Job Title: Network Security Architect
Location: Portland, OR
Position Overview
We are seeking an experienced Network Security Architect with strong hands-on expertise in enterprise network security, SASE, Zero Trust, firewalls, secure web gateways, data loss prevention, and application security.
The ideal candidate will have extensive experience designing, implementing, migrating, and troubleshooting large-scale enterprise security environments, with deep expertise in Juniper Networks, Palo Alto Networks, Barracuda, Zscaler, Cisco ISE, and Broadcom/Symantec DLP.
Key Responsibilities
Design, implement, and maintain secure enterprise network and security architectures.
Provide hands-on administration, troubleshooting, and optimization of network security technologies.
Design and implement SASE and Zero Trust Security architectures aligned with enterprise security requirements.
Configure, manage, and troubleshoot firewalls, VPNs, security policies, routing, switching, and network access controls.
Lead firewall migrations, security technology implementations, and large-scale enterprise deployments.
Develop and maintain centralized security management and monitoring solutions.
Troubleshoot complex production issues across network, firewall, SASE, ZTNA, DLP, and web security environments.
Collaborate with network, infrastructure, application, cloud, and security teams to implement secure and scalable solutions.
Develop and tune security policies, threat-prevention controls, DLP policies, and web security policies.
Support security incident investigation, remediation, and policy optimization.
Required Technical Qualifications
1. SASE, Zscaler & Zero Trust β 6+ Years
Strong hands-on experience with SASE, Zscaler, ZIA, ZPA/ZTNA, Secure Web Gateway, and cloud security policies.
Experience with end-to-end Zscaler deployments, including:
Tenant setup and administration
Security policy configuration
SSL inspection
Authentication and identity integration
Traffic forwarding using GRE, IPSec, and PAC
Experience with user migration and application onboarding.
Strong production troubleshooting experience in Zscaler environments.
Strong understanding of SASE and Zero Trust security architecture principles.
2. Juniper Networks β 10+ Years
10+ years of experience with Juniper Networks technologies.
Strong hands-on experience with:
Juniper SRX Firewalls
VPNs
NAT
Security policies
Junos OS administration
Strong knowledge of enterprise routing and switching protocols, including:
Experience with network security implementation, troubleshooting, and optimization.
Experience with Juniper Security Director and Junos Space for centralized firewall and network management.
3. Palo Alto Networks
Hands-on experience with Palo Alto Networks NGFW and Panorama.
Strong experience with centralized firewall administration and policy management.
Experience with:
App-ID
Threat Prevention
WildFire
IPS/IDS
GlobalProtect VPN
Advanced threat-prevention capabilities
Hands-on experience with Panorama and Strata Cloud Manager.
Experience supporting firewall migrations and large-scale enterprise deployments.
4. Barracuda Networks β 6+ Years
6+ years of experience with Barracuda Networks security solutions.
Strong hands-on experience configuring and managing:
Barracuda WAF
Reverse Proxy
Load Balancing
Web Security
Experience with SSL offloading, application traffic management, and web traffic filtering.
Strong understanding of OWASP Top 10 vulnerabilities and web application security best practices.
5. Broadcom / Symantec DLP β 6+ Years
6+ years of experience with Broadcom/Symantec Data Loss Prevention (DLP) solutions.
Hands-on experience with:
Knowledge of data leakage prevention controls across:
Email
Web
USB/removable media
Endpoints
Network channels
6. Cisco ISE
Strong hands-on experience with Cisco Identity Services Engine (ISE).
Experience configuring, administering, troubleshooting, and optimizing Cisco ISE in enterprise environments.
Strong understanding of network access control, authentication, authorization, and security policy enforcement.
Core Competencies
The successful candidate should demonstrate strong practical experience in:
Enterprise Network Security Architecture
SASE & Zero Trust Architecture
Zscaler ZIA / ZPA / ZTNA
Juniper SRX & Junos OS
Palo Alto NGFW & Panorama
Barracuda WAF & Reverse Proxy
Broadcom/Symantec DLP
Cisco ISE
Firewall Migration & Enterprise Deployments
VPN, NAT & Security Policies
BGP, OSPF & VLANs
SSL Inspection & SSL Offloading
IPS/IDS & Threat Prevention
GlobalProtect
Secure Web Gateway
Data Classification & DLP Incident Management
OWASP Top 10
Production Troubleshooting