Network Architect

Ampstek

Lyon

Sur place

EUR 70 000 - 110 000

Plein temps

Il y a 7 jours
Soyez parmi les premiers à postuler

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Ampstek in Lyon, France seeks an experienced Network Architect to define target architectures across on-prem, data centre, campus, WAN, WLAN, cloud and hybrid connectivity. You will lead design governance, security-by-design, and multi-vendor routing strategies in global environments.

You will collaborate with engineering, security and operations teams, produce ADRs and design standards, and drive automation and observability in complex enterprise networks.

Qualifications

  • Define target network architectures for on-premise, data centre, campus, WAN, WLAN, cloud and hybrid connectivity environments.
  • Act as a technical design authority for network infrastructure projects.
  • Define architecture standards and reusable design patterns across global environments.
  • Security-by-Design: integrate security into network architecture (VPN, firewalling, cloud connectivity).
  • Knowledge of Cisco, Aruba, Fortinet and Palo Alto security platforms.
  • WAN/SD-WAN architecture: routing, connectivity and multi-technology integration.
  • Cloud connectivity design with Azure and AWS.
  • Network as Code and automation governance.
  • Monitoring, observability and operational readiness requirements.

Responsabilités

  • Define target network architectures for on-premise, data centre, campus, WAN, WLAN, cloud and hybrid connectivity environments.
  • Act as technical design authority for network infrastructure projects and validate designs.
  • Review high-level and low-level designs, migration approaches and technical patterns.
  • Contribute to the evolution of the network technology roadmap and standards.
  • Security architecture: segmentation, filtering, VPN, firewalling and cloud connectivity.
  • Provide architecture support to deployment, migration and transformation projects.
  • Produce architecture documentation, ADRs, diagrams and patterns.
  • Guide engineers and international teams, run architecture boards and governance forums.

Connaissances

Enterprise-scale network design
Architecture principles & standards
Network resilience & performance
Cisco Campus/Data Centre
Aruba network environments
STP/VLAN/IP addressing
BGP & OSPF
WAN/SD-WAN architecture
Firewall & security architecture
Fortinet FortiManager/FortiGate
Palo Alto firewalling
Cloud networking (Azure/AWS)
Cisco ACI (Data Centre)
DDI / Efficient IP
Network as Code / automation
Cisco Catalyst Center
Zscaler proxy
F5 load balancing
Network documentation
Leadership & governance
English communication

Outils

Cisco Catalyst Center
Fortinet FortiManager/FortiGate
Palo Alto
Aruba Central
Cisco ACI
Jira

Description du poste

Required Profile & Skills: Technical Expertise
  • Strong experience designing enterprise-scale network architectures across Campus, Data Centre, WAN, WLAN, Cloud and Hybrid Connectivity environments.
  • Ability to define architecture principles, standards, patterns and target-state designs.
  • Strong understanding of enterprise network resilience, scalability, segmentation, performance and operational supportability.
Routing, Switching & WLAN
  • Deep knowledge of Cisco environments across Campus and Data Centre domains.
  • Strong understanding of Aruba network environments, including Aruba Central, switch deployment, Wi-Fi access points and standard network protocols.
  • Excellent knowledge of STP, VLANs, IP addressing, Radius, routing, switching and network access control principles.
Dynamic Routing, WAN & SD-WAN
  • Strong architectural understanding of WAN and SD-WAN models.
  • Advanced knowledge of BGP and OSPF.
  • Ability to design and govern routing across multi-vendor and multi-environment landscapes, including Cisco, Aruba, Fortinet, Palo Alto and Azure/AWS cloud environments.
Network Security & Firewalling
  • Strong understanding of security architecture principles applied to network infrastructure.
  • Good knowledge of Fortinet technologies, including FortiManager and FortiGate architecture and integration principles.
  • Good knowledge of Palo Alto firewalling and traffic filtering design.
  • Ability to define secure connectivity models, filtering principles, segmentation patterns, VPN architecture and cloud security integration.
Data Centre & Advanced Network Technologies
  • Strong understanding of Cisco ACI architecture and data centre network design.
  • Ability to provide guidance on complex routing, segmentation and data centre interconnect scenarios.
  • Knowledge of F5 load balancing concepts would be an advantage.
  • Knowledge of Zscaler proxy architecture would be an advantage.
DDI, Monitoring & Tooling
  • Solid understanding of DDI architecture, ideally with Efficient IP.
  • Ability to define IP addressing, DNS/DHCP integration and dependency models.
  • Experience defining network monitoring, observability and operational-readiness requirements.
  • Familiarity with network automation, configuration governance and Network as Code approaches.
  • Knowledge of Cisco Catalyst Center automation capabilities would be beneficial.
Soft Skills & Languages
  • Fluent written and spoken English is essential for operating in an international context.
  • Ability to write clear architecture documentation, design principles, decision records and technical standards in English.
  • Ability to collaborate with local IT teams and global stakeholders across multiple countries.
Mandatory English – Fluent
  • Fluent written and spoken English is essential for operating in an international context.
  • Ability to write clear architecture documentation, design principles, decision records and technical standards in English.
  • Ability to collaborate with local IT teams and global stakeholders across multiple countries.
Leadership & Communication
  • Strong ability to explain complex network architecture topics clearly to technical and non-technical stakeholders.
  • Ability to influence technical decisions without direct hierarchical authority.
  • Proven ability to work with architects, engineers, operations teams, security teams and project managers.
Governance & Documentation
  • Strong rigour in producing structured, high-quality architecture documentation.
  • Ability to maintain architecture consistency across projects, regions and technology domains.
  • Comfortable contributing to technical committees, steering committees and architecture review boards.
  • Ability to integrate quickly into an existing technical organization.
  • Strong knowledge-transfer mindset.
  • Ability to guide engineers and local IT teams during design, deployment, migration and transition phases.
  • Strong knowledge-transfer mindset.
Optional Skills
  • Experience with F5 load balancing architecture.
  • Knowledge of Zscaler proxy and secure internet access architectures.
  • Familiarity with Cisco Catalyst Center for automation and network assurance.
  • Experience with cloud networking on Azure and/or AWS.
  • Experience contributing to NIS 2, cybersecurity resilience or infrastructure compliance programmes.
Experience leading architecture reviews, design boards or technical governance forums.
Key Responsibilities and Activities
1. Network Architecture, Strategy & Design Authority
  • Architecture Definition: Define target network architectures for on-premise, data centre, campus, WAN, WLAN, cloud and hybrid connectivity environments.
  • Design Authority: Act as a technical design authority for network infrastructure projects, ensuring that proposed solutions are robust, secure, scalable and aligned with enterprise standards.
  • Architecture Governance: Review and validate high-level designs, low-level designs, migration approaches, technical patterns and implementation choices proposed by engineering or project teams.
  • Technology Roadmap: Contribute to the evolution of the network technology roadmap, including routing, switching, SD-WAN, WLAN, cloud networking, firewalling, segmentation and automation.
  • Standardization: Define and maintain network architecture standards, reference designs, design principles and reusable technical patterns across Groupe SEB’s global environments.
2. Network Security & Compliance Architecture
  • Security-by-Design: Integrate security requirements into network architecture, including segmentation, filtering, access control, VPN, firewalling, cloud connectivity and secure remote access.
  • Firewall & Security Architecture: Define architectural principles and target designs for Palo Alto, Fortinet/FortiManager/FortiGate, vRouters and related security platforms.
  • Regulatory Alignment: Ensure network architecture takes account of regulatory and security requirements, including NIS 2-related resilience, traceability, segmentation and operational control expectations.
  • Risk Management: Identify architecture risks, technical debt, non-standard implementations and resilience gaps; propose mitigation plans and prioritized remediation actions.
  • Operational Security: Work with cybersecurity and operations teams to ensure that network designs can be monitored, operated, audited and maintained securely.
  • Campus & WLAN Architecture: Define architecture standards for Cisco and Aruba-based LAN/WLAN environments, including switching, wireless access, VLAN design, STP, Radius integration and access policies.
  • Data Centre Architecture: Provide architecture expertise for data centre network environments, including Cisco technologies, Cisco ACI and complex routing designs.
  • WAN / SD-WAN Architecture: Define and govern WAN and SD-WAN architectures, including dynamic routing, connectivity models and integration across global sites.
  • Dynamic Routing: Provide architectural guidance on routing protocols such as BGP and OSPF across multi-technology environments including Cisco, Aruba, Fortinet, Palo Alto and public cloud platforms.
  • Cloud Networking: Support the design of secure and resilient connectivity between on-premise environments and public/private cloud platforms, including Azure and AWS.
  • DDI Integration: Define architectural principles for DDI services, including Efficient IP integration, IP addressing, DNS/DHCP design and operational dependencies.
  • Network as Code Strategy: Define architecture principles for automated network deployment, configuration management, compliance checking and repeatable infrastructure delivery.
  • Automation Governance: Support the industrialization of network build and change processes through automation tooling, including potential use of Cisco Catalyst Center and other orchestration platforms.
  • Monitoring Architecture: Define monitoring requirements, key metrics, alerting principles, and observability expectations for network services.
  • Operational Readiness: Ensure that monitoring, logging, performance indicators and support procedures are included in network architecture deliverables before production release.
  • Tooling Alignment: Work with engineering and operations teams to align network tooling with architecture principles, operational requirements and security expectations.
5. Project Support, Technical Leadership & Transition to RUN
  • Architecture Support to Projects: Provide architecture support to deployment, migration, security and transformation projects across global network infrastructures.
  • Technical Leadership: Guide network engineers and project teams on complex design decisions, particularly around Cisco ACI, dynamic routing, SD-WAN, segmentation, firewalling and cloud connectivity.
  • Design Documentation: Produce and validate architecture documentation, including high-level designs, architecture decision records, network diagrams, design standards and technical principles.
  • Transition to RUN: Ensure that solutions are production-ready by validating runbooks, DEX documentation, operational procedures, support models and knowledge transfer materials.
  • International Enablement: Support and guide local IT teams during deployment, migration or transformation phases, ensuring consistent understanding of the target architecture.
  • Technical Committees: Participate in architecture boards, technical committees, steering committees and project governance forums.
  • Project Tracking: Contribute to technical planning, dependency tracking and delivery governance using tools such as Jira.

The Network Architect will be expected to produce or contribute to:

  • Network architecture principles and standards.
  • High-level designs and target-state architecture documents.
  • Network reference architectures and reusable design patterns.
  • Security and segmentation design principles.
  • WAN, SD-WAN, LAN, WLAN, data centre and cloud connectivity designs.
  • Routing and IP addressing standards.
  • Network diagrams and architecture views.
  • Operational-readiness checklists.
  • Technical risk assessments and mitigation recommendations.
  • Contributions to Jira tracking, technical committees and steering governance.
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Network Engineer
Network Engineer

Curium Pharma • Saclay

Sur place
EUR 55 000 - 75 000
Architecture Reseau et Securité F/H
Architecture Reseau et Securité F/H

NTT DATA, Inc. • Paris

Hybride
EUR 65 000 - 85 000
Ingénieur Sécu & Réseau N2 - IMPERATIF : Fluent English & XP > 5 ans
Ingénieur Sécu & Réseau N2 - IMPERATIF : Fluent English & XP > 5 ans

Tricefal • France

Sur place
EUR 45 000 - 65 000
Architecte Réseau
Architecte Réseau

TDS By Nomios ⭕️ Cyber, Network & Security Talent Profiler • Le Havre

Sur place
EUR 60 000 - 90 000
Responsable Infrastructure & Architecture
Responsable Infrastructure & Architecture

Jobtailor • Mougins

Sur place
EUR 90 000 - 120 000
Network & Security Architect - freelance - hybrid - Ile de France
Network & Security Architect - freelance - hybrid - Ile de France

Comgent • Besné

Sur place
EUR 60 000 - 80 000
Security and Network Engineer
Security and Network Engineer

Jobtailor • Marcoussis

Sur place
EUR 65 000 - 90 000
Senior Network Engineer
Senior Network Engineer

Jobtailor • Guyancourt

Sur place
EUR 70 000 - 110 000
Network and Security Administrator Consultant
Network and Security Administrator Consultant

Jobtailor • Bondoufle

Sur place
EUR 65 000 - 110 000
Network & Security Architecture Manager (Transition Manager)
Network & Security Architecture Manager (Transition Manager)

Devoteam • France

Sur place
EUR 70 000 - 90 000
Suivi de carrière régulier
Accès à des certifications techniques
Activités communautaires et sportives