Security Engineer at OpticoreIT, London, 6 Months, £Contract Rate

Contract Description

Opticore IT is a specialist Network Engineer and Project Management consultancy offering a wide variety of opportunities to work within fast-paced, challenging environments across our client base spanning multiple sectors including Finance, Broadcast Media, Telecommunications and more.

Opticore IT are currently searching for a Security Engineer who is highly competent with Zscaler to come and join the team for an initial 6 month contract inside IR35 with scope to extend. This opportunity will require two days a week on site in central London.

This opportunity will deliver Zscaler tenant separation, policy build-out, and operational readiness across ZIA and ZPA for a large-scale corporate divestiture programme, building a net-new tenant for the retained entity and ensuring bidirectional separacy between entities ahead of Day 1.

What You'll Be Doing

  • Build and configure a new Zscaler tenant (ZIA and ZPA) as full net-new deployment for the retained entity
  • Configure ZIA internet security policies (URL filtering, threat protection, DLP, SSL inspection, cloud firewall) based on policies defined by the architect.
  • Configure ZPA access, forwarding, inspection, and isolation policies; deploy ZPA App Connectors in retained-entity network segments and validate connectivity based on policies defined by the architect.
  • Establish GRE tunnels from PoP internet routers to the new ZIA cloud instance and configure Zscaler Digital Experience (ZDX) monitoring
  • Configure SAML/OIDC federation and attribute-based user routing between the new tenant and shared identity provider (e.g. Okta)
  • Implement and validate bidirectional separacy controls between entities and configure automated policy audit mechanisms to detect and alert on separacy violations
  • Configure Multi-ZPA Tenant Access for explicitly agreed shared services during the transitional period, with periodic access reviews
  • Remove retained-entity users, policies, application segments, and App Connectors from the divested tenant, and reconfigure RBAC for the divested operations team
  • Provide transitional administration of the divested tenant (platform, connector, and tunnel management) and support handover including admin transfer, IdP migration, and cross-tenant policy removal
  • Configure independent cyber reporting (e.g. Zscaler 360i) for each tenant to prevent cross-entity data leakage

What You'll Bring

  • Zscaler ZIA & ZPA Administration
  • Identity Federation (SMAL/OIDC, Okta, SCIM)
  • Zscaler Multi-Tenant/Separation Delivery
  • Zero Trust Network Access & Policy Design
  • Zscaler Client Connector & GRE/IPSec Tunnel Integration

Diversity:

At Opticore IT we embrace diversity and are committed to equal opportunities. We actively recruit for an inclusive and diverse workforce and as such, want to ensure we do everything we can to support your application.

We want you to feel empowered to let us know if you require any adjustments to be made with your application or interview process so please speak to our recruitment team.