Job Details
Job Description
About the Role
This principal-level individual contributor serves as Altera's senior technical authority for network security architecture and engineering. The role defines scalable security patterns, guides complex designs, and provides hands‑on expertise to strengthen the resilience, integrity, and protection of Altera’s global infrastructure and data.
Department Description
- Incident response and digital forensics
- Threat hunting and event analysis
- Security policy, standards, and governance
- Risk assessments and advisory
- Security architecture and engineering support
- Threat detection, monitoring, and forensic capabilities
- Security awareness and education
- Endpoint, network, and cloud security
As Principal Network Security Engineer/Architect
As Principal Network Security Engineer/Architect, you will shape, design, and improve the security of Altera's on-premises, cloud, and hybrid network environments. You will operate as a hands‑on technical lead and trusted advisor, influencing engineering teams through architecture, standards, technical decisions, and mentorship without direct people‑management responsibility.
Technical Strategy & Architecture Ownership
- Define and evolve Altera's enterprise network security strategy, target‑state architecture, technical roadmap, and reusable reference patterns.
- Serve as the senior technical authority for complex network security decisions, design exceptions, and modernization initiatives.
- Drive adoption of Zero Trust, least‑privilege access, micro‑segmentation, and secure‑by‑design network principles.
- Establish architecture standards, decision criteria, and measurable outcomes for attack‑path reduction, rule hygiene, segmentation coverage, resilience, and network visibility.
Network Security Architecture & Engineering
- Architect and review secure designs for data center, campus, laboratory, cloud, WAN, remote‑access, and hybrid environments.
- Design segmentation and traffic‑control models using security zones, VRFs, next‑generation firewalls, secure routing, identity‑aware access, and workload‑level controls.
- Evaluate and guide adoption of ZTNA, SWG, SASE, SD‑WAN, NDR, IDS/IPS, firewall, and network‑security automation capabilities.
- Partner with network, cloud, platform, product security, and operations teams to translate security requirements into implementable designs.
- Validate architecture through design reviews, configuration analysis, packet and flow analysis, resilience testing, and post‑implementation verification.
- Conduct ongoing firewall administration and operations including policy lifecycle management, rule administration, hardening, and exception governance.
Threat Detection, Monitoring, & Incident Response
- Provide senior technical expertise during investigations involving network intrusion, lateral movement, command‑and‑control activity, privilege misuse, and data exfiltration.
- Design and improve network telemetry, logging, detection coverage, and correlation across SIEM, NDR, firewalls, proxies, DNS, VPN, and cloud network services.
- Perform or guide packet capture, flow analysis, protocol troubleshooting, and root‑cause analysis for complex security events.
- Act as a technical escalation point during major incidents and translate findings into architecture improvements, detection enhancements, and remediation plans.
Risk Management, Governance & Compliance
- Perform security architecture and risk assessments for new systems, cloud services, network changes, and exceptions.
- Author and maintain network security standards, reference architectures, technical guidelines, and control requirements.
- Align designs with relevant frameworks and requirements, including NIST CSF, NIST SP 800-53, NIST SP 800-207, and ISO/IEC 27001.
- Provide technical evidence and remediation guidance for audits, assessments, and control‑validation activities.
Cross‑Functional Collaboration & Communication
- Serve as a trusted technical advisor to IT & Engineering teams including Network Engineering, Cloud, Infrastructure, DevOps, Product Security, Risk, Privacy, and Legal stakeholders.
- Facilitate architecture workshops and design reviews, clearly documenting decisions, risks, assumptions, and required controls.
- Translate complex technical risks into practical, business‑aligned recommendations for engineering and executive audiences.
- Influence delivery teams without direct authority and mentor engineers through technical guidance, peer review, and knowledge sharing.
Qualifications:
Required Experience
- 8+ years of progressive experience in enterprise networking and cybersecurity, including substantial experience designing security architecture for large, distributed environments.
- Demonstrated success serving as a principal engineer, architect, or senior technical authority for complex network‑security programs and transformations.
- Proven ability to own technical outcomes from discovery and requirements through design, implementation guidance, validati