Job Description
Our client a well known Financial Services Firm is seeking a Network Security Architect in their St Petersburg, Florida location!
Design and Architecture: - Utilize standardized architecture templates to design network and network security solutions that adhere strictly to enterprise standards and best practices.
- Develop comprehensive, secure network designs by selecting appropriate hardware and software components that align with project goals and organizational objectives.
- Assist the Lead Architect in coordinating activities of the Network Architecture Team, ensuring effective collaboration and alignment with business strategy.
- Research and evaluate emerging technologies and methodologies to improve network infrastructure and security posture.
- Conduct complex technology assessments, gather business and technical requirements, and evaluate existing systems for efficiency, scalability, and effectiveness.
- Provide expert-level technical guidance to architecture and engineering teams, promoting architectural excellence and successful project execution.
- Produce detailed architectural documentation, including high-level and low-level network diagrams, and deliver clear handoffs to the network engineering team.
- Implement robust network security controls, such as firewalls, IDS/IPS, VPNs, and encryption protocols, to defend against cybersecurity threats.
- Stay up-to-date on evolving network technologies, industry standards, and best practices to ensure scalable, secure, and future-ready architectures.
- Evaluate network capacity based on current and forecasted usage to ensure scalability and accommodate business growth.
Support and Documentation: - Provide ad-hoc support to network engineering and operations teams as needed.
- Maintain up-to-date architecture documents and design guidelines using approved templates to guide system configuration, testing, and implementation.
- Ensure service level agreement (SLA) compliance, track key performance indicators (KPIs), and meet all project deadlines.
- Address vulnerabilities and security design concerns promptly in accordance with regulatory frameworks (e.g., PCI DSS, PII, CIS, NIST).
Leadership and Collaboration: - Lead cross-functional collaboration to evaluate, introduce, and implement new network technologies.
- Coordinate assigned projects, taking ownership of both technical and communication deliverables.
- Align with architecture and engineering peers to support shared project and enterprise goals.
- Conduct knowledge transfer and cross-training initiatives.
- Serve as a technical leader and subject matter expert (SME) within IT project teams.
Required Skills and Experience: - Proven experience with network and network security architecture in enterprise environments (10,000+ users).
- Strong grasp of architecture and design principles.
- Expertise in Cisco and Arista enterprise technologies, including:
- Layer 2 technologies (STP, VLANs, VTP, LACP)
- High availability (VPC, SVL, HSRP, VRRP, MLAG)
- Routing protocols (BGP, OSPF, EIGRP, MP-BGP, VXLAN)
- Data center spine/leaf architecture
- SD-WAN technologies (Cisco, Palo Alto ION)
- SASE solutions (e.g., Palo Alto Prisma Access)
- Cisco wireless solutions in large-scale deployments (Cisco WLC, FlexConnect, CAPWAP)
- In-depth knowledge of network security technologies, VPNs, intrusion prevention/detection, and encryption protocols
- Capacity planning, network performance optimization, and load balancing expertise
- Strong analytical and problem-solving skills-ability to evaluate data from multiple sources and draw strategic conclusions
Preferred (Desirable) Experience: - Design of Palo Alto NGFWs (PAN-OS, Threat Prevention, GlobalProtect, HA)
- F5 Clusters and load balancing (LTM, GTM, APM, SSL policies, DNS Geolocation, ASM/Cloud WAF)
- Remote access VPN solutions (GlobalProtect, F5 BIG-IP Edge)
- Network Access Control (NAC) design (Forescout, Cisco ISE)
- Cloud network security architecture (AWS, Azure, etc.)
- Certificate management (Venafi), PKI, cryptographic protocols
- Infoblox DNS/IPAM functionality
- Automation and scripting (Python, Ansible)
- Familiarity with monitoring and observability tools (SevOne, SolarWinds, DataDog, Splunk)
Job Tags
Remote work,