Full Job Description
The Network Security Architect is responsible for defining, designing, and governing enterprise network security architectures that support business objectives, technology modernization initiatives, and risk management requirements. This role collaborates closely with internal IT teams, client managers, business stakeholders, third-party partners, vendors, and auditors to ensure effective security outcomes. Working alongside Security Engineers, the Security Architect develops secure architectural solutions and provides guidance for successful implementation and operational adoption by Security Engineers and Analysts.
What You’ll Do:
- Define and maintain the enterprise network security architecture roadmap, ensuring alignment with business objectives, risk management requirements, and technology strategies.
- Serve as the technical authority for network security architecture decisions and provide design governance across enterprise technology initiatives.
- Lead the architecture, design, and deployment of network security solutions supporting enterprise infrastructure and business applications.
- Lead the design and governance of enterprise firewall architectures, network segmentation strategies, secure remote access solutions, and Zero Trust initiatives.
- Architect, design, and review secure network and connectivity solutions across on-premises, cloud, hybrid, and third-party environments.
- Establish architectural standards and reference designs for network security technologies, including firewalls, VPNs, network access controls, and cloud-delivered security services.
- Conduct and oversee technical risk assessments and security exposure analyses across systems, networks, and applications.
- Lead security design reviews for new applications, infrastructure, and technology initiatives.
- Serve as a trusted advisor to IT and business teams by assessing and communicating security risks associated with technology changes.
- Recommend and promote information security policies, standards, best practices, and regulatory compliance requirements.
- Lead initiatives to audit security controls, address policy violations, and ensure compliance with established security standards and procedures.
- Research, evaluate, and recommend emerging security technologies and industry best practices to strengthen the organization's security posture and support strategic technology decisions.
- Drive continuous improvement of security processes, operational procedures, and departmental practices to enhance efficiency and effectiveness.
- Provide technical leadership and mentorship within the Information Security function, acting as a security subject matter expert.
- Support critical business needs by providing after-hours coverage when required.
Job Complexities & Impact
- Maintains a comprehensive understanding of information technology, cybersecurity, and business operations to align security architecture and strategic initiatives with organizational objectives.
- Applies advanced professional expertise and deep industry knowledge to address complex security, operational, and business challenges.
- Provides architectural guidance for the resolution of complex network security challenges and mentors engineers on security design and implementation best practices.
- Exercises sound judgment when making decisions, recognizing that actions and errors at this level can have significant operational, financial, regulatory, and reputational impact.
What You'll Bring:
- Minimum 5 years of experience designing, implementing, and governing enterprise network security architectures in large-scale, complex environments.
- Demonstrated experience leading the architecture and design of network security solutions, including enterprise firewalls, secure remote access, network segmentation, Zero Trust, and cloud connectivity.
- Must have experience integrating network security architectures with enterprise identity, directory, and infrastructure services.
- Must have experience evaluating security products, conducting proof-of-concept assessments, and managing vendor and strategic partner relationships.
- Must have a strong hands-on knowledge of network and security technologies, including firewalls, routers, network segmentation, access control lists (ACLs), intrusion detection/prevention systems (IDS/IPS), virtual private networks (VPNs), multifactor authentication (MFA), and public key infrastructure (PKI).
- Must have a deep understanding of networking concepts, including WAN, LAN, cloud connectivity, Internet protocols, network services, and hybrid infrastructure environments.
- Must have working knowledge of information security frameworks, standards, and regulatory requirements, including ISO 27001/27002, NIST, CIS Controls, COBIT, and related governance frameworks.
- Must have excellent communication and consulting skills, with the ability to translate technical security concepts into business-focused recommendations for stakeholders at all organizational levels.
- Has proven ability to develop and communicate security policies, standards, procedures, and architectural guidelines.
- Demonstrated ability to balance business objectives, operational requirements, and security priorities to enable secure business outcomes.
- Must have experience designing modern network security architectures, including Zero Trust, SASE/SSE, ZTNA, CASB, SD-WAN, network segmentation, and micro segmentation strategies.
- Must have proven experience designing and governing enterprise network security architectures in large-scale, complex environments.
- Must have extensive experience with Palo Alto Networks technologies, including Next-Generation Firewalls, Panorama, GlobalProtect, and Prisma Access.
- Must have experience securing cloud network architectures and hybrid connectivity models across Azure, AWS, and/or Google Cloud environments.
- Bachelor's degree in Computer Science, Information Systems, Information Security, Engineering, or a related field, or equivalent combination of education and experience.
- Advanced security training, professional certifications, and continuing education in cybersecurity, networking, and cloud technologies are preferred.
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CCSP (Certified Cloud Security Professional)
- PCNSE (Palo Alto Networks Certified Network Security Engineer)
- CCSK (Certificate of Cloud Security Knowledge)
- CCNP Security
- AWS Certified Security – Specialty
Pay Range: $129,300.00 - $172,300.00 AnnuallyThis hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on a number of factors which may include job-related knowledge, skills, experience, business requirements and geographic location.
What We Offer
By choice, we don’t simply accept individuality – we embrace it, we support it, and we thrive on it! Our People First culture is inclusive for all employees - not just because it's the right thing to do, but because it's the key to our success. We are proud to foster an authentic and inclusive workplace For All. You are free and encouraged to bring your entire, unique self to work.
Based on eligibility, First American offers a comprehensive benefits package including medical, dental, vision, 401k, PTO/paid sick leave and other great benefits like an employee stock purchase plan.