Job Title: Network Security Architect -Β Architects Only!! 12 - 14+ Yrs Only
Location: Portland, OR
Position Overview
We are seeking an experienced Network Security Architect with strong hands-on expertise in enterprise network security, SASE, Zero Trust, firewalls, secure web gateways, data loss prevention, and application security.
The ideal candidate will have extensive experience designing, implementing, migrating, and troubleshooting large-scale enterprise security environments, with deep expertise in Juniper Networks, Palo Alto Networks, Barracuda, Zscaler, Cisco ISE, and Broadcom/Symantec DLP.
Key Responsibilities
- Design, implement, and maintain secure enterprise network and security architectures.
- Provide hands-on administration, troubleshooting, and optimization of network security technologies.
- Design and implement SASE and Zero Trust Security architectures aligned with enterprise security requirements.
- Configure, manage, and troubleshoot firewalls, VPNs, security policies, routing, switching, and network access controls.
- Lead firewall migrations, security technology implementations, and large-scale enterprise deployments.
- Develop and maintain centralized security management and monitoring solutions.
- Troubleshoot complex production issues across network, firewall, SASE, ZTNA, DLP, and web security environments.
- Collaborate with network, infrastructure, application, cloud, and security teams to implement secure and scalable solutions.
- Develop and tune security policies, threat-prevention controls, DLP policies, and web security policies.
- Support security incident investigation, remediation, and policy optimization.
Required Technical Qualifications
1. SASE, Zscaler & Zero Trust β 6+ Years
- Strong hands-on experience with SASE, Zscaler, ZIA, ZPA/ZTNA, Secure Web Gateway, and cloud security policies.
- Experience with end-to-end Zscaler deployments, including:
- Tenant setup and administration
- Security policy configuration
- Authentication and identity integration
- Traffic forwarding using GRE, IPSec, and PAC
- Experience with user migration and application onboarding.
- Strong production troubleshooting experience in Zscaler environments.
- Strong understanding of SASE and Zero Trust security architecture principles.
2. Juniper Networks β 10+ Years
- 10+ years of experience with Juniper Networks technologies.
- Strong hands-on experience with:
- Strong knowledge of enterprise routing and switching protocols, including:
- Experience with network security implementation, troubleshooting, and optimization.
- Experience with Juniper Security Director and Junos Space for centralized firewall and network management.
3. Palo Alto Networks
- Hands-on experience with Palo Alto Networks NGFW and Panorama.
- Strong experience with centralized firewall administration and policy management.
- Advanced threat-prevention capabilities
- Hands-on experience with Panorama and Strata Cloud Manager.
- Experience supporting firewall migrations and large-scale enterprise deployments.
4. Barracuda Networks β 6+ Years
- 6+ years of experience with Barracuda Networks security solutions.
- Strong hands-on experience configuring and managing:
- Experience with SSL offloading, application traffic management, and web traffic filtering.
- Strong understanding of OWASP Top 10 vulnerabilities and web application security best practices.
5. Broadcom / Symantec DLP β 6+ Years
- 6+ years of experience with Broadcom/Symantec Data Loss Prevention (DLP) solutions.
- Hands-on experience with:
- Experience with DLP policy tuning and sensitive-data protection.
- Knowledge of data leakage prevention controls across:
6. Cisco ISE
- Strong hands-on experience with Cisco Identity Services Engine (ISE).
- Experience configuring, administering, troubleshooting, and optimizing Cisco ISE in enterprise environments.
- Strong understanding of network access control, authentication, authorization, and security policy enforcement.
Core Competencies
- The successful candidate should demonstrate strong practical experience in:
- Enterprise Network Security Architecture
- SASE & Zero Trust Architecture
- Palo Alto NGFW & Panorama
- Barracuda WAF & Reverse Proxy
- Firewall Migration & Enterprise Deployments
- VPN, NAT & Security Policies
- SSL Inspection & SSL Offloading
- IPS/IDS & Threat Prevention
- Data Classification & DLP Incident Management
- Production Troubleshooting