hirly

Legendcareers

Senior Zero Trust Architect / Engineer

Bridgewater, New Jersey, United States; Somerset, New Jersey, United States

Apply through hirly

Upload your resume and get a version tailored to this job, plus a cover letter, in about thirty seconds — before you create an account.

Apply with hirly

hirly's read of this role

Seniority
Senior
Country
US
Work mode
Remote-friendly
First seen by hirly
21 Sept 2026

Derived automatically from the posting. Sign up to see how the role scores against your own resume.

the posting

Legend Biotech is a global biotechnology company dedicated to treating and, one day, curing life-threatening diseases. Headquartered in Bridgewater, New Jersey, we are advancing the next generation of cell therapy through a portfolio of innovative technologies, including autologous, allogeneic, and in vivo cell therapy approaches. Our research spans chimeric antigen receptor T-cell (CAR-T), T-cell receptor (TCR-T), natural killer (NK) cell-based therapies, and other emerging platforms designed to transform the treatment of serious diseases. From our global network of research and development sites, we are committed to discovering and developing safe, effective, and cutting-edge therapies for patients worldwide.

Legend Biotech entered into a global collaboration agreement with Johnson & Johnson to jointly develop and commercialize CARVYKTI® (ciltacabtagene autoleucel; cilta-cel). Through this strategic partnership, we combine complementary expertise and capabilities to advance innovative immunotherapies for patients living with multiple myeloma.

Legend Biotech is seeking a Senior Zero Trust Architect / Engineer as part of the Information Technology team based in Bridgewater, NJ or Somerset, NJ.

Role Overview

The Senior Zero Trust Architect / Engineer is responsible for designing, implementing, and governing the organization's Zero Trust security strategy across users, devices, applications, networks, data, and cloud environments. This role serves as a senior technical leader, driving the adoption of modern security architectures that continuously verify trust, minimize attack surfaces, enforce least-privilege access, and protect critical enterprise assets.

The candidate should possess deep expertise in identity security, network security, cloud security, endpoint protection, data protection, and security architecture. This position partners closely with Infrastructure, Cloud, Digital Workplace, Enterprise Applications, Compliance, and Cybersecurity teams to ensure security controls align with business objectives while supporting a modern, flexible workforce.

The ideal candidate will have hands-on experience with Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), and Zero Trust architecture.

Key Responsibilities

Develop and maintain the enterprise Zero Trust architecture roadmap aligned with business and cybersecurity objectives.

Design and implement security architectures based on NIST Zero Trust Architecture (SP 800-207), CISA Zero Trust Maturity Model, and industry best practices.

Lead enterprise-wide Zero Trust transformation initiatives across cloud, on-premises, and hybrid environments.

Define security reference architectures, standards, policies, and design principles.

Conduct architecture reviews and provide guidance for new technology deployments.

Architect micro-segmentation and software-defined perimeter solutions.

Design secure access controls for:

Corporate networks

Data centers

Cloud environments

Third-party connectivity

Implement Zero Trust Network Access (ZTNA) technologies.

Reduce reliance on traditional VPN architectures.

Lead network access policy modernization initiatives.

Design and implement security architectures across:

Microsoft Azure

AWS

Collaborate with cloud engineering teams to establish secure landing zones.

Implement cloud-native security controls and posture management capabilities.

Evaluate and improve cloud identity and access security.

Lead implementation of Zero Trust security technologies and integrations.

Establish security monitoring and continuous verification capabilities.

Support incident response and threat hunting activities.

Identify security gaps and remediation opportunities through assessments and architecture reviews.

Develop automation and orchestration solutions to improve security operations.

Translate regulatory and compliance requirements into technical security controls.

Participate in risk assessments and security audits.

Develop metrics and KPIs to measure Zero Trust maturity and effectiveness.

Present architecture recommendations and risk findings to senior leadership.

Strong executive communication and presentation skills.

Ability to influence stakeholders across business and technical teams.

Strategic thinker with strong architectural and analytical skills.

Proven ability to lead complex enterprise transformation initiatives.

Excellent problem-solving and decision-making capabilities.

Requirements

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.

Master's degree preferred

Zscaler Certified Administrator (ZCCA)

Zscaler Certified Professional (ZCCP)

Microsoft Security certifications

CISSP, CCSP, Security+, or equivalent certifications

Microsoft Certified Cybersecurity Architect Expert (SC-100)

Microsoft Security Operations Analyst (SC-200)

Azure Solutions Architect Expert

GIAC Security Certifications

Network certification

10+ years of IT infrastructure, cybersecurity, or security engineering experience.

5+ years designing enterprise security architectures.

3+ years leading Zero Trust initiatives or enterprise identity modernization programs.

Experience in highly regulated industries such as biotechnology, pharmaceuticals, healthcare, or financial services preferred.

Technical Expertise:

Microsoft Entra ID (Azure AD)

Microsoft Active Directory (ADDS)

Conditional Access

Identity Governance

Privileged Identity Management (PIM)

Privileged Access Management (PAM)

Federation technologies supporting SSO (SAML, OAuth, OIDC)

Microsoft: Defender, Purview, M365, Intune, MS Graph

Optional: Sentinel

Azure

AWS

Zero Trust Network Access (ZTNA)

Secure Web Gateway

Network Micro-Segmentation

Zscaler – zia, zpa, zdx

NIST 800-207

NIST Cybersecurity Framework

CISA Zero Trust Maturity Model

AI Literacy: Possesses a working knowledge of AI technologies and approved AI tools, applies them responsibly to enhance productivity and decision-making, exercises appropriate human oversight of AI-generated outputs, and complies with organizational policies governing AI use.

Language(s): English, Mandarin a plus

#Li-FB1

#Li-Onsite

The base pay range below is what Legend Biotech USA Inc. reasonably expects to offer at the time of posting. Actual compensation may vary based on experience, skills, qualifications, and geographic location. The company reserves the right to modify this range as needed and in accordance with applicable laws.

Other Types of Pay: Performance-based bonus and/or equity is available to employees in eligible roles.

Benefits and Paid Time Off: Medical, dental, and vision insurance as well as a 401(k) retirement plan with a company match that vests fully on day one. We offer eight (8) weeks of paid parental leave after just three (3) months of employment, and a paid time off policy that includes vacation time, personal time, sick time, floating holidays, and eleven (11) company holidays. Additional voluntary benefits include flexible spending and health savings accounts, life and AD&D insurance, short- and long-term disability coverage, legal assistance, and supplemental plans such as pet, critical illness, accident, and hospital indemnity insurance. We also provide voluntary commuter benefits, family planning and care resources, well-being initiatives, and peer-to-peer recognition programs; demonstrating our ongoing commitment to building a culture where our people feel empowered, supported, and inspired to do their best work.

Pay Range (Base Pay):

$110,706 — $145,303 USD

Please note: These benefits are offered exclusively to permanent full-time employees. Contractors are not eligible for benefits through Legend Biotech.

Work Authorization & Employment Eligibility

Applicants must be authorized

Original posting on Legendcareers's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job