Cyber Security Architect

HCLTech

Dallas (TX)

On-site

USD 130,000 - 185,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Performance-based bonuses
Medical/Dental/Vision insurance
401(k) retirement plan
Paid time off
Paid holidays

Job summary

HCLTech seeks an experienced Level 4 Senior Network Security Consultant to oversee and optimize our security infrastructure. You will design, implement, and maintain enterprise security solutions, lead incident response, and develop security policies across cloud, network, and endpoints.

You will manage Proofpoint, Imperva WAF, Zscaler, Cisco ISE, PKI, and DLP programs, mentor staff, and collaborate with vendors to keep defenses up-to-date. Strong leadership and communication required.

Qualifications

  • Requires hands-on expertise in Proofpoint, Imperva WAF, Zscaler, Cisco ISE, PKI, DLP, CASB.
  • Designs, implements, and maintains security solutions; leads incident response and policy development.
  • Mentors staff and collaborates with vendors and IT teams.

Responsibilities

  • Manage Proofpoint email security including POD, TRAP, TAP and email security architecture.
  • Configure and troubleshoot Imperva WAF for web app security.
  • Implement and manage Zscaler cloud security platform.
  • Maintain Cisco ISE for network access control.
  • Lead incident response efforts for network security threats.
  • Conduct security assessments and audits.
  • Develop and enforce security policies and procedures.
  • Mentor junior staff and lead security projects.
  • Collaborate with vendors and cross-department teams.
  • Manage enterprise PKI including MS ADCS and certificate lifecycle.
  • Integrate Venafi for certificate automation.
  • Manage SSL/TLS certificates with DigiCert.
  • Perform PKI health checks and vulnerability remediation.
  • Enforce certificate governance and key management best practices.
  • Deploy MDCA for SaaS discovery and conditional access.
  • Operate Netskope CASB for inline and API enforcement.
  • Implement shadow IT discovery and anomaly detection.
  • Design and tune DLP across endpoints, email, and cloud.
  • Manage Microsoft Purview DLP and classify sensitive data.
  • Operate Trellix and Netskope DLP for endpoints and policy enforcement.
  • Lead false positive tuning and incident analysis.
  • Deploy and maintain endpoint security tools (CrowdStrike, Trellix).
  • Monitor endpoint alerts and respond to threats.
  • Execute updates, patching, and health checks on endpoints.
  • Enforce endpoint security policies and conduct vulnerability scans.
  • Collaborate with IT to ensure endpoint compliance.
  • Investigate and analyze security incidents; train users and staff.
  • Stay current with threats and endpoint security technologies.
  • Document procedures and incident reports.

Skills

15+ years exp
Incident response
Leadership
Threat intelligence

Education

CISSP
CCNP Security
ISE Specialist Certification
MCSE
CompTIA Security+
NCCSA
Trellix Endpoint Certification

Tools

Proofpoint
Imperva WAF
Zscaler
Cisco ISE
PKI
Venafi
DigiCert
MDCA
Netskope
CrowdStrike
Trellix

Job description

As a Level 4 Senior Network Security Consultant you will oversee and support our critical security infrastructure. This role requires hands‑on expertise with Proofpoint (POD, TRAP, TAP, Email Security), Imperva WAF, Zscaler cloud security platform, and Cisco ISE, Public Key Infrastructure (PKI), Data Loss Prevention (DLP), Cloud Access Security Broker (CASB), for managing, supporting, and optimizing endpoint security solutions such as CrowdStrike, Trellix (formerly McAfee ePolicy Orchestrator), and other endpoint protection platforms. The role involves designing, implementing, and maintaining security solutions, incident response, policy development, and supporting secure network architectures.

Key Responsibilities
  • Manage and support Proofpoint email security solutions including POD (Proofpoint On‑Demand), TRAP (Threat Response Attachment Protection), TAP (Targeted Attack Protection), and overall email security architecture.
  • Configure, monitor, and troubleshoot Imperva WAF for web application security.
  • Implement and manage Zscaler security platform for cloud‑based internet security.
  • Maintain and optimize Cisco ISE for network access control and segmentation.
  • Lead incident response efforts related to network security threats.
  • Conduct security assessments, audits, and compliance checks.
  • Develop and enforce security policies and procedures.
  • Mentor junior staff and lead security projects.
  • Collaborate with vendors and cross‑department teams to ensure security measures are effective and up‑to‑date.
  • Administer and troubleshoot enterprise PKI infrastructure including Microsoft ADCS.
  • Manage certificate lifecycle: issuance, renewal, revocation, and CRL/OCSP validation.
  • Integrate Venafi for certificate automation and orchestration across multi‑cloud/hybrid environments.
  • Manage external SSL/TLS certificates with DigiCert, including domain validation and SAN/Wildcard certs.
  • Perform PKI health checks, vulnerability remediation, and root/intermediate CA maintenance.
  • Define and implement certificate governance and key management best practices.
  • Deploy, manage, and optimize Microsoft Defender for Cloud Apps (MDCA) for SaaS discovery, OAuth app governance, and conditional access enforcement.
  • Operate Netskope CASB for inline and API mode enforcement.
  • Implement shadow IT discovery, sanctioned app policies, and anomaly detection.
  • Design, implement, and fine‑tune DLP policies across endpoint, email, and cloud channels.
  • Manage Microsoft Purview DLP including sensitive information types, EDMs, and trainable classifiers.
  • Operate Trellix (McAfee) and Netskope DLP for endpoint and policy enforcement.
  • Lead false positive tuning, incident analysis, and cross‑platform correlation.
  • Deploy, configure, and maintain endpoint security solutions including CrowdStrike Falcon, Trellix, and other AV/EDR tools.
  • Monitor endpoint security alerts and respond promptly to threats or incidents.
  • Perform regular updates, patch management, and health checks on endpoint security agents.
  • Develop and enforce endpoint security policies across the organization.
  • Conduct endpoint security assessments and vulnerability scans.
  • Collaborate with IT teams to ensure endpoints are compliant with security standards.
  • Investigate and analyze security incidents related to endpoints.
  • Provide training and support to end‑users and IT staff on endpoint security best practices.
  • Stay current with emerging threats and evolving endpoint security technologies.
  • Document procedures, incident reports, and security configurations.
Required Skills
  • 15+ years of experience, strong knowledge of network security protocols, endpoint, and data security architectures.
  • Experience with incident response and forensic analysis.
  • Communication and leadership skills.
  • Ability to stay current with emerging security threats and technologies.
Certifications Preferred
  • Certified Information Systems Security Professional (CISSP)
  • Cisco Certified Network Professional (CCNP) Security
  • Proofpoint Certified Security Professional
  • Imperva Certified Security Professional
  • Cisco Identity Services Engine (ISE) Specialist Certification (if available)
  • MCSE, SC‑200
  • Trellix DLP
  • Netskope Certified Cloud Security Administrator (NCCSA)
  • CompTIA Security+.
  • Certified Endpoint Security Professional
  • CompTIA Security+ or CySA+
  • Trellix Endpoint Security Certification
Disclaimer

HCL is an equal opportunity employer, committed to providing equal employment opportunities to all applicants and employees regardless of race, religion, sex, color, age, national origin, pregnancy, sexual orientation, physical disability or genetic information, military or veteran status, or any other protected classification, in accordance with federal, state, and/or local law. Should any applicant have concerns about discrimination in the hiring process, they should provide a detailed report of those concerns to secure@hcltech.com for investigation.

Compensation and Benefits

A candidate’s pay within the range will depend on their work location, skills, experience, education, and other factors permitted by law. This role may also be eligible for performance‑based bonuses subject to company policies. In addition, this role is eligible for the following benefits subject to company policies: medical, dental, vision, pharmacy, life, accidental death & dismemberment, and disability insurance; employee assistance program; 401(k) retirement plan; 10 days of paid time off per year (some positions are eligible for need‑based leave with no designated number of leave days per year); and 10 paid holidays per year.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CyberSecurity Delivery Manager
CyberSecurity Delivery Manager

HCLTech • East Brunswick Township (NJ)

On-site
USD 118,000 - 182,000
Medical, dental, and vision insurance
401(k) retirement plan
10 paid holidays per year
+1
Senior Network Engineer
Senior Network Engineer

HCLTech • Town of Florida (NY)

On-site
USD 120,000 - 170,000
Network Engineer
Network Engineer

HCLTech • Quincy (MA)

On-site
USD 140,000 - 190,000
Network and Security Service Delivery Manager
Network and Security Service Delivery Manager

HCLTech • Portland (OR)

On-site
USD 84,000 - 148,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
+1
Senior Network Engineer
Senior Network Engineer

HCLTech • Downers Grove (IL)

On-site
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+2
Engineer III - Security Analyst
Engineer III - Security Analyst

IEHP • Rancho Cucamonga (CA)

On-site
USD 135,000 - 179,000
Competitive salary
On-site fitness center
Medical, Dental, Vision
+8
Cybersecurity Engineer – Threat Hunting & Security Validation
Cybersecurity Engineer – Threat Hunting & Security Validation

Cognizant • Blaine (MN)

On-site
USD 115,000 - 134,000
Medical/Dental/Vision/Life Insurance
Paid holidays + PTO
401(k) plan
Cyber Security Architect
Cyber Security Architect

HCLTech • Frisco (TX)

On-site
USD 72,000 - 134,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Cyber Threat Defense - Security Operations Engineer
Senior Cyber Threat Defense - Security Operations Engineer

Segment (Twilio) • Draper (UT)

On-site
USD 110,000 - 160,000
Competitive compensation
Comprehensive benefits
Flexible work environment
+1
Staff Information Security Engineer - Threat Defense & Automation
Staff Information Security Engineer - Threat Defense & Automation

Proofpoint • Draper (UT)

Hybrid
USD 137,000 - 276,000
Competitive pay
Comprehensive benefits
Flexible work environment
+3