Cyber Security Consultant

Role overview

-Contract resource for 9 months.

-Inside IR35

-Hybrid – with 2 visits per month to Glasgow required

We are seeking a confident and demonstrable Zscaler Private Access Subject Matter Expert to provide technical leadership across a large-scale Secure Access Transformation Programme. The SME will act as a trusted adviser and technical authority, shaping the ZPA strategy, target design, application-onboarding standards and migration approach across a complex enterprise environment.

The role is focused on expert direction, design assurance and complex problem-solving rather than routine configuration activity. The SME must nevertheless have sufficient practical delivery experience to challenge designs, guide engineers, assure implementation decisions and provide credible escalation support as access moves from traditional VPN connectivity to an identity- and application-centric Zero Trust model.

Key responsibilities

Technical leadership and advisory

  • Act as the principal ZPA technical authority for the programme, providing expert guidance to project, architecture, security and engineering teams.
  • Define the technical direction for migrating private application access from traditional VPN services to ZPA.
  • Advise senior stakeholders on ZPA capability, design choices, technical constraints, risks and delivery dependencies.
  • Lead technical workshops and provide clear recommendations where requirements, ownership or design decisions are unclear.

Architecture, standards and governance

  • Own or assure the ZPA target architecture across on-premises, Azure and AWS environments.
  • Define design principles, onboarding patterns, policy standards and reusable technical templates aligned to Zero Trust and least-privilege access.
  • Review and approve high-level and low-level designs, ensuring consistency, scalability, resilience and operational supportability.
  • Provide governance over Application Segments, Segment Groups, Access Policies, App Connector Groups, Browser Access and identity integrations.
  • Ensure technical decisions are documented, traceable and aligned with wider security architecture and regulatory obligations.

Migration assurance and complex escalation

  • Define how applications and VPN use cases should be assessed, classified, prioritised and grouped into migration waves.
  • Guide delivery engineers through complex onboarding scenarios involving authentication, DNS, routing, firewall rules, ports, protocols and application dependencies.
  • Assure pilot designs, test strategies, acceptance criteria, rollback approaches and go-live readiness.
  • Provide expert escalation support for complex identity, policy, connectivity, App Connector and application-access issues.
  • Identify systemic risks or recurring defects and recommend improvements to architecture, standards or delivery methods.

Operational readiness and knowledge leadership

  • Define the documentation, runbook, support and handover standards required for transition into BAU.
  • Coach and mentor client and delivery teams, raising capability across ZPA design, onboarding and troubleshooting.
  • Lead knowledge-transfer sessions and assure that operational teams can safely support the resulting service.
  • Provide clear technical reporting on key decisions, risks, assumptions, dependencies and recommended actions.

Essential experience

  • Demonstrable subject matter expertise in Zscaler Private Access across complex enterprise environments.
  • A strong record of providing technical leadership or design authority for major ZPA, ZTNA or secure-access transformation programmes.
  • Deep knowledge of ZPA architecture, Application Segments, Segment Groups, Access Policies, App Connectors/App Connector Groups, Browser Access and platform design considerations.
  • Proven experience shaping or assuring the migration of users and applications from traditional remote-access VPNs to ZTNA/ZPA.
  • Expert understanding of Zero Trust and least-privilege access, with the ability to translate principles into scalable architecture, standards and policy.
  • Strong identity and authentication knowledge, including Microsoft Entra ID/Azure AD, SAML, OIDC, MFA and conditional or device-based access controls.
  • Strong networking fundamentals, including DNS, routing, firewalls, TCP/IP, ports and protocols.
  • Experience working across on-premises and cloud-hosted applications, ideally within Azure and AWS.
  • Confident engagement with senior stakeholders, architects, security teams, application owners, technical SMEs and delivery engineers.
  • Ability to create and critically review architecture, high-level and low-level designs, standards, technical decisions and operational documentation.
  • Strong diagnostic and analytical capability, with credibility as the escalation point for complex design and delivery challenges.
  • Experience mentoring technical teams and transferring specialist knowledge into operational capability.

Desirable experience

  • Current Zscaler certification such as ZCCA, ZCCP, ZCCA-PA or an equivalent ZPA-focused credential.
  • Delivery experience within utilities, energy, Critical National Infrastructure or another regulated environment.
  • Experience with Azure, AWS, Nutanix and hybrid application hosting patterns.
  • Experience integrating Zscaler telemetry with SIEM platforms such as Google Chronicle.
  • Terraform or other Infrastructure as Code experience.
  • Knowledge of NIS2, NIST 800-207 and recognised Zero Trust good practice.
  • Broader Zscaler experience across ZIA, ZDX or related SASE capabilities.

Job Details

Company
Phoenix47
Location
Scotland, United Kingdom
Posted