Full Time

Lead Engineer - Secure VPN & Zero Trust - Odyssey Group - Stamford, CT

Odyssey Group

Stamford, CT
Posted 12 days ago

About the position

Odyssey Group Holdings, Inc., and its subsidiaries, collectively referred to as Odyssey Group, is one of the world’s leading providers of reinsurance and specialty insurance, encompassing three distinct yet complementary operating platforms supported by six divisions, 37 business units and a network of more than 30 offices. Odyssey Group is a subsidiary of Fairfax Financial Holdings Limited, a holding company with total assets of \$92.0 billion in total assets and \$27.7 billion in total equity. We are a financially strong and cohesive global enterprise, locally responsive and built on a unified management and underwriting culture. Position Summary The Lead Engineer is a senior technical leader responsible for modernizing Odyssey’s global secure‑access architecture, from legacy perimeter‑based VPN/VDI to a fully application‑centric Zero Trust Network Access (ZTNA) model. This role is both strategic and hands‑on, requiring expertise in architecture, design, implementation, configuration, and troubleshooting across cloud and on‑prem environments. You will own the engineering lifecycle end‑to‑end: building architecture diagrams, leading solution design workshops, implementing ZTNA and VPN configurations, writing infrastructure‑as-code, deploying secure connectivity patterns, and validating end‑user experience.

Responsibilities

Zero Trust Architecture & Design Lead the transition from legacy VDI/Citrix access to per‑application ZTNA, including hands‑on buildout of access policies, identity‑based segmentation, and app‑level routing.Produce high‑fidelity architecture diagrams (Visio, Draw.io, Lucidchart) representing application flows, identity boundaries, private endpoints, and ZTNA enforcement points.Document threat models and convert them into implementable, measurable technical controls.Design and maintain Conditional Access policies tied to device posture, risk signals, and session context.Customer Experience & Hands-On Secure Connectivity Engin