Lead the design, implementation, and optimization of enterprise network security infrastructures across campus, data center, and cloud environments. Collaborate with cross-functional teams to develop Zero Trust architectures and drive strategic network modernization initiatives.
This is a remote position.
Position Summary
We are seeking a Senior Network Security Architect & Engineer to lead the design, implementation, modernization, and optimization of enterprise network security infrastructures. The ideal candidate possesses deep expertise across Cisco, Palo Alto Networks, Fortinet, and Brocade technologies, with extensive experience designing Zero Trust network architectures for large enterprise environments. This role requires a hands-on technical leader who can architect secure network solutions while partnering with stakeholders to drive strategic security initiatives.
Cloud networking experience in Microsoft Azure, AWS, or Google Cloud Platform is highly desirable.
Primary Responsibilities
- Design, implement, and support enterprise network security architectures across campus, data center, branch, and cloud environments.
- Develop and implement Zero Trust network architectures aligned with NIST SP 800-207 principles.
- Design secure segmentation strategies using traditional and software-defined networking technologies.
- Architect and deploy next-generation firewall (NGFW) solutions, VPNs, secure remote access, and microsegmentation.
- Lead network modernization initiatives, including hardware refreshes, network consolidation, and migration projects.
- Design highly available and resilient network infrastructures supporting business-critical applications.
- Configure and optimize routing, switching, wireless, and security platforms.
- Conduct network security assessments, architecture reviews, and risk analyses.
- Develop network security standards, reference architectures, and technical documentation.
- Collaborate with cybersecurity, cloud, infrastructure, and application teams to integrate secure networking solutions.
- Troubleshoot complex network and security issues across hybrid environments.
- Provide technical leadership, mentoring, and knowledge transfer to engineering teams.
Required Technical Skills
Cisco Technologies
- Cisco Catalyst Switching
- Cisco Nexus Data Center Switching
- Cisco ISR / ASR Routers
- Cisco ACI
- Cisco Firepower
- Cisco Secure Firewall
- Cisco Identity Services Engine (ISE)
- Cisco Secure Access (preferred)
- Cisco DNA Center
- Cisco SD-WAN
- Cisco Wireless LAN Controllers
- Cisco ThousandEyes (preferred)
Palo Alto Networks
- Palo Alto Next-Generation Firewalls
- Panorama
- GlobalProtect
- Prisma Access
- Prisma SD-WAN (preferred)
- App-ID
- User-ID
- Device-ID
- Threat Prevention
- URL Filtering
- WildFire
- DNS Security
Fortinet
- FortiGate
- FortiManager
- FortiAnalyzer
- FortiAuthenticator
- FortiNAC
- FortiSwitch
- FortiClient
- FortiWeb (preferred)
Brocade
- Brocade Fibre Channel Switching
- Brocade SAN Infrastructure
- Brocade IP Networking
- SAN Fabric Management
Networking Expertise
- Enterprise Routing & Switching
- BGP
- OSPF
- EIGRP
- VXLAN
- EVPN
- MPLS
- SD-WAN
- Software Defined Networking (SDN)
- High Availability
- Network Load Balancing
- QoS
- Network Performance Optimization
- IPv4 / IPv6
- Multicast
Network Security Expertise
- Zero Trust Architecture
- Microsegmentation
- East-West Traffic Protection
- Network Access Control (NAC)
- Identity-Based Networking
- Network Detection & Response (NDR)
- IDS / IPS
- Secure Remote Access
- Site-to-Site VPN
- Remote Access VPN
- SSL Inspection
- Network Threat Hunting
- DDoS Mitigation
- Secure DNS
- PKI
- Network Encryption
Required Experience
- 10+ years of enterprise networking experience.
- 7+ years designing and implementing enterprise network security solutions.
- Experience leading large-scale network modernization or transformation projects.
- Extensive experience with Cisco, Palo Alto Networks, Fortinet, and Brocade platforms.
- Experience designing highly available enterprise network architectures.
- Experience implementing Zero Trust network strategies.
- Experience supporting enterprise environments with multiple data centers and cloud connectivity.
- Strong troubleshooting skills across complex hybrid infrastructures.
Desired Knowledge
- SASE (Prisma Access, Cisco Secure Access, FortiSASE, Netskope, or Zscaler)
- SSE (Security Service Edge)
- Network automation using Python, Ansible, or Terraform
- Infrastructure as Code (IaC)
- Kubernetes networking
- Service mesh technologies
- Network observability platforms (ThousandEyes, Kentik, LogicMonitor, SolarWinds)
- OT/ICS network security
- AI-assisted network operations (AIOps)
Ideal Candidate Profile
The ideal candidate is a seasoned network security architect who combines deep hands-on engineering expertise with strategic architectural vision. They have successfully designed and deployed large-scale Cisco, Palo Alto, Fortinet, and Brocade environments, understand how to implement Zero Trust principles across enterprise networks, and can guide organizations through modernization initiatives spanning on-premises, hybrid, and cloud environments. They are equally comfortable developing long-term network strategies, leading complex implementations, and serving as a trusted technical advisor to executive and engineering stakeholders.