We are looking for a Network Security Architect to lead the security architecture for a large-scale network consolidation program at a US-based Tier-2 Telco. The role owns security design, firewall rule consolidation, and policy definition, focusing on transforming fragmented legacy security postures into a standardized target-state architecture executable at scale. This position is ideal for professionals experienced in large-scale firewall transformations who excel at simplifying complex rule sets and designing scalable, segmented security architectures.
Responsibilities
• Translate enterprise-level security architecture into actionable, site-level security blueprints aligned with the overall program vision.
• Define and document the target-state architecture for the Network Security domain, including firewall rule consolidation, VRF-based macro-segmentation, and DDoS mitigation strategies.
• Analyze and optimize legacy security policies by consolidating overlapping firewall rules into streamlined, standardized templates.
• Collaborate closely with client Security and CISO teams, supporting design validation, risk alignment, and compliance with regulatory frameworks (e.g., CISA, HIPAA).
• Identify and resolve complex IP subnet overlaps and security-related routing conflicts flagged during data analysis phases.
• Define clear security exit criteria and guardrails as part of the migration factory Definition of Done (DoD).
• Contribute to architecture governance, including participation in architecture reviews, design approvals, and development of enterprise standards and reference architectures, while collaborating with cross-domain architects.
• 10+ years of experience in enterprise Network Security Architecture, with strong focus on large-scale firewall migrations and rule consolidation.
• Deep expertise in NAT/PAT, VRF segmentation, Zero Trust frameworks, and enterprise firewall platforms (e.g., Palo Alto, Fortinet, Cisco).
• Proven experience designing and integrating DDoS mitigation and traffic scrubbing solutions at network edges.
• Strong ability to translate complex security policies into standardized, reusable Low-Level Design (LLD) templates suitable for automated deployment.
• Solid understanding of compliance-driven architecture, with ability to align technical designs to regulatory frameworks while not owning final approvals.
• Experience working within secure client environments (VDI/VPN) and adhering to strict change control processes without direct production access.
• English proficiency at B2 (Upper-Intermediate) to C1 (Advanced) level, with strong spoken communication skills.
Benefits: enjoy a comprehensive compensation and benefits package, including health insurance, and a relocation program.
Originally posted on Himalayas