Job offer
Remote Access Engineer (Citrix NetScaler & Zscaler Private Access) 100% (f/m/d)
Julius Baer is looking for a Remote Access Engineer in Madrid with over 5 years of experience in Citrix NetScaler and Zscaler Private Access to manage and further develop the secure remote access infrastructure as part of a zero-trust architecture.
Tasks
- Manage, configure, and continuously improve the Citrix NetScaler ADC and NetScaler Gateway infrastructure as part of a dedicated security engineering team to ensure high availability, performance, and operational resilience in primary and disaster recovery environments.
- Management and maintenance of SSL VPN and clientless access services, including virtual server configurations, authentication policies, rewrite rules, responder policies, and traffic control mechanisms.
- Design, implementation, and maintenance of secure authentication and conditional access policies based on device type, network location, and operational risk factors.
- Participated in the design, implementation, and deployment of the bank’s Zscaler Private Access (ZPA) infrastructure; supported the transition to a modern Zero Trust Network Access architecture; and contributed to overall network security and modern remote access solutions.
- Development and maintenance of enterprise-wide access solutions for internal applications, services, and data using remote access platforms—ZPA for application-based access (App Bypass) and NetScaler for other use cases—to establish a robust and scalable zero-trust posture.
- Lead the implementation of secure remote access controls by integrating Zscaler Private Access with existing Identity and Access Management (IAM) technologies to enable context-aware, policy-driven access that aligns with the bank’s zero-trust and secure remote access strategy.
- Monitoring, troubleshooting, and optimizing the performance, availability, and security of Citrix NetScaler and Zscaler Private Access environments; incident response; and change management in a highly regulated environment.
- Collaborate with infrastructure, network, endpoint, and application teams to design integrated remote access solutions that ensure consistency, scalability, and resilience.
- Drive the continuous development of secure remote access solutions by monitoring industry trends, vendor innovations, and evolving threat landscapes, and by incorporating improvements into the bank's long-term architecture.
- Contribution to the documentation of company-wide remote access, including architectural diagrams, runbooks, and operational procedures, to ensure standardization and knowledge sharing within the team.
- Contribute to the design, implementation, and operationalization of the bank’s future Zscaler Private Access (ZPA) platform and support the further development of the remote access landscape toward a modern Zero Trust Network Access (ZTNA) architecture.
- Work closely with IAM Endpoint Management, Security Operations, and Global IT teams to deliver secure, reliable, and scalable remote connectivity that meets the bank's regulatory requirements and aligns with its strategic security roadmap.
- Opportunity to contribute to and gain hands-on experience with the security services managed by the team, including Internet proxy, multi-factor authentication (MFA), privileged access management (PAM), public key infrastructure (PKI), and secure mail gateway solutions.
Requirements
- Bachelor's degree (or equivalent) in computer science, information security, cybersecurity, data science, or related technical fields; must meet the bank's requirements.
- More than 5 years of experience in the design, implementation, and management of enterprise-wide remote access, application access, or network security solutions, with at least several years of direct hands-on expertise in Citrix NetScaler ADC/Gateway and Zscaler Private Access.
- Extensive hands-on expertise in configuring Citrix NetScaler ADC/Gateway and Zscaler Private Access, including application visibility, traffic routing, policy configuration, and enterprise integration.
- Proven experience with application-based secure access platforms and the ability to implement application-specific access controls
Job details