Security Architect

Hace 24 horas

Barcelona, Cataluña, España Colt Technology Services Jornada completa 90.000 € - 120.000 € Por obra

Colt provides network, voice and data centre services to thousands of businesses around the world, allowing them to focus on delivering their business goals instead of the underlying infrastructure.

Why we need this role

We are looking for a Security Architect specialising in Cloud Security and Secure Access to join the Security and Resilience – Security Architecture team.

This role acts as a subject matter expert across cloud security architecture (IaaS/PaaS) and secure access technologies, with a primary focus on Azure and GCP environments and Colt’s strategic Zscaler platform (ZIA / ZPA).

The successful candidate will work closely with Security Engineering, SOC, Threat Intelligence and Risk functions, as well as wider technology teams (Cloud Engineering, Network Engineering, Service Delivery), to design and implement secure, scalable and Zero Trust-aligned architectures.

The Role Combines

  • Security architecture and design across cloud platforms and access layers
  • Security assurance, governance and integration
  • Strategic engagement across Colt’s hybrid technology estate

You Will Play a Critical Role In Driving

  • Secure cloud adoption across Azure and GCP environments
  • Zero Trust Network Access (ZTNA) via Zscaler (ZIA / ZPA)
  • Integration of identity, access and network security controls
  • Consistent, secure access to applications, services and data across a distributed enterprise

What You Will Do

  • Act as the security architecture authority for cloud and secure access solutions, with a focus on Azure, GCP and Zscaler platforms
  • Define and maintain the target architecture for cloud security and secure access, aligned to Colt’s Zero Trust principles
  • Design and implement secure architectures for IaaS and PaaS environments, ensuring appropriate controls across networking, compute, storage and identity layers
  • Lead the design and implementation of Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) solutions to enable secure user-to-internet and user-to-application access
  • Define architectures for Zero Trust Network Access (ZTNA), replacing or reducing reliance on traditional VPN-based access models
  • Design and implement identity-integrated access controls, leveraging Entra ID and federation technologies such as SAML
  • Define secure access patterns for internal applications, SaaS services and cloud-hosted workloads
  • Ensure consistent integration between Zscaler, identity providers (Entra ID) and cloud platforms, supporting seamless authentication and access control
  • Conduct security architecture reviews and provide assurance for cloud and access-related solutions, supporting formal sign-off or risk acceptance processes
  • Work with cloud and network engineering teams to ensure secure and scalable implementation of architecture patterns
  • Support the adoption of Secure by Design principles across cloud-native and access solutions
  • Ensure alignment with regulatory and compliance requirements such as TSA, DORA and ISO27001
  • Define and document standard architecture patterns for cloud security and secure access, including segmentation, identity enforcement and traffic control
  • Assess and mitigate risks associated with cloud-native architectures, including misconfiguration, over-permissioning and insecure exposure of services
  • Engage with vendors (Zscaler, Microsoft, Google) to stay aligned with roadmaps and emerging capabilities
  • Produce high-quality architecture artefacts, standards and guidance documentation

Must Haves

What we're looking for

  • 5+ years of experience in information security within large-scale enterprise or telecommunications environments
  • Strong experience in cloud security architecture, particularly across:
    • Microsoft Azure
    • Google Cloud Platform (GCP)
  • Strong experience with Zscaler platform, including:
    • Zscaler Internet Access (ZIA)
    • Zscaler Private Access (ZPA)
  • Strong understanding of Zero Trust Network Access (ZTNA) and modern secure access architectures
  • Experience designing secure solutions across IaaS/PaaS environments, including networking, identity and workload protection
  • Good understanding of identity and authentication technologies, including Entra ID, SAML and federation-based access models
  • Experience conducting security design reviews and translating policy into enforceable technical controls
  • Experience performing risk assessments aligned to recognised frameworks
  • Strong understanding of networking and security technologies, including segmentation, routing, secure access and traffic inspection
  • Ability to translate complex technical concepts into clear business-alig