Senior Zero Trust Architect / EngineerRole OverviewThe Senior Zero Trust Architect / Engineer is responsible for designing, implementing, and governing the organization's Zero Trust security strategy across users, devices, applications, networks, data, and cloud environments. This role serves as a senior technical leader, driving the adoption of modern security architectures that continuously verify trust, minimize attack surfaces, enforce least-privilege access, and protect critical enterprise assets.
The candidate should possess deep expertise in identity security, network security, cloud security, endpoint protection, data protection, and security architecture. This position partners closely with Infrastructure, Cloud, Digital Workplace, Enterprise Applications, Compliance, and Cybersecurity teams to ensure security controls align with business objectives while supporting a modern, flexible workforce.
The ideal candidate will have hands-on experience with Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zero Trust architecture.
Key Responsibilities- Develop and maintain the enterprise Zero Trust architecture roadmap aligned with business and cybersecurity objectives.
- Design and implement security architectures based on NIST Zero Trust Architecture (SP 800-207), CISA Zero Trust Maturity Model, and industry best practices.
- Lead enterprise-wide Zero Trust transformation initiatives across cloud, on-premises, and hybrid environments.
- Define security reference architectures, standards, policies, and design principles.
- Conduct architecture reviews and provide guidance for new technology deployments.
- Architect micro-segmentation and software-defined perimeter solutions.
- Design secure access controls for:
- Corporate networks
- Data centers
- Cloud environments
- Third-party connectivity
- Implement Zero Trust Network Access (ZTNA) technologies.
- Reduce reliance on traditional VPN architectures.
- Lead network access policy modernization initiatives.
- Design and implement security architectures across:
- Collaborate with cloud engineering teams to establish secure landing zones.
- Implement cloud-native security controls and posture management capabilities.
- Evaluate and improve cloud identity and access security.
- Lead implementation of Zero Trust security technologies and integrations.
- Establish security monitoring and continuous verification capabilities.
- Support incident response and threat hunting activities.
- Identify security gaps and remediation opportunities through assessments and architecture reviews.
- Develop automation and orchestration solutions to improve security operations.
- Translate regulatory and compliance requirements into technical security controls.
- Participate in risk assessments and security audits.
- Develop metrics and KPIs to measure Zero Trust maturity and effectiveness.
- Present architecture recommendations and risk findings to senior leadership.
- Strong executive communication and presentation skills.
- Ability to influence stakeholders across business and technical teams.
- Strategic thinker with strong architectural and analytical skills.
- Proven ability to lead complex enterprise transformation initiatives.
- Excellent problem-solving and decision-making capabilities.
Requirements- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
- Master's degree preferred
- Zscaler Certified Administrator (ZCCA)
- Zscaler Certified Professional (ZCCP)
- Microsoft Security certifications
- CISSP, CCSP, Security+, or equivalent certifications
- Microsoft Certified Cybersecurity Architect Expert (SC-100)
- Microsoft Security Operations Analyst (SC-200)
- Azure Solutions Architect Expert
- GIAC Security Certifications
- Network certification
- 10+ years of IT infrastructure, cybersecurity, or security engineering experience.
- 5+ years designing enterprise security architectures.
- 3+ years leading Zero Trust initiatives or enterprise identity modernization programs.
- Experience in highly regulated industries such as biotechnology, pharmaceuticals, healthcare, or financial services preferred.
- Technical Expertise:
- Microsoft Entra ID (Azure AD)
- Microsoft Active Directory (ADDS)
- Conditional Access
- Identity Governance
- Privileged Identity Management (PIM)
- Privileged Access Management (PAM)
- Federation technologies supporting SSO (SAML, OAuth, OIDC)
- Microsoft: Defender, Purview, M365, Intune, MS Graph
- Optional: Sentinel
- Azure
- AWS
- Zero Trust Network Access (ZTNA)
- Secure Web Gateway
- Network Micro-Segmentation
- Zscaler - zia, zpa, zdx
- NIST 800-207
- NIST Cybersecurity Framework
- CISA Zero Trust Maturity Model
- Language(s): English, Mandarin a plus
#Li-FB1
#Li-Onsite
The base pay range below is what Legend Biotech USA Inc. reasonably expects to offer at the time of posting. Actual compensation may vary based on experience, skills, qualifications, and geographic location. The company reserves the right to modify this range as needed and in accordance with applicable laws.
Other Types of Pay: Performance-based bonus and/or equity is available to employees in eligible roles.
Benefits and Paid Time Off: Medical, dental, and vision insurance as well as a 401(k) retirement plan with a company match that vests fully on day one. We offer eight (8) weeks of paid parental leave after just three (3) months of employment, and a paid time off policy that includes vacation time, personal time, sick time, floating holidays, and eleven (11) company holidays. Additional voluntary benefits include flexible spending and health savings accounts, life and AD&D insurance, short- and long-term disability coverage, legal assistance, and supplemental plans such as pet, critical illness, accident, and hospital indemnity insurance. We also provide voluntary commuter benefits, family planning and care resources, well-being initiatives, and peer-to-peer recognition programs; demonstrating our ongoing commitment to building a culture where our people feel empowered, supported, and inspired to do their best work.
Pay Range (Base Pay):
$110,706-$145,303 USD
Please note: These benefits are offered exclusively to permanent full-time employees. Contractors are not eligible for benefits through Legend Biotech.