Zero Trust Adoption Lead
CRAFZ Heredia (CRAFZ) Afz, Costa Rica
Kyndryl
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day.Who We Are
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities.
The Role
Practice Leadership & Strategy:
• Develop and drive the Zero Trust Adoption practice strategy.
• Stay ahead of Zero Trust trends, technologies, and best practices to enhance service offerings.
• Collaborate with leadership to define roadmaps, frameworks, and service models.
• Establish and refine Zero Trust methodologies, standards, and governance models.
Zero Trust Security Strategy & Architecture:
- Lead the design and implementation of Zero Trust architectures, aligning with Kyndryl’s Zero Trust Adoption, NIST 800-207, Forrester ZTX, and Gartner CARTA frameworks.
- Define Zero Trust security models across identity, devices, networks, applications, and data.
- Design and implement software-defined perimeters (SDP) and micro-segmentation strategies to minimize attack surfaces.
- Develop and enforce least privilege access controls, continuous authentication, and real-time risk-based access policies.
- Work with cloud security teams to integrate Zero Trust principles in multi-cloud environments (AWS, Azure, Google Cloud).
Identity & Access Management (IAM) & Privileged Access Management (PAM):
- Implement Zero Trust identity principles with strong authentication, MFA, adaptive access controls, and risk-based authentication.
- Design and manage IAM and PAM solutions using platforms such as SailPoint, CyberArk, Okta, Microsoft Entra ID.
- Secure machine identities, service accounts, and third-party access through identity federation and least privilege principles.
- Develop Zero Trust identity governance frameworks, ensuring compliance with SOX, GDPR, NIST, and ISO 27001.
Zero Trust Network & Cloud Security:
- Implement Zero Trust Network Access (ZTNA) solutions to replace traditional VPNs.
- Define secure access service edge (SASE) and software-defined perimeter (SDP) strategies for enterprise environments.
- Work with network security teams to enforce micro-segmentation, secure remote access, and least privilege networking.
- Collaborate with DevSecOps teams to integrate Zero Trust security in cloud-native applications, CI/CD pipelines, and container security.
Compliance, Risk Management & Security Leadership:
- Ensure Zero Trust compliance with industry regulations, including NIST 800-207, PCI-DSS, HIPAA, SOX, ISO 27001.
- Conduct security risk assessments, gap analysis, and Zero Trust maturity assessments for enterprise clients.
- Provide strategic guidance to CISOs, CIOs, and IT leadership teams on Zero Trust adoption roadmaps.
- Lead Zero Trust workshops, security awareness training, and best practice advisory sessions.
Client Engagement & Advisory:
- Act as a trusted advisor to clients, understanding their Enterprise Security Architecture and Zero Trust needs and challenges.
- Lead discovery workshops, requirement gathering, and solution demonstrations.
- Provide expert guidance on Zero Trust Adoption including governance, cultural adoptions, operating model etc.
- Develop proposals, statements of work (SOWs), and client presentations.
Team Leadership & Mentoring:
• Lead and mentor a team of Enterprise Security Architecture consultants.
• Provide training and knowledge-sharing sessions on Zero trust technologies and best practices.
• Foster a culture of innovation, collaboration, and continuous improvement.
Who You Are
Must-Have Skills:
- 8+ years of experience in enterprise security architecture, cybersecurity consulting, or Zero Trust implementations.
- Deep expertise in Zero Trust security models, identity security, network security, and cloud security.
- Hands-on experience with IAM, PAM, ZTNA, MFA, and identity federation solutions.
- Strong understanding of cloud security frameworks (AWS Well-Architected, Azure CAF, Google Cloud Security Best Practices).
- Experience in SIEM, SOAR, UEBA, and threat intelligence for continuous monitoring.
- Soft Skills & Leadership:
- Strong leadership and team management experience.
- Excellent communication and stakeholder management skills.
- Ability to engage with C-level executives and technical teams alike.
- Strategic thinker with the ability to align IAM initiatives with business objectives.
Nice-to-Have Skills:
- Experience with Zero Trust security vendors (Zscaler, Palo Alto Prisma, Cisco Duo, Microsoft Entra ID, BeyondTrust).
- Security certifications such as CISSP, CCSP, CISM, SABSA, TOGAF, or Zero Trust Certified Architect (ZTCA).
- Knowledge of AI-driven security analytics, behavioral analysis, and insider threat detection.
Being You
Diversity is a whole lot more than what we look like or where we come from, it’s how we think and who we are. We welcome people of all cultures, backgrounds, and experiences. But we’re not doing it single-handily: Our Kyndryl Inclusion Networks are only one of many ways we create a workplace where all Kyndryls can find and provide support and advice. This dedication to welcoming everyone into our company means that Kyndryl gives you – and everyone next to you – the ability to bring your whole self to work, individually and collectively, and support the activation of our equitable culture. That’s the Kyndryl Way.
What You Can Expect
With state-of-the-art resources and Fortune 100 clients, every day is an opportunity to innovate, build new capabilities, new relationships, new processes, and new value. Kyndryl cares about your well-being and prides itself on offering benefits that give you choice, reflect the diversity of our employees and support you and your family through the moments that matter – wherever you are in your life journey. Our employee learning programs give you access to the best learning in the industry to receive certifications, including Microsoft, Google, Amazon, Skillsoft, and many more. Through our company-wide volunteering and giving platform, you can donate, start fundraisers, volunteer, and search over 2 million non-profit organizations. At Kyndryl, we invest heavily in you, we want you to succeed so that together, we will all succeed.
Get Referred!
If you know someone that works at Kyndryl, when asked ‘How Did You Hear About Us’ during the application process, select ‘Employee Referral’ and enter your contact's Kyndryl email address.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics AWS Azure C CCSP CI/CD CISM CISSP Cloud Compliance Cyberark DevSecOps GCP GDPR Governance HIPAA IAM ISO 27001 Monitoring Network security NIST Okta Risk assessment Risk management SailPoint SASE Security strategy SIEM SOAR SOX Strategy Threat detection Threat intelligence TOGAF VPN Zero Trust ZTNA
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.