Senior Network Security Architect/Engineer
Location: Remote
We are seeking a Senior Network Security Engineer/Architect with a strong security mindset and the ability to apply risk-based decision-making to drive the design, implementation, and operational management of enterprise network security controls. This role is responsible for securing hybrid environments across on-premises, cloud, and OT/PCN networks while advancing the organization's Zero Trust strategy.
The ideal candidate combines deep hands-on engineering expertise with architectural ownership and can lead complex initiatives, including M&A integrations, security platform modernization, and the protection of high-trust environments. This role requires the ability to evaluate not only how to implement security solutions, but also whether they should be implemented based on risk, business requirements, and long-term security impact.
Key Responsibilities
1. Security Architecture & Strategy
- Define and enforce enterprise network security standards, including firewall governance, least-privilege principles, and network segmentation.
- Design and drive Zero Trust architecture, including identity-aware and persona-based access controls.
- Develop secure network architectures for cloud, hybrid, and internet-facing environments.
- Lead network security workstreams for Mergers & Acquisitions (M&A), including integration planning and risk reduction.
- Drive adoption and maturity of Zscaler capabilities and the organization's Zero Trust strategy.
- Design and implement security controls for Specific Use Networks (SUN) and other controlled environments.
- Architect and secure high-trust environments, including Operational Technology (OT) and Process Control Networks (PCN).
2. Network Security Engineering, Operations & Delivery
- Design, implement, and administer enterprise firewall solutions.
- Configure, manage, and optimize Zscaler (ZIA/ZPA) for secure internet and private application access.
- Manage and tune Web Application Firewall (WAF) platforms such as Akamai to protect internet-facing applications.
- Design and manage IPsec VPN connectivity for B2B partners, including encryption standards, security policies, and lifecycle management.
- Monitor, troubleshoot, and resolve complex network security issues across distributed enterprise environments.
- Implement network segmentation, monitoring, and security controls aligned with industry best practices.
- Balance operational requirements with security controls across business-critical and high-trust environments.
- Conduct periodic firewall rule reviews to ensure compliance with security standards and audit requirements.
- Ensure adherence to regulatory requirements and internal security policies.
- Support security audits, risk assessments, and incident response activities when required.
Required Qualifications
Experience
- 8+ years of experience in Network Security Engineering or Network Security Architecture.
Technical Expertise
Strong hands-on experience with:
- Enterprise firewall platforms
- Zscaler (ZIA/ZPA) or equivalent SSE/SASE platforms
- Web Application Firewall (WAF) technologies such as Akamai, Cloudflare, or F5
Strong understanding of:
- Zero Trust architecture principles
- Network protocols, routing, and segmentation (TCP/IP, BGP, VPNs, etc.)
- Secure application and web traffic flows
- Troubleshooting complex, large-scale distributed network environments
Additional requirements:
- Proven ability to lead technical initiatives and influence cross-functional teams.
Preferred Qualifications
- Experience with cloud platforms including Azure, AWS, or GCP and their native security services.
- Experience supporting Operational Technology (OT) or Process Control Network (PCN) environments.
- Familiarity with SASE/SSE architectures and implementations.
Preferred Certifications
- CISSP
- CISM
- PCNSE
- CCNP Security
- Equivalent network or security certifications
Key Competencies
- Strong security mindset with the ability to apply risk-based decision-making, including determining when a security solution should—or should not—be implemented.
- Excellent analytical and problem-solving skills.
- Ability to translate business risks into practical technical security controls.
- Strong communication skills with both technical teams and executive leadership.
- Proven ability to operate effectively in high-visibility, high-impact environments.
- Self-motivated with a passion for continuous improvement and advancing security maturity.