Network Security Architect
Ideal Candidate :
Senior Network Security Architect + strong enterprise networking/security architecture + hands-on PQC knowledge (FIPS 203/204/205) + experience assessing PQC readiness and its impact on Firewalls, WAF, NAC, Proxy, VPN/PKI and perimeter security.
Role Overview
We are looking for a Senior Network Security Architect who can design and secure large enterprise network environments across on-prem, data center, and multi-cloud platforms.
The most important differentiator for this role is Post-Quantum Cryptography (PQC) expertise, specifically NIST FIPS 203, FIPS 204, and FIPS 205, and how PQC impacts network security technologies.
Critical Must-Haves
1. Post-Quantum Cryptography – Key Requirement
- Strong understanding of NIST PQC standards: FIPS 203, 204, and 205.
- Experience assessing or planning PQC readiness within enterprise environments.
- Understanding of the “Harvest Now, Decrypt Later” threat.
- Ability to assess the impact of PQC on:
- Firewalls / NGFW
- Web Application Security
- Network Access Control (NAC)
- Proxy infrastructure
- Perimeter/Email Security
- VPN and encryption technologies
- PKI / certificates
- Ability to provide recommendations for PQC migration and cryptographic modernization.
2. Network Security Architecture
- 8+ years of enterprise networking experience.
- 3+ years in Network/Cybersecurity Architecture.
- Strong knowledge of:
- LAN/WAN
- BGP, MPLS, IP Routing
- SD-WAN
- VPN
- Data Center Networking
- Zero Trust Architecture
- Network segmentation / secure zoning
- Experience designing security architecture using NGFW, IDS/IPS and NAC.
3. Security Technologies
Hands-on experience with one or more of:
- Palo Alto
- Cisco
- Check Point
- SIEM
- EDR
- Proxy
- Web Application Security
- NAC
- PKI
- MFA / SSO
4. Cloud Security
Experience securing network environments in:
- AWS
- Azure
- Google Cloud Platform
Must understand cloud network perimeters, connectivity, segmentation and secure integration with enterprise/on-prem networks.
5. Risk, Compliance & Regulatory
- Experience performing security assessments, gap analysis and vulnerability assessments.
- Familiarity with NIST, CIS and SANS frameworks.
- Financial-services regulatory knowledge is highly relevant, especially:
- FFIEC
- DORA
- SEC cybersecurity guidance
- Ability to incorporate security/compliance requirements into architecture recommendations and RFP deliverables.
6. Automation
- Python or PowerShell scripting for network/security automation is preferred.
Responsibilities
The architect will:
- Assess the existing network/security architecture.
- Identify security and cryptographic gaps.
- Design secure enterprise and cloud network architectures.
- Develop PQC readiness and migration recommendations.
- Evaluate the impact of PQC on existing security technologies.
- Support RFPs, technical evaluations and architecture decisions.
- Work with security engineers, project managers and senior stakeholders.
- Provide guidance during major security incidents and post-incident reviews.
Preferred Certifications
- CISSP / CISSP-ISSAP
- CCIE / CCDP
- CISM
- SABSA