Multisite Network & Security Architect

Citadel Aviation

Dallas (TX)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Citadel Aviation seeks a seasoned network and security engineer to design, operate, and secure the company’s global network and identity infrastructure across multiple hangar sites. You will ensure reliable connectivity, a hardened identity platform, and a scalable security posture in coordination with the SOC and MDR partners.

The role requires hands-on management of firewalls, switching, wireless, and endpoint security, plus vulnerability management and incident response collaboration with IT

Qualifications

  • Bachelor’s degree in IT, CS, cybersecurity, network engineering, or related field.
  • 5+ years in enterprise network engineering and information security.
  • Hands-on with Palo Alto firewalls, Cisco switching, Meraki wireless.
  • Experience with endpoint security: Defender for Endpoint, Entra ID, CA, MFA.
  • Experience with MDR/SOC partnerships.
  • Vulnerability management tooling and remediation.
  • Experience with external security assessments and audits.
  • Experience in multi-site operations with uptime and security requirements.
  • Project delivery from scope to completion with vendor coordination.
  • Strong communication to stakeholders and leadership.

Responsibilities

  • Design, operate, and secure Citadel’s network infrastructure across all sites.
  • Maintain firewalls, switching, wireless, ISP connectivity, and backup connections; design upgrades.
  • Manage voice and unified communications integrated with Microsoft 365.
  • Ensure consistent service quality across sites; travel as needed.
  • Partner with SOC/MDR on detection tuning and remediation.
  • Oversee endpoint security policy on Microsoft 365, Entra ID, and Intune.
  • Run vulnerability management with MDR provider; drive remediation.
  • Oversee identity and access management hardening (MFA, CA).
  • Coordinate third-party security reviews of vendors and integrations.
  • Deliver IT projects within networking and security scopes; budget tracking.

Skills

Network engineering
Information security
SOC/MDR collaboration
Vulnerability management
Multi-site operations
Cloud/identity security

Education

Bachelor's degree in IT/CS
Equivalent professional experience

Tools

Palo Alto
Cisco switching
Meraki wireless
Microsoft Entra ID
Microsoft Defender
Intune
Tenable Nessus
KnowBe4

Job description

Information technology is foundational to how Citadel Aviation operates at every site, from the systems that move work across the hangar floor and the shops to the platforms that support administrative staff. Secure, reliable network and identity infrastructure enable Citadel to operate without interruption, protect its work and its people, and meet its obligations to customers and partners.

This role owns the design, operation, and security of Citadel’s network and identity infrastructure across every Citadel site: reliable connectivity, a hardened identity platform, and a security posture that scales with the business. The role serves as Citadel’s internal technical counterpart to the company’s security SOC and managed detection and response (MDR) provider, partners with IT leadership and peers across IT and the business, owns assigned IT projects, and is accountable for the reliability of the network and the strength of the security posture across every site.

The technology stack includes Palo Alto next-generation firewalls, Cisco switching, Meraki wireless, Microsoft 365 with Entra ID for identity, Microsoft Defender for Endpoint and Intune for endpoint security and management, Tenable for vulnerability management, and KnowBe4 for security awareness. Security operations are delivered in partnership with an external SOC and MDR provider.

Essential Job Functions

  • Own the design, operation, and security of Citadel’s network infrastructure across all sites. Maintain firewalls, switching, wireless, ISP connectivity, and backup connectivity. Design and implement upgrades to support growth, lead network design and turn-up for new Citadel facilities, and maintain secure connectivity between sites, between sites and the cloud, and for remote users.
  • Own the design, operation, and security of Citadel’s voice and unified communications infrastructure, including the company’s calling system, VOIP infrastructure, and integration with Microsoft 365 communications.
  • Maintain consistent network and security service quality across all Citadel sites. Travel between sites is heavier during the initial standardization phase across existing sites and during turn-up of new sites, and lighter once the environment reaches steady state.
  • Perform in line with established KPIs and service-level targets, including network availability, security patch SLA, mean time to remediate vulnerabilities, mean time to respond to security incidents, and related measures. Track and report performance regularly to IT leadership.
  • Serve as the internal technical counterpart to the company’s security SOC and MDR provider, who operate detection, monitoring, and response. Partner closely on detection tuning, alert triage, investigation, and remediation.
  • Own endpoint security policy across the Microsoft 365 platform, including Microsoft Defender for Endpoint configuration, conditional access, identity hardening, and Intune security baselines. Partner with the IT manager and the support team on day-to-day operation and enforcement.
  • Own technical email security controls, including anti-phishing, anti-malware, secure transport, and tenant security configuration. Partner with the IT manager on user-facing reporting and response workflows.
  • Run Citadel’s vulnerability management process in partnership with the MDR provider. Operate scanning tooling, prioritize findings, and drive remediation across the IT organization.
  • Own identity and access management hardening, including multi-factor authentication, conditional access policy, privileged access controls, and account lifecycle hygiene.
  • Set program direction and content for Citadel’s cybersecurity awareness program, including training plans, phishing simulation strategy, and ongoing user education topics. Partner with the IT manager, who runs the user-facing activities and reporting.
  • Conduct third-party security review of new vendors, software platforms, and integrations before they enter the environment. Assess data handling, integration security, and ongoing risk; track approval and remediation.
  • Coordinate Citadel’s response to external security assessments, including penetration testing, cyber insurance reviews, customer security questionnaires, and regulatory inquiries. Scope engagements, work with vendors, maintain evidence, and track remediation.
  • Deliver assigned IT projects within networking and security, and contribute to broader IT initiatives. Coordinate with IT leadership and peers, and engage external specialists and contractors as needed.
  • Partner with IT leadership and peers in infrastructure, support, and software development on initiatives originating in those service lines. Contribute network and security expertise to keep delivery on track.
  • Own vendor relationships within the network and security portfolio, including ISPs, network hardware, security tooling, and specialized contractors. Take on broader IT vendor relationships as assigned.
  • Own the network and security operating budget, with broader budget scope as assigned. Track expenses, project upcoming needs, and provide input on annual IT budget planning.
  • Own the on-call rotation for network and security incidents. Drive diagnosis, coordinate internal and external resources, and engage directly in resolution.
  • Own incident communication for network and security events. Notify IT leadership and impacted business stakeholders, provide regular status updates throughout an incident, and deliver post-incident summaries with root cause and follow-up actions.
  • Conduct periodic internal security audits across user access, identity hygiene, configuration baselines, vulnerability posture, and policy adherence. Remediate findings in partnership with the IT manager.
  • Maintain and enforce IT network and security policies, procedures, runbooks, technical documentation, and asset inventory. Contribute to the creation and modification of policies as needed.
  • Identify and propose improvements in network design, security posture, monitoring coverage, and tool consolidation. Deliver approved initiatives.

Minimum Qualifications or Experience

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Network Engineering, or a related technical discipline. Equivalent professional experience considered in lieu of degree.
  • 5+ years of progressive experience in enterprise network engineering and information security.
  • Hands-on experience designing, deploying, and operating enterprise networks, including next-generation firewalls (Palo Alto or comparable), enterprise switching (Cisco or comparable), and wireless (Meraki or comparable).
  • Hands-on experience with endpoint security platforms, including Microsoft Defender for Endpoint and modern identity and access management (Microsoft Entra ID, conditional access, multi-factor authentication).
  • Experience operating in partnership with a managed detection and response (MDR) provider or security operations center (SOC).
  • Experience with vulnerability management, including scanning tooling (Tenable Nessus or comparable), prioritization, and driving remediation across an organization.
  • Experience operating in an environment with regular external security assessments (penetration testing, cyber insurance reviews, customer security audits) and remediating findings under deadline.
  • Experience supporting multi-site operations or production environments where uptime, security, and consistency of service are operational requirements.
  • Experience delivering IT projects from scope through completion, including scheduling, vendor coordination, and budget tracking.
  • Demonstrated ability to communicate technical concepts clearly to non-technical business stakeholders and to senior leadership.
  • Demonstrated experience adhering to and enforcing security best practices across network, endpoint, and identity domains.

Preferred Qualifications or Experience

  • Experience in aviation, aerospace, manufacturing, MRO, or other regulated operational environments.
  • Active IT industry certifications such as CompTIA Security+ or Network+, Cisco CCNA / CCNP, Palo Alto PCNSA / PCNSE, Microsoft Security or Identity certifications, CISSP, GIAC, or comparable.
  • Experience designing and bringing up network infrastructure at new sites or facilities.
  • Experience with SD-WAN, zero-trust architecture, network segmentation, or related modern network design patterns.
  • Familiarity with security frameworks (NIST, CIS) and audit or compliance work.
  • Experience with security awareness platforms (KnowBe4 or comparable).
  • Experience administering identity and access controls in a hybrid or cloud-first environment.
  • Experience with VOIP or unified communications infrastructure.

Supervisory Responsibilities

  • This position has no direct reports.
  • Coordinates day-to-day with external network and security contractors, managed-service providers, and the company’s SOC and MDR partner.
  • Provides technical guidance and security expertise to IT team peers and to business stakeholders as needed.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network & Security Engineer
Network & Security Engineer

Citadel Aviation • Dallas (TX)

On-site
USD 120,000 - 180,000
Information Technology Network Administrator
Information Technology Network Administrator

LMK Recruiting Solutions • Hillside (IL)

Hybrid
USD 70,000 - 90,000
Manager, Network & Cybersecurity Engineering-816
Manager, Network & Cybersecurity Engineering-816

Socket.dev • Tampa (FL)

On-site
USD 140,000 - 150,000
Principal Security Engineer
Principal Security Engineer

Jobtailor • New Jersey

On-site
USD 120,000 - 190,000
Senior Network Security Engineer
Senior Network Security Engineer

Liquid Environmental Solutions • Irving (TX)

On-site
USD 120,000 - 150,000
Security Engineer
Security Engineer

Cortavo, Inc. • Atlanta (GA)

Hybrid
USD 100,000 - 130,000
Competitive salary
Health benefits
Company cell phone plan
+2
Security Field Engineer III
Security Field Engineer III

Network Solutions, Inc. • Indiana (PA)

On-site
USD 110,000 - 160,000
Remote work option
Occasional travel to customer sites
Senior Network Security Engineer
Senior Network Security Engineer

Ignite IT, LLC • Suitland (MD)

On-site
USD 100,000 - 130,000
Health insurance
Flexible schedule
401(k) matching
+2
Senior Network Security Engineer
Senior Network Security Engineer

Jobtailor • New Jersey

On-site
USD 120,000 - 170,000
Cyber Security Specialist
Cyber Security Specialist

X-Bow Systems Inc. • Luling (TX)

On-site
USD 70,000 - 110,000