Senior Network Security Architect

Thomas To

Santa Clara (CA)

On-site

USD 196,000 - 380,000

Full time

6 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

NVIDIA Enterprise Network Architecture is seeking a seasoned network security architect to design and implement protection frameworks across firewalls, IDS/IPS, VPNs, and scalable security tooling. You will drive identity-centric access controls, stand up secure, segmented architectures for AI workloads, and collaborate with ProdSec to deploy production-grade security features across internal networks.

You’ll work with cloud and on-prem environments, evaluating new security platforms and guiding

Qualifications

  • MS or PhD in Electrical Engineering, Computer Science, Computer Engineering, Artificial Intelligence, Data Science, Mathematics, Statistics, or equivalent experience.
  • 12+ years of experience in building, managing and supporting large scale hybrid networks on the foundations of security.
  • Experience developing automation technology with Python, Ruby, Go or other languages used in infrastructure automation.
  • Advanced knowledge of NIST CSF, CIS controls, or MITRE ATT&CK frameworks.
  • Strong knowledge of networking protocols and encryption services and how these serve elevated security posture for a network.
  • Experience evaluating and testing new vendor platforms and in-house network initiatives for security issues.
  • Knowledge of cloud platforms like AWS, Azure, or Google Cloud, and their respective security practices and services.
  • Experience working cross-functionally with identity/IAM and product security teams to turn security capabilities into org-wide standards, not just point solutions.
  • Comfort operating in ambiguity on emerging problem spaces — including securing AI agent platforms where standards and precedent are still being written.

Responsibilities

  • Build and implement network protection frameworks, including firewalls, intrusion detection/prevention systems, VPNs and other security technologies.
  • Partner with Enterprise Security — working across IAM, network access control (NAC/802.1X), and Zero Trust identity/posture-based policy so that network access decisions are increasingly driven by who/what is connecting and its security posture, not just IP/VLAN placement.
  • Partner with Product Security (ProdSec) to enable NVIDIA’s own security products and tooling for internal customers at scale — taking platforms validated in staging/pilot and driving them into org-wide production use (e.g., artifact/supply-chain scanning gates, access-control gateways, endpoint/network detection tooling), removing the friction that keeps good tooling stuck at "validated but not embraced."
  • Design network-level isolation for autonomous/agentic AI workloads ("autorun") and multi-tenant environments running disparate, co-located workloads at different trust levels — defining trust-domain boundaries, segmentation models, and long-term end-state architecture (e.g., firewall-based "chambers" today, migrating toward DPU-based zero-trust micro-segmentation as that capability matures) so that a compromised or malicious workload cannot reach other tenants or the broader corporate network.
  • Lead efforts to move NVIDIA's internal office and lab networks from a largely flat, implicitly-trusted model toward explicit east-west segmentation — internal/collapsed firewalls at key boundary points, a service-catalog-based access model, and a foundation for dynamic Zero Trust controls (posture, identity, application awareness) — without breaking existing lab/office workflows.
  • Research, evaluate, and recommend security solutions, products, and technologies that can enhance the network's security posture.
  • Partner and conduct security audits and penetration tests to assess the network's security and identify vulnerabilities.
  • Create and maintain documentation, including security policies, procedures, network diagrams, and multi-functional feasibility reviews that define clear ownership boundaries between network, identity, platform, and application-security teams.
  • Deliver guidelines, validated design standards, and direction on security standards/policies/roadmaps like Zero Trust to ensure consistent security practices across the organization. Provide domain expertise, consultation, and critical issue support.

Skills

Automation scripting
Networking security
Zero Trust
Security audits

Education

MS/PhD in Electrical Engineering, Computer Science, Computer Engineering, Artificial Intelligence, Data Science, Mathematics, Statistics, or equivalent

Tools

Python
Go
Ruby

Job description

NVIDIA has been transforming computer graphics, PC gaming, and accelerated computing for more than 25 years. It’s a unique legacy of innovation that’s fueled by great technology—and amazing people. Today, we’re tapping into the unlimited potential of AI to define the next era of computing. An era in which our GPU acts as the brains of computers, robots, and self-driving cars that can understand the world. Doing what’s never been done before takes vision, innovation, and the world’s best talent. As an NVIDIAN, you’ll be immersed in a diverse, supportive environment where everyone is inspired to do their best work. Come join the team and see how you can make a lasting impact on the world.

NVIDIA Enterprise Network Architecture team is seeking experienced candidates in the extensive domain of network security. Great foundations generating documentation for architectural planning, roadmaps, designs, evaluations, test plans, along with a passion for configuration standards will set you apart. Outstanding problem-solving abilities and a comprehensive understanding of network security protocols & standards, routing, switching, automation, and a deep understanding of fundamental network theory is also critical to your success at NVIDIA. This is a broad network security architecture role spanning traditional network security design, identity-driven access control, enablement of security products at scale, and emerging problem spaces like agentic AI workload isolation — with a strong emphasis on driving adoption, not just designing on paper.

What You’ll Be Doing
  • Build and implement network protection frameworks, including firewalls, intrusion detection/prevention systems, VPNs and other security technologies.
  • Partner with Enterprise Security — working across IAM, network access control (NAC/802.1X), and Zero Trust identity/posture-based policy so that network access decisions are increasingly driven by who/what is connecting and its security posture, not just IP/VLAN placement.
  • Partner with Product Security (ProdSec) to enable NVIDIA’s own security products and tooling for internal customers at scale — taking platforms validated in staging/pilot and driving them into org-wide production use (e.g., artifact/supply-chain scanning gates, access-control gateways, endpoint/network detection tooling), removing the friction that keeps good tooling stuck at "validated but not embraced."
  • Design network-level isolation for autonomous/agentic AI workloads ("autorun") and multi-tenant environments running disparate, co-located workloads at different trust levels — defining trust-domain boundaries, segmentation models, and long-term end-state architecture (e.g., firewall-based "chambers" today, migrating toward DPU-based zero-trust micro-segmentation as that capability matures) so that a compromised or malicious workload cannot reach other tenants or the broader corporate network.
  • Lead efforts to move NVIDIA's internal office and lab networks from a largely flat, implicitly-trusted model toward explicit east-west segmentation — internal/collapsed firewalls at key boundary points, a service-catalog-based access model, and a foundation for dynamic Zero Trust controls (posture, identity, application awareness) — without breaking existing lab/office workflows.
  • Research, evaluate, and recommend security solutions, products, and technologies that can enhance the network's security posture.
  • Partner and conduct security audits and penetration tests to assess the network's security and identify vulnerabilities.
  • Create and maintain documentation, including security policies, procedures, network diagrams, and multi-functional feasibility reviews that define clear ownership boundaries between network, identity, platform, and application-security teams.
  • Deliver guidelines, validated design standards, and direction on security standards/policies/roadmaps like Zero Trust to ensure consistent security practices across the organization. Provide domain expertise, consultation, and critical issue support.
What We Need To See
  • MS or PhD in Electrical Engineering, Computer Science, Computer Engineering, Artificial Intelligence, Data Science, Mathematics, Statistics, or equivalent experience.
  • 12+ years of experience in building, managing and supporting large scale hybrid networks on the foundations of security.
  • Experience developing automation technology with Python, Ruby, Go or other languages used in infrastructure automation.
  • Advanced knowledge of NIST CSF, CIS controls, or MITRE ATT&CK frameworks.
  • Strong knowledge of networking protocols and encryption services and how these serve elevated security posture for a network.
  • Experience evaluating and testing new vendor platforms and in-house network initiatives for security issues.
  • Knowledge of cloud platforms like AWS, Azure, or Google Cloud, and their respective security practices and services.
  • Experience working cross-functionally with identity/IAM and product security teams to turn security capabilities into org-wide standards, not just point solutions.
  • Comfort operating in ambiguity on emerging problem spaces — including securing AI agent platforms where standards and precedent are still being written.
Ways To Stand Out From The Crowd
  • Experience with ML/AI as it relates to security analysis, vulnerability assessment and detection, threat modeling, malware detection, binary analysis, network analytics or other security-related research.
  • Experience working with heterogeneous security platforms and building them as code.
  • Experience driving org-wide adoption of a security standard or gate (e.g., getting a scanning/enforcement tool out of staging and into default production use across many teams).
  • Direct experience securing agentic AI / autonomous coding-agent infrastructure — sandboxing, egress control, and trust-domain isolation for workloads that complete AI-generated code with minimal human oversight.
  • Experience crafting segmentation for large-scale flat corporate and campus networks using internal firewalls, VLANs/VRFs, and NAC. You have a track record of gaining multi-functional sign-off and making the handoff operational, not just crafting it.

NVIDIA is leading the way in groundbreaking developments in Artificial Intelligence, High-Performance Computing and Visualization. The GPU, our invention, serves as the visual cortex of modern computers and is at the heart of our products and services. Our work opens up new universes to explore, enables outstanding creativity and discovery, and powers what were once science fiction inventions from artificial intelligence to autonomous cars. NVIDIA is looking for exceptional people like you to help us accelerate the next wave of artificial intelligence.

Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 196,000 USD - 310,500 USD for Level 5, and 240,000 USD - 379,50 USD for Level 6.

You will also be eligible for equity and benefits.

Applications for this job will be accepted at least until September 13, 2026.

This posting is for an existing vacancy.

NVIDIA uses AI tools in its recruiting processes.

NVIDIA is committed to fostering an inclusive work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Security Architect
Senior Network Security Architect

NVIDIA • Santa Clara (CA)

On-site
USD 196,000 - 380,000
Equity
Comprehensive benefits
Senior Network Security Architect
Senior Network Security Architect

NVIDIA Corporation • Santa Clara (CA)

On-site
USD 196,000 - 380,000
Senior Software Engineer, Security
Senior Software Engineer, Security

NVIDIA • California (MO)

On-site
USD 184,000 - 357,000
Equity
Benefits
Senior Security Architect - AI/HPC Infra (Equity Eligible)
Senior Security Architect - AI/HPC Infra (Equity Eligible)

NVIDIA • California (MO)

On-site
USD 184,000 - 357,000
Intellectual Property Security Engineer
Intellectual Property Security Engineer

NVIDIA AI • Durham (NC)

On-site
USD 184,000 - 357,000
Equity
Benefits
Senior Network Engineer - DGX Cloud
Senior Network Engineer - DGX Cloud

NVIDIA • Santa Clara (CA)

On-site
USD 168,000 - 265,000
Intellectual Property Security Engineer
Intellectual Property Security Engineer

NVIDIA • Michigan

On-site
USD 184,000 - 357,000
Intellectual Property Security Engineer
Intellectual Property Security Engineer

Nvidia Corporation • Santa Clara (CA)

On-site
USD 184,000 - 287,500
Equity
Benefits
Intellectual Property Security Engineer
Intellectual Property Security Engineer

NVIDIA • Austin (TX)

On-site
USD 184,000 - 357,000
Equity
Benefits
Intellectual Property Security Engineer
Intellectual Property Security Engineer

NVIDIA • Durham (NC)

On-site
USD 184,000 - 357,000
Equity
Benefits