We are seeking an experienced Senior Network Security Architect to help design and guide secure, large-scale network solutions across enterprise, cloud, remote access, partner connectivity, and internet-facing environments.
This role is ideal for someone with deep experience in enterprise networking, DMZ architecture, cloud connectivity, network segmentation, firewalls, routing, switching, VPNs, and security-focused infrastructure design. This person will work closely with business, cybersecurity, engineering, and operations teams to create secure, scalable network designs that support critical business needs.
The Senior Network Security Architect will develop high-level and detailed network designs, review proposed solutions for security and architecture standards, help teams resolve design challenges, and support the delivery of complex infrastructure projects.
What You Will Do
- Design secure network solutions for enterprise, cloud, remote access, vendor, customer, and business-to-business connectivity.
- Create architecture designs for DMZ, VPN, SD-WAN, cloud, hosting, and secure external access environments.
- Partner with cybersecurity, engineering, operations, and business teams to understand requirements and translate them into practical technical designs.
- Review network design requests to ensure they meet security, performance, reliability, and scalability standards.
- Guide project teams through technical challenges and help move designs from concept to delivery.
- Serve as a technical escalation point for complex network architecture and security-related issues.
- Support proof-of-concept and lab testing for new or complex network solutions.
- Help define architecture standards, templates, best practices, and future-state roadmaps.
- Evaluate technology options and help recommend the right platforms, tools, and approaches.
- Support design reviews to ensure solutions are secure, maintainable, scalable, and aligned with company standards.
What We Are Looking For
- 10 or more years of experience in enterprise technology, network engineering, network architecture, or infrastructure architecture.
- Strong background designing secure network environments for large, complex organizations.
- Experience with cloud networking and integrating enterprise networks with platforms such as AWS, Microsoft Azure, Google Cloud Platform, or IBM Cloud.
- Strong understanding of network security, DMZ design, traffic segmentation, and secure connectivity.
- Hands-on knowledge of routing, switching, firewalls, VPNs, DNS, HTTP/S, IPv4/IPv6, and network monitoring.
- Experience with platforms and technologies such as Cisco, Arista, Cisco Nexus, Cisco ASA/Firepower, Fortinet, Catalyst, ASR, ISR, and Nexus.
- Strong understanding of protocols and concepts such as TCP/IP, OSPF, BGP, VLANs, IPsec, PKI, QoS, multicast, MPLS, port-channeling, VRRP, FHRP, VPC, VDC, and software-defined networking.
- Experience supporting DDoS protection and mitigation using tools such as Arbor, Akamai/Prolexic, F5 Silverline, or similar platforms.
- Experience working with large-scale DMZ, ISP, hosting, remote access, and partner connectivity environments.
- Familiarity with authentication and identity tools such as Active Directory, PingFederate, or similar solutions.
- Ability to use scripting or automation to improve network processes and solution delivery.
Preferred Experience
- Experience connecting enterprise environments to AWS, Azure, Google Cloud Platform, or other public cloud providers.
- Knowledge of cloud connectivity services such as Direct Connect, ExpressRoute, Cloud Interconnect, and site-to-site VPNs.
- Experience with network testing tools such as Quali CloudShell, Viavi TeraVM, or similar platforms.
- General knowledge of security technologies, including firewalls, intrusion detection, and threat protection.
- Exposure to Arista EOS, Cisco IOS-XR, IPv6 testing, and cloud-based network automation.
- Experience with Python or infrastructure automation tools such as Terraform, Ansible, NetConf, YANG, or Arista CloudVision.