Senior / Principal Ip Networks & Security Architect

Carecone Group

New South Wales

On-site

AUD 180,000 - 240,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Carecone Group is seeking a Senior / Principal IP Networks & Security Architect to lead the design, evolution, and governance of large-scale service provider networks in Sydney. You will own advanced routing architectures (eBGP, MPLS/L3VPN), edge security, and the integration of mobile core with Gi/SGi/N6 interfaces.

This role requires 10-15+ years in IP networking within mobile operator environments, multi-vendor exposure (Fortinet, Check Point, Cisco), and a track record of delivering

Qualifications

  • 10-15+ years in IP networking within service provider or mobile operator environments.
  • Experience designing scalable IP/MPLS networks for mobile environments.

Responsibilities

  • Design scalable IP/MPLS networks for mobile core, aggregation, and edge environments.
  • Develop routing strategies using eBGP, iBGP, OSPF/IS-IS and traffic engineering.
  • Architect and manage MPLS services (L3VPN, L2VPN, segment routing).
  • Lead integration of IP networks with mobile packet core (4G/5G) including Gi/SGi/N6.
  • Define and implement network security architecture including edge firewall placement.

Skills

eBGP
MPLS
Edge security
Mobile core integration
Routing protocols
Network virtualization
Programmability (Python/Ansible)

Education

CCIE/JCIE/NSE equivalent

Tools

Fortinet FortiGate
Check Point
Cisco

Job description

Job Description

Hiring for Senior / Principal IP Networks & Security Architect

Location- Sydney

Position- Permanent

Description-

Description

Job Title: Senior / Principal IP Networks & Security Architect

Experience: 10-15+ years

Role Overview

We are seeking a highly experienced IP Networks & Security Architect to lead the design, evolution, and governance of large-scale service provider networks. This role is focused on advanced routing architectures, MPLS-based services, and security frameworks within mobile operator environments.

The ideal candidate will bring deep expertise in eBGP, L3VPN, and edge security, with hands‑on experience across multi‑vendor ecosystems.

Key Responsibilities:
  • Design and architect scalable IP/MPLS networks supporting mobile core, aggregation, and edge environments.
  • Develop and optimize routing strategies using eBGP, iBGP, OSPF/IS-IS, and advanced traffic engineering techniques.
  • Architect and maintain MPLS services including L3VPN, L2VPN, and segment routing (preferred).
  • Lead the integration of IP networks with mobile packet core (4G/5G), including Gi/SGi/N6 interfaces.
  • Define and implement network security architecture, including edge firewall placement, segmentation, and policy control.
  • Evaluate and integrate firewall solutions (Fortinet, Check Point, Cisco) into service provider environments.
  • Drive high availability and resiliency designs (fast convergence, redundancy models, failure domains).
  • Provide technical leadership for network transformation initiatives, including virtualization and cloud integration.
  • Collaborate with operations, engineering, and vendors for deployment, troubleshooting, and optimization.
  • Produce high- & low‑level design documentation (HLD/LLD), standards, and architectural guidelines.
Required Skills & Experience:

10-15+ years in IP networking, with significant experience in service provider or mobile operator environments.

Strong expertise in:
  • eBGP (multi‑homing, route policies, scaling, convergence tuning)
  • MPLS (L3VPN, LDP, RSVP‑TE, Segment Routing preferred)
  • Core routing protocols (IS‑IS, OSPF)
  • Deep understanding of mobile network architectures (4G EPC, 5G Core) and IP transport integration.
  • Proven experience with edge security design and firewall technologies.
Hands‑on experience with at least two of the following vendors:
  • Fortinet (FortiGate)
  • Check Point
  • Strong knowledge of high availability, redundancy models, and traffic engineering.
  • Experience with network automation or programmability (Python, Ansible, APIs) is advantageous.
Preferred Qualifications:
  • Experience with cloud networking (AWS, Azure, or private cloud integration).
  • Familiarity with SDN/NFV architectures.
  • Relevant certifications (e.g., CCIE, JNCIE, Nokia SRA, NSE, CCSP).
  • Exposure to DDoS protection, CGNAT, or internet edge architectures.

Note- Must have valid Australian work Authorization.

Get your free, confidential resume review.
or drag and drop your file here.