We're looking for a
Principal Network Security Administrator to serve as the technical architect and highest level of internal escalation for our Zero Trust Platform, DNS Security/IPAM, and Secure Vendor Remote Access (SVRA) ecosystem-setting the strategy, standards, and architecture that keep IDEXX secure at global scale. This role also carries our newly rolled out CASB, Generative AI Control, and DLP capabilities forward as they mature.
In this role, you will...- Lead efforts to define the overall security architecture and roadmap for Zero Trust, DNS Security/IPAM, and Secure Vendor Remote Access, across current and future initiatives.
- Own enterprise DNS security and IP address management platforms (IPAM, DNS/DHCP, DNS Security), setting standards for reliability, security controls, and operational excellence.
- Architect and expand Zero Trust access, partnering with network, endpoint, and security leadership to deliver secure user/app connectivity at global scale.
- Set strategy and governance for secure third-party access through the SVRA platform, enforcing least-privilege access, strong auditing, and vendor lifecycle controls.
- Support and help mature our first-generation rollout of CASB, Generative AI Control, and DLP, partnering with the security team to expand policy coverage and adoption.
- Research and evaluate emerging security technologies, producing gap analyses and technical recommendations that shape enterprise-wide architecture decisions.
- Translate risk into engineering outcomes: drive segmentation, policy, logging, and security automation strategy that reduces exposure without slowing the business.
- Build clarity through standards and documentation: create runbooks, reference architectures, and design patterns that make secure operations repeatable and scalable across the organization.
- Serve as the highest level of internal escalation for complex network security issues; mentor other engineers through design reviews, troubleshooting, and best-practice adoption.
- Assess and report on the impact and ramifications of proposed security changes, and provide input into broader infrastructure strategy.
What you will need to succeed...- You must have 7+ years of hands-on experience in the following areas:
- Enterprise network security engineering, with demonstrated expert-level knowledge in the discipline.
- Strong experience in IPAM and DNS/DHCP, plus DNS Security administration and operational troubleshooting.
- Experience implementing Zero Trust in production enterprise environments.
- Experience managing Secure Vendor Remote Access (or closely equivalent), with security controls and auditability.
- Strong foundational skills in TCP/IP, DNS, routing, firewall concepts, authentication/authorization, and security logging/monitoring.
- Foundational knowledge of CASB, Generative AI Control, and DLP concepts and controls.
- Demonstrated ability to work independently, with guidance needed only in the most complex situations; recognized as an expert resource within and outside own discipline.
- Proven track record as technical lead on complex infrastructure/security projects, able to solve complex problems and take a broad perspective to identify solutions.
- Experience working in a global environment with 24/7 system availability requirements.
- Bachelor's degree or equivalent combination of education and experience.
- Excellent communication skills-able to translate complex technical systems into actionable decisions for technical and non-technical partners alike, and to align a single line of business around shared security outcomes.
It would be a plus if you had any of these experiences...- Automation or infrastructure-as-code experience (APIs, scripting, policy automation, CI/CD integration); proficiency automating increasingly complex administrative tasks.
- Experience integrating DNS and Zero Trust telemetry into SIEM/SOC workflows.
- Cloud networking/security exposure (Azure/AWS/GCP), plus enterprise identity integrations.
- Experience with audit/compliance frameworks (e.g., SOX) and supporting internal or external audits.
- Relevant certifications (e.g., CCNP Security, CISSP, GIAC).
What you can expect from us:• Base annual salary target starts at $120,000 and we offer more based on experience
• Opportunity for annual cash bonus
• Health / Dental / Vision Benefits Day-One
• 5% matching 401k
• Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!