Security Architect

  • New Zealand
  • Auckland
  • Contract
  • Negotiable

Security Architect – Network Security & ZTNA

We’re looking for a Security Architect for a 5 month Contract.

Join a major enterprise security transformation and help deliver modern network security, Zero Trust Network Access and segmentation capabilities at scale.

This is a hands-on architecture role for someone who enjoys working closely with engineering and operations teams, not simply reviewing solutions from the sidelines. You will turn security strategy into practical patterns, guardrails and delivery-ready solutions across a complex hybrid and multi-cloud environment.

The opportunity

Embedded within the Network and Security Services function, you will help accelerate a broad programme of work covering:

  • Zero Trust Network Access (ZTNA)

  • Dynamic Trust and identity-aware access

  • Data-centre and cloud micro-segmentation

  • SD-WAN and branch security uplift

  • Firewall and IPS modernisation

  • CIS compliance

  • Network security automation

  • Converged monitoring and observability

  • Secure cloud connectivity

  • AI-enabled network security operations

You will own and develop reusable architecture patterns, standards and guardrails while supporting delivery teams through implementation.

Key responsibilities

  • Design enterprise ZTNA policies incorporating identity, endpoint posture, EDR, DLP and Entra ID controls.

  • Support enterprise-wide ZTNA rollout, including application publishing, user onboarding, exception management and migration from legacy access.

  • Develop micro-segmentation strategies across data centres, cloud platforms, virtual machines and Kubernetes environments.

  • Lead application dependency mapping, impact assessments, phased enforcement and database traffic coordination.

  • Design Layer 7 firewall controls, context-aware policies, IPS uplift, DNS security and centralised policy management.

  • Define secure hybrid and multi-cloud connectivity patterns across AWS, Azure and GCP.

  • Develop standards for shared VPC/VNet environments, private endpoints, hub-and-spoke networks, cloud-to-cloud connectivity and hybrid DNS.

  • Improve SD-WAN and branch segmentation, including NAC integration, device posture and the separation of user and machine traffic.

  • Establish network security telemetry covering firewall, proxy, DNS, flow and ZTNA data.

  • Support security monitoring, dashboards, detection use cases, automation triggers and forensics-ready logging.

  • Design automation for firewall requests, policy lifecycle management and broader network security operations.

  • Produce architecture decision records, standards, implementation guardrails and delivery-ready backlog items.

  • Test security controls in live environments before publishing them as organisational standards.

  • Clearly communicate residual risks, control gaps, compensating controls and delivery trade-offs.

  • Work directly with cyber, architecture, engineering, operations, risk, service management and vendor teams.

Technology environment

You may work across technologies including:

  • Check Point firewalls and IPS

  • Netskope Proxy, DLP and ZTNA

  • Illumio segmentation

  • Akamai DNS and security services

  • Cisco Nexus and Catalyst

  • F5 BIG-IP and WAF

  • AWS, Azure and GCP native firewalls

  • Kubernetes networking and security

  • Terraform and policy as code

  • SIEM, network telemetry and AIOps platforms

Experience across every listed product is not required; however, you will need strong enterprise network security architecture experience and the ability to work confidently across a varied technology landscape.

What you’ll bring

  • At least eight years’ experience in security architecture or senior network security engineering.

  • Five or more years working with enterprise network security, ZTNA, segmentation, firewalls, proxies, DNS or cloud networking.

  • Experience within financial services, critical infrastructure or another highly regulated environment.

  • Proven delivery of enterprise-scale ZTNA, network segmentation or Zero Trust initiatives.

  • Strong hybrid and multi-cloud network security knowledge.

  • Experience producing reusable architecture patterns, standards and implementation guardrails.

  • The ability to translate strategy and regulatory requirements into practical technical controls and measurable outcomes.

  • Hands-on experience with Terraform, policy as code or network security automation.

  • Strong consultation and communication skills across engineering, cyber, risk, operations and executive stakeholders.

  • A pragmatic “yes, if” mindset that enables delivery while keeping solutions within risk appetite.

  • The confidence to sign off designs, defend recommendations at architecture review and manage exceptions pragmatically.

Certifications

Relevant certifications may include:

  • CISSP, CCSP, SABSA or equivalent security architecture experience

  • AWS Advanced Networking – Specialty

  • Microsoft Azure Network Engineer Associate

  • Google Professional Cloud Network Engineer

  • Check Point CCSE

  • Cisco security or networking certifications

  • Netskope, Illumio, F5 or Akamai certifications

Strong, clearly demonstrated enterprise delivery experience may substitute for formal certifications.

Why consider this role?

This is an opportunity to influence a significant security transformation while remaining close to delivery. You will help shape how Zero Trust, segmentation, cloud connectivity and network security automation are implemented across a large and complex enterprise environment.

If you are a delivery-focused Security Architect who can combine deep network security expertise with practical stakeholder engagement, we would love to hear from you.

Apply now

Submit your details and attach your resume below. Hint: make sure all relevant experience is included in your CV and keep your message to the hiring team short and sweet - 2000 characters or less is perfect.