## **Job Description:****About the Role** This principal-level individual contributor serves as Altera’s senior technical authority for network security architecture and engineering. The role defines scalable security patterns, guides complex designs, and provides hands-on expertise to strengthen the resilience, integrity, and protection of Altera’s global infrastructure and data.**Department Description**Altera’s Information Security organization is responsible for:* Incident response and digital forensics* Threat hunting and event analysis* Security policy, standards, and governance* Risk assessments and advisory* Security architecture and engineering support* Threat detection, monitoring, and forensic capabilities* Security awareness and education* Endpoint, network, and cloud securityAs Principal Network Security Engineer/Architect, you will shape, design, and improve the security of Altera’s on-premises, cloud, and hybrid network environments. You will operate as a hands-on technical lead and trusted advisor, influencing engineering teams through architecture, standards, technical decisions, and mentorship without direct people-management responsibility.**Technical Strategy & Architecture Ownership*** Define and evolve Altera’s enterprise network security strategy, target-state architecture, technical roadmap, and reusable reference patterns.* Serve as the senior technical authority for complex network security decisions, design exceptions, and modernization initiatives.* Drive adoption of Zero Trust, least-privilege access, micro-segmentation, and secure-by-design network principles.* Establish architecture standards, decision criteria, and measurable outcomes for attack-path reduction, rule hygiene, segmentation coverage, resilience, and network visibility.**Network Security Architecture & Engineering*** Architect and review secure designs for data center, campus, laboratory, cloud, WAN, remote-access, and hybrid environments.* Design segmentation and traffic-control models using security zones, VRFs, next-generation firewalls, secure routing, identity-aware access, and workload-level controls.* Evaluate and guide adoption of ZTNA, SWG, SASE, SD-WAN, NDR, IDS/IPS, firewall, and network-security automation capabilities.* Partner with network, cloud, platform, product security, and operations teams to translate security requirements into implementable designs.* Validate architecture through design reviews, configuration analysis, packet and flow analysis, resilience testing, and post-implementation verification.* Conduct ongoing firewall administration and operations including policy lifecycle management, rule administration, hardening, and exception governance.**Threat Detection, Monitoring, & Incident Response*** Provide senior technical expertise during investigations involving network intrusion, lateral movement, command-and-control activity, privilege misuse, and data exfiltration.* Design and improve network telemetry, logging, detection coverage, and correlation across SIEM, NDR, firewalls, proxies, DNS, VPN, and cloud network services.* Perform or guide packet capture, flow analysis, protocol troubleshooting, and root-cause analysis for complex security events.* Act as a technical escalation point during major incidents and translate findings into architecture improvements, detection enhancements, and remediation plans.**Risk Management, Governance & Compliance*** Perform security architecture and risk assessments for new systems, cloud services, network changes, and exceptions.* Author and maintain network security standards, reference architectures, technical guidelines, and control requirements.* Align designs with relevant frameworks and requirements, including NIST CSF, NIST SP 800-53, NIST SP 800-207, and ISO/IEC 27001.* Provide technical evidence and remediation guidance for audits, assessments, and control-validation activities.**Cross‐Functional Collaboration & Communication*** Serve as a trusted technical advisor to IT & Engineering teams including Network Engineering, Cloud, Infrastructure, DevOps, Product Security, Risk, Privacy, and Legal stakeholders.* Facilitate architecture workshops and design reviews, clearly documenting decisions, risks, assumptions, and required controls.* Translate complex technical risks into practical, business-aligned recommendations for engineering and executive audiences.* Influence delivery teams without direct authority and mentor engineers through technical guidance, peer review, and knowledge sharing.### ## **Qualifications:****Required Experience*** 8+ years of progressive experience in enterprise networking and cybersecurity, including substantial experience designing security architecture for large, distributed environments.* Demonstrated success serving as a principal engineer, architect, or senior technical authority for complex network-security programs and transformations.* Proven ability to own technical outcomes from discovery and requirements through design, implementation guidance, validation, and operational transition.**Technical Expertise*** Deep expertise in enterprise network architecture, TCP/IP, routing, switching, BGP, DNS, TLS, proxies, VPN, firewalls, IDS/IPS, segmentation, and Zero Trust.* Hands-on experience with next-generation firewalls, firewall policy governance, ZTNA, SWG, SASE, SD-WAN, NDR, SIEM, and related network-security controls.* Strong packet capture, protocol analysis, network-flow analysis, and complex troubleshooting skills.* Experience designing secure network connectivity and controls across on-prem, cloud and hybrid environments.* Experience with common enterprise platforms such as Cisco, Palo Alto Networks, Tufin, Azure, AWS, or comparable technologies.* Strong understanding of high availability, failover, capacity, secure management planes, encrypted connectivity, and resilient architecture.**Operational & Strategic Skills*** Experience in firewall management, administration, and operations including firewall architecture, policy lifecycle management, rule recertification, configuration hardening, and operational governance.* Ability to identify and reduce attack paths, improve rule hygiene, expand segmentation coverage, and strengthen network telemetry.* Proficiency in network incident response, technical escalation, root-cause analysis, and remediation design.* Ability to establish repeatable engineering processes, architecture review methods, validation criteria, and operational runbooks.* Experience automating network-security analysis, policy management, validation, or reporting using Python, APIs, infrastructure-as-code, KQL, or similar technologies.**Communication & Influence*** Excellent executive‐level communication skills.* Ability to translate technical concepts into business‐aligned recommendations.* Strong stakeholder management across technical and non‐technical teams.