Practice - CIS - Cloud, Infrastructure, and Security Services
About Cloud Infrastructure & Security Services: Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS), is all about embracing digital transformation by driving core modernization holistically across layers. We help customers transform infrastructure and workplace to meet the rapidly evolving needs of the digital era. Our holistic approach delivers key results for our customers by achieving cloud driven modernization and workplace and operational transformation to run the business in a secure environment.
Job Summary
We are seeking an experienced Zero Trust Security Architect to lead the design, implementation, and optimization of secure connectivity solutions across global cloud and hybrid environments. This role will focus on Zero Trust Network Access (ZTNA), Zscaler, cloud VPN architectures, Secure Access Service Edge (SASE), and Security Service Edge (SSE) technologies to enable secure business operations and support merger and acquisition integration initiatives. The ideal candidate will possess deep expertise in cloud security, identity-aware networking, secure access architectures, and enterprise security transformation. This position requires strong architecture leadership, stakeholder engagement, and hands-on experience designing scalable and resilient Zero Trust environments.
In this role, you will:
· Design and maintain enterprise Zero Trust security architectures spanning identity, endpoints, applications, networks, cloud platforms, and data access pathways.
· Architect secure connectivity solutions including cloud VPN, site-to-site VPN, remote access, ZTNA, and hybrid-cloud access models.
· Design, implement, and optimize Zscaler capabilities including Secure Internet Access (ZIA), Private Access (ZPA), DLP, traffic inspection, threat prevention, and policy enforcement.
· Define identity-aware access models based on least-privilege principles and Zero Trust security frameworks.
· Lead secure integration and connectivity planning for new business platforms and enterprise technology initiatives.
· Architect network, application, and security integration strategies for mergers and acquisitions, including discovery, segmentation, access controls, migration planning, and target-state architecture development.
· Conduct threat modeling, security risk assessments, and architecture reviews focused on access flows, trust boundaries, and data protection requirements.
· Develop architecture standards, reference architectures, design patterns, implementation roadmaps, and reusable security artifacts.
· Collaborate with cloud engineering, infrastructure, security, and application teams to embed security controls and governance requirements into technology solutions.
· Evaluate and recommend Zscaler, SASE, SSE, VPN, and Zero Trust technologies based on business, security, scalability, and operational requirements.
· Provide architecture oversight, design reviews, and implementation guidance to ensure solutions align with enterprise security standards.
· Define and monitor security metrics, effectiveness measurements, and continuous improvement initiatives to strengthen enterprise security posture.
What you need to have to be considered
· 8+ years of experience in Security Architecture, Network Security, Cloud Security, or Enterprise Security Engineering roles.
· Strong expertise in Zero Trust Architecture, Zero Trust Network Access (ZTNA), Identity-Aware Access Controls, and Secure Connectivity solutions.
· Extensive hands-on experience with Zscaler technologies including ZIA, ZPA, DLP, policy management, and cloud-delivered security services.
· Experience designing enterprise cloud VPN, remote access, hybrid-cloud networking, and secure connectivity architectures.
· Strong understanding of SASE, SSE, cloud-native security architectures, and modern network security principles.
· Experience working with AWS, Azure, or multi-cloud environments, including cloud security, networking, identity, and connectivity services.
· Strong knowledge of enterprise identity systems, federation, MFA, RBAC, and least-privilege access models.
· Experience supporting M&A security integration initiatives and enterprise-scale network transformation projects.
· Deep understanding of security frameworks and compliance requirements including PCI-DSS, SOX, GDPR, and Zero Trust best practices.
· Strong architecture documentation, stakeholder management, communication, and technical leadership skills.
· Relevant certifications such as CISSP, Zscaler Certifications, AWS Security Specialty, Azure Security Engineer, CCSP, or equivalent are highly desirable.
#LI-EF1
#CB
#Ind123
Applications will be accepted until 23 Oct 2026.
Salary and Other Compensation:
The annual salary for this position is between $[134,000 - 154,500] depending on experience and other qualifications of the successful candidate.
This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.
Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:
· Medical/Dental/Vision/Life Insurance
· Paid holidays plus Paid Time Off
· 401(k) plan and contributions
· Long-term/Short-term Disability
· Paid Parental Leave
· Employee Stock Purchase Plan
关于高知特 (Cognizant)
高知特(Cognizant)(纳斯达克代码:CTSH)作为一家AI Builder和相关技术服务提供商,致力于通过打造全栈AI解决方案,帮助企业将人工智能投资转化为实际价值。公司凭借深厚的行业经验、流程优化和工程技术专长,将企业独特的业务场景融入科技系统,赋能组织释放人才潜能,推动切实成果,并帮助全球企业在瞬息万变的环境中保持领先。如需了解更多详情,敬请访问 cognizant.ai 或关注@cognizant。
补充雇佣信息
薪酬信息截至本职位发布之日为准。Cognizant 保留在适用法律允许的范围内随时修改该信息的权利。
申请人可能需要通过现场面试或视频会议的方式参加面试。此外,候选人在每次面试时可能需要出示其当前所在州或政府签发的有效身份证件。
Cognizant 是一家提供平等就业机会的雇主。在招聘过程中,您的申请和候选资格不会因种族、肤色、性别、宗教、信仰、性取向、性别认同、国籍、残疾、遗传信息、怀孕、退伍军人身份或任何其他受联邦、州或地方法律保护的特征而受到影响。







