Principal Network Security Architect — Zero-Trust AI Isolation

Thomas To

Santa Clara (CA)

On-site

USD 196,000 - 380,000

Full time

2 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

NVIDIA Enterprise Network Architecture is seeking a seasoned network security architect to design and implement protection frameworks across firewalls, IDS/IPS, VPNs, and scalable security tooling. You will drive identity-centric access controls, stand up secure, segmented architectures for AI workloads, and collaborate with ProdSec to deploy production-grade security features across internal networks.

You’ll work with cloud and on-prem environments, evaluating new security platforms and guiding

Qualifications

  • MS or PhD in Electrical Engineering, Computer Science, Computer Engineering, Artificial Intelligence, Data Science, Mathematics, Statistics, or equivalent experience.
  • 12+ years of experience in building, managing and supporting large scale hybrid networks on the foundations of security.
  • Experience developing automation technology with Python, Ruby, Go or other languages used in infrastructure automation.
  • Advanced knowledge of NIST CSF, CIS controls, or MITRE ATT&CK frameworks.
  • Strong knowledge of networking protocols and encryption services and how these serve elevated security posture for a network.
  • Experience evaluating and testing new vendor platforms and in-house network initiatives for security issues.
  • Knowledge of cloud platforms like AWS, Azure, or Google Cloud, and their respective security practices and services.
  • Experience working cross-functionally with identity/IAM and product security teams to turn security capabilities into org-wide standards, not just point solutions.
  • Comfort operating in ambiguity on emerging problem spaces — including securing AI agent platforms where standards and precedent are still being written.

Responsibilities

  • Build and implement network protection frameworks, including firewalls, intrusion detection/prevention systems, VPNs and other security technologies.
  • Partner with Enterprise Security — working across IAM, network access control (NAC/802.1X), and Zero Trust identity/posture-based policy so that network access decisions are increasingly driven by who/what is connecting and its security posture, not just IP/VLAN placement.
  • Partner with Product Security (ProdSec) to enable NVIDIA’s own security products and tooling for internal customers at scale — taking platforms validated in staging/pilot and driving them into org-wide production use (e.g., artifact/supply-chain scanning gates, access-control gateways, endpoint/network detection tooling), removing the friction that keeps good tooling stuck at "validated but not embraced."
  • Design network-level isolation for autonomous/agentic AI workloads ("autorun") and multi-tenant environments running disparate, co-located workloads at different trust levels — defining trust-domain boundaries, segmentation models, and long-term end-state architecture (e.g., firewall-based "chambers" today, migrating toward DPU-based zero-trust micro-segmentation as that capability matures) so that a compromised or malicious workload cannot reach other tenants or the broader corporate network.
  • Lead efforts to move NVIDIA's internal office and lab networks from a largely flat, implicitly-trusted model toward explicit east-west segmentation — internal/collapsed firewalls at key boundary points, a service-catalog-based access model, and a foundation for dynamic Zero Trust controls (posture, identity, application awareness) — without breaking existing lab/office workflows.
  • Research, evaluate, and recommend security solutions, products, and technologies that can enhance the network's security posture.
  • Partner and conduct security audits and penetration tests to assess the network's security and identify vulnerabilities.
  • Create and maintain documentation, including security policies, procedures, network diagrams, and multi-functional feasibility reviews that define clear ownership boundaries between network, identity, platform, and application-security teams.
  • Deliver guidelines, validated design standards, and direction on security standards/policies/roadmaps like Zero Trust to ensure consistent security practices across the organization. Provide domain expertise, consultation, and critical issue support.

Skills

Automation scripting
Networking security
Zero Trust
Security audits

Education

MS/PhD in Electrical Engineering, Computer Science, Computer Engineering, Artificial Intelligence, Data Science, Mathematics, Statistics, or equivalent

Tools

Python
Go
Ruby

Job description

NVIDIA Enterprise Network Architecture is seeking a seasoned network security architect to design and implement protection frameworks across firewalls, IDS/IPS, VPNs, and scalable security tooling. You will drive identity-centric access controls, stand up secure, segmented architectures for AI workloads, and collaborate with ProdSec to deploy production-grade security features across internal networks.

You’ll work with cloud and on-prem environments, evaluating new security platforms and guiding

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Security Architect — Zero-Trust AI Security
Senior Network Security Architect — Zero-Trust AI Security

NVIDIA Corporation • Santa Clara (CA)

On-site
USD 196,000 - 380,000
Senior Network Security Architect — Zero Trust & AI
Senior Network Security Architect — Zero Trust & AI

NVIDIA • Santa Clara (CA)

On-site
USD 196,000 - 380,000
Equity
Comprehensive benefits
Lead Network Security Engineer - Zero-Trust for HPC & AI Compute
Lead Network Security Engineer - Zero-Trust for HPC & AI Compute

The Consensus • San Jose (CA)

On-site
USD 180,000 - 240,000
Medical, dental, and vision packages
Waiver credit $500/month for medical
Housing subsidy $2k/month near office
+4
Senior IAM Platform Engineer | Zero Trust Leader | Equity
Senior IAM Platform Engineer | Zero Trust Leader | Equity

NVIDIA Gruppe • Santa Clara (CA)

On-site
USD 196,000 - 311,000
Equity
Benefits
Zero-Trust Network Security Engineer for HPC/AI Infra
Zero-Trust Network Security Engineer for HPC/AI Infra

Etched.ai, Inc. • San Jose (CA)

On-site
USD 120,000 - 150,000
Medical, dental, and vision packages
Housing subsidy of $2k per month
Relocation support for new employees
+2
Zero-Trust Network Security Engineer for HPC & AI Infra
Zero-Trust Network Security Engineer for HPC & AI Infra

Etched • San Jose (CA)

On-site
USD 175,000 - 275,000
Medical, dental, and vision packages
Housing subsidy
Relocation support
+3
Lead Network Security Architect - Zero Trust
Lead Network Security Architect - Zero Trust

Candescent Technologies Corporation • Atlanta (GA)

On-site
USD 130,000 - 150,000
Principal Network Security Architect
Principal Network Security Architect

ConglomerateIT • Atlanta (GA)

On-site
USD 120,000 - 150,000
Network Security Architect — Zero Trust & SASE Leader
Network Security Architect — Zero Trust & SASE Leader

ConglomerateIT • Atlanta (GA)

On-site
USD 120,000 - 150,000
Lead Security Architect for Zero-Trust AI Compute
Lead Security Architect for Zero-Trust AI Compute

Neurophos Inc. • Sunnyvale (TX), Northern (KY)

Hybrid
USD 180,000 - 240,000
100% health plan premiums coverage
HSA contributions
Unlimited PTO
+3