Position Title: Principal Network Security Architect SASE | Multi-Cloud
Location: Remote must be in USA
Duration: 12 months plus with possible extension
Job Summary
Senior Network Security Architect with 12+ years of experience designing, securing, and automating large-scale enterprise, data center, and multi-cloud network environments.
Proven expertise in Next-Generation Firewalls, SASE/SSE platforms, SD-WAN, Zero Trust architecture, and cloud security across AWS, Azure, and Google Cloud Platform.
Adept at leading migrations, automating infrastructure using Terraform/Ansible/Python, and delivering highly available, compliant, and scalable global network solutions.
Key Responsibilities
Network Security Architecture
Design enterprise-grade secure architectures for data centers, branch networks, and hybrid/multi-cloud environments
Implement Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), CASB, and SASE/SSE frameworks
Lead NGFW strategy, segmentation, threat prevention, and policy governance
Firewall & Security Platforms
Deploy and manage Palo Alto (VM-Series, Panorama, Prisma Access), Fortinet FortiGate, Check Point, Cisco ASA/Firepower
Implement SSL decryption, IPS/IDS, URL filtering, VPNs (IPSec/SSL), and threat intelligence
Execute large-scale firewall migrations (Palo Alto Fortinet, ASA Palo Alto)
Cloud Networking & Security
Architect secure networking in AWS, Azure, and Google Cloud Platform (VPC/VNet design, routing, NAT, VPN, Transit Gateway, Interconnect)
Integrate cloud-native firewalls and security controls
Build hybrid connectivity between on-prem and cloud
SASE / SSE / SD-WAN
Design and deploy Netskope, Prisma Access, Zscaler, and SD-WAN (Cisco Viptela, Meraki, Versa)
Traffic steering, endpoint clients, DLP, CASB, RBI, and compliance controls
Replace legacy VPN/proxy solutions with modern cloud-delivered security
Automation & DevOps
Automate network and firewall deployments using Terraform, Ansible, Python
Develop API integrations and CI/CD pipelines for configuration-as-code
Use NetBox/IPAM as source of truth
Implement config drift detection, health checks, and automated provisioning
Routing & Data Center
Design BGP, OSPF, EVPN/VXLAN spine-leaf architectures
Deploy Arista, Cisco Nexus, Juniper platforms
High availability, failover, and performance optimization
Operations & Compliance
Lead incident response, troubleshooting, and performance tuning
Stream logs to SIEM/Splunk for monitoring and audit
Ensure compliance with NIST, ISO 27001, SOC2, GDPR
Mentor engineers and produce operational runbooks/documentation