Lead Network & Security Architect
We are seeking a highly experienced and meticulous Lead Network & Security Architect to join the IT Support team for the Hardware Platform Solutions (HPS) group. In this role, you will take ownership of our global Research and Development Lab (RDL) reference architecture and drive its deployment, management, and scaling across all current and future HPS Design Centers.
Core Responsibilities
- Deploy Reference Architecture: Standardize and implement the RDL reference design across all global HPS design locations.
- Support New Instantiations: Act as the primary technical design authority to spin up new RDL network instances for upcoming HPS design projects.
- Strict Constraint Enforcement: Maintain absolute isolation of the RDL environments, ensuring zero public internet connectivity and excluding out‑of‑scope systems or agents from the lab network.
Network Infrastructure & Security
- SD‑WAN & Routing: Design, configure, and maintain the private, full‑mesh SD‑WAN overlay connecting global RDL sites.
- Secure Firewalling: Configure and administer enterprise‑grade firewalls protecting the perimeter of each localized lab, defining strict ingress/egress filtering rules.
- Switching & Segmentation: Manage core and access layer switches to segment the RDL into logical, multi‑tenant VLAN environments, separating Export Controlled and Non‑Export Controlled network zones.
Identity and Remote Access Management
- Remote Customer Access: Oversee the implementation and administration of CyberArk vPAM for remote customer connections.
- Corporate Remote Access: Configure and maintain Zscaler ZTNA and App Connectors to terminate connections securely on Linux‑based local jump hosts.
- Decentralized Authentication: Design and maintain a secure user management protocol on jump hosts and local RDL nodes, defining local system accounts and role‑based access control.
- Repository Architecture: Maintain the multi‑tier secure data distribution system, including IT Repository Server, Global Repository Server, and RDL Local Repository Server, and ensure secure, programmatically validated transfer of transfer bundles across the air gap.
- Security Scans & Compliance: Coordinate with corporate IT and security teams to execute periodic vulnerability scanning and patching of repository servers, ensuring integrity checks before packages reach the inner RDL networks.
Required Technical Skills
- Hardware & OS Competencies: Experience with Checkpoint Firewalls, Cisco Catalyst switches, and SilverPeak SD‑WAN solutions.
- Security & Identity Tools: Expert understanding of CyberArk and Zscaler solutions.
- Virtualization & Systems: Administration experience in VMware vSphere Enterprise and/or Microsoft Hyper‑V on bare‑metal systems.
- Linux Administration: Proficiency with Linux environments for jump host configuration and secure web repository servers.
- Network Segmentation & Protocols: Expertise in VLAN tagging, inter‑VLAN routing, subnetting, IPAM, and secure file transfer protocols.
- Automated Data Pipelines: Familiarity with script‑based file synchronization and automated integrity validation mechanisms.
Strongly Preferred Certifications
- Checkpoint Certified Security Expert (CCSE) or Master (CCSM)
- Cisco Certified Network Professional (CCNP) – Enterprise or Security
- CyberArk Certified Defender or Sentry
- Certified Information Systems Security Professional (CISSP)
Soft Skills & Working Style
- Detailed Documentation: Proven track record of generating flawless high‑level and low‑level designs, block diagrams, and SOPs.
- Strategic Problem Solver: Comfortable working within strict operational boundaries where typical modern agents and automated tools are banned.
- Cross‑functional Partner: Able to collaborate closely with HPS Design Engineers, Project Managers, Corporate IT Security, and external customers.
- Financial Stewardship: Skilled at working with procurement to specify, justify, and size bill of materials for infrastructure upgrades and new sites.
Physical Demands
- Normal office environment duties, extended periods of sitting and sustained visual concentration on a computer monitor or detailed data.
- Repetitive manual movements such as data entry, using a computer mouse, and using a calculator.
Typical Education and Experience
- Bachelor’s degree in Network Engineering, Computer Science, Cybersecurity, or a related technical field.
- Minimum 8+ years of experience in network architecture, with heavy emphasis on securing air‑gapped or highly isolated enterprise environments.
Celestica is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws. This policy applies to hiring, promotion, discharge, pay, fringe benefits, job training, classification, referral and other aspects of employment and also states that retaliation against a person who files a charge of discrimination, participates in a discrimination proceeding, or otherwise opposes an unlawful employment practice will not be tolerated. All information will be kept confidential according to EEO guidelines.
Celestica is an E‑Verify employer.