bypass
n
n
What we are looking for
n
n
- Demonstrable hands-on ownership of Zscaler Private Access at enterprise scale, not exposure to it inside a wider platform role
n
- Evidence you designed the policy rather than executed someone else's design
n
- A network security lineage. Firewalls, routing, traffic inspection and segmentation thinking, rather than a purely Microsoft security background
n
- Experience taking applications off a VPN and the political reality that comes with it
n
- The ability to write it down properly. Design documentation, configuration standards, runbooks and operational handover material that other engineers can actually work from
n
- Confidence holding a technical position in front of application owners and senior stakeholders who want an exception
n
- Zscaler certification (ZCCA-PA or above) is a robust signal, though delivery evidence matters more than the certificate
n
n
Adjacent micro-segmentation experience will be viewed favourably. The disciplines are close relatives.
n
What this role is not
n
Worth being direct, because it saves everyone time.
n
n
- Not a secure web gateway or proxy administration role
n
- Not a governance, risk and compliance role. This is technical policy ownership, not framework and audit work
n
- Not a broad platform engineering role covering endpoint, email and mobile device management. The scope here is deliberately narrow and deep
n
n
Why it is worth a conversation
n
Single-platform ownership roles at this scale are rare. Most organisations either spread the work across four engineers who each own a slice, or hand it to an integrator who builds it and leaves.
n
This one is yours to own, with the mandate and the seniority to make decisions rather than recommend them.
📌 Senior Security Engineer (New South Wales)
🏢 RONIN Dynamics
📍 New South Wales