Network Security Architect 35828813 Job at Pitisci & Associates, Saint Petersburg, FL

QWRPN0FwbGlwQUR2RFZDZ1VlTm9vUk5HZnc9PQ==
  • Pitisci & Associates
  • Saint Petersburg, FL

Job Description

Network Security Architect

W2 Contract (Must be a USC or have a Green Card)

No third party candidates considered

St. Petersburg, FL

Prefer candidates in the EST time zone.

Our client is seeking a Sr. Network Security Architect. This position requires Arista (no exceptions) and certifications are preferred.

Job Summary

  • Responsible for creating new network and network security architecture documents and designing complex network solutions that meet the organization's requirements for performance, automation, resiliency, scalability, security, and compliance. Work closely with the Lead Architect, Lead Engineers, and other IT teams, such as infrastructure, security, and applications, to ensure that the network is designed to meet the organization's needs.
  • Utilize standard architecture templates to design network and network security solutions and strictly adheres to enterprise standards.
  • Design comprehensive secure network solutions by carefully selecting hardware and software components, ensuring optimal alignment with project requirements and objectives.
  • Assists the Lead Architect in activities of the Network Architect Team, ensuring seamless collaboration and alignment with organizational objectives.
  • Research and recommend innovative technologies and approaches for network and network security management, upgrades, or improvements.
  • Perform complex technology and system assessments, collect business and technical requirements, and employ advanced methodologies to assess the efficiency and effectiveness of existing systems.
  • Create detailed network and network security documentation, including network diagrams and provide clear guidelines and seamless handover to network engineering team.
  • Incorporate network and network security principles and practices into network architecture, ensuring the implementation of effective security controls, such as firewalls, intrusion detection systems, and encryption protocols, to safeguard the network against cyber threats.
  • Assessing network capacity requirements based on current and projected usage patterns and planning for scalability to accommodate future growth and changing business needs.
  • Use approved architecture templates to produce and maintain documentation with regards to design and architecture principals that will aid engineers in building, configuring, and testing of new systems or system changes.
  • Maintain service level agreements of SNS metrics, key performance indicators and adhere to strict project timelines.
  • Maintain/Improve security posture, promptly addressing design issues, vulnerabilities, and security requirements according to regulatory guidelines (PCIDSS, PII, CIS, NIST)

Required:

  • Experience with architecture and design principles.
  • Experience in network and network security architecture, design, and documentation of medium-large scale enterprise networks (10,000+ users)

Experience with Cisco and Arista enterprise technologies, such as:

  • Layer 2 LAN technologies (STP, VLANs, VTP, LACP)
  • High availability technologies (VPC, SVL, HSRP, VRRP, MLAG)
  • Routing protocols concepts (BGP, EIGRP, OSPF, MPBGP, VXLAN)
  • Experience in design and documentation of data center spine and leaf fabric (Arista/Cisco).
  • Experience with SDWAN technologies (Cisco, Palo Alto ION)
  • Experience with Secure Access Service Edge (SASE) technologies (Palo Alto Prisma Access)
  • Experience with Cisco wireless technologies in a large enterprise environment (Cisco WLC, FlexConnect, CAPWAP)
  • Experience with network security protocols, intrusion detection and prevention systems, secure socket layer (SSL) protocols, and virtual private networks (VPNs),
  • Experience with Network performance optimization, capacity planning and load balancing.
  • Ability to identify and understand issues, problems, and opportunities then compare data from different sources to draw conclusions.

Desirable:

  • Experience with designing Palo Alto Centrally managed firewall platforms (NGFW Pan OS, Threat Prevention, UserID, Global Protect, and HA setup)
  • Experience with designing F5 Clusters, Load balancing, SSL decryption policies, DNS Geolocation (LTM, GTM, APM, ASM/Cloud WAF).
  • Experience with remote access VPN solutions (Global Protect, F5 BIG-IP Edge)
  • Experience with designing Network Access Control (NAC) solutions (Forescout/Cisco ISE)
  • Experience in designing secure and scalable network solutions for Cloud environments.
  • Familiarity with Certificate management (Venafi), Cryptographic protocols and algorithms, certificate PKI.
  • Familiarity with Infoblox DNS/IPAM functions.
  • Familiarity with Cloud computing principles.
  • Familiarity with Automation/scripting experience (Python, Ansible)
  • Familiarity with Network performance optimization, capacity planning and load balancing.
  • Familiarity with the following monitoring platforms: Microsoft SevOne, SolarWinds, DataDog, Splunk)
  • Familiarity with Information Security concepts, practices, and procedures, encompassing all aspects of safeguarding information assets.
  • Familiarity with Information Security programs including, but not limited to, audit reviews, risk assessment, awareness and training, identity and access management, data protections, secure SDLC, incident management, disaster recovery procedures, vulnerability assessment, penetration testing, third-party assessment, secure configurations, and patch management.
  • Familiarity with Cryptographic protocols and algorithms.
  • Familiarity with government regulations, compliance and requirements related to Information Security (e.g., GLBA, GDPR, SOXA 404, FFIEC, PCI, Privacy, HIPAA, etc.).
  • Familiarity with emerging technologies, such as 5G, software-defined networking (SDN), and network functions virtualization (NFV).

EDUCATION AND EXPERIENCE

  • Bachelor's degree in computer science, information technology or a related field.
  • 10+ years of relevant experience in Network or Information Security, or an equivalent combination of education, training and experience.
  • Financial services experience highly preferred.
  • Cisco Certified Internetwork Expert (CCIE) is Preferred
  • ITIL v3 Master Certification (Preferred)
  • Security and control certifications (CISSP, CISM, CISA, CRISC) (Preferred) GIAC/SANS Certificates (Sec504/Sec560) (Preferred)

Job Tags

Contract work, Remote job,

Similar Jobs

Cedars-Sinai

Nurse Practitioner - General & Infusion Oncology - Part-Time (20/hrs per week) - Pasadena Job at Cedars-Sinai

 ...**Licenses/Certifications:**+ Current, unrestricted California RN license required+ Current, unrestricted California Nurse Practitioner...  ...ID** : 9131**Working Title** : Nurse Practitioner - General & Infusion Oncology - Part-Time (20/hrs per week) - Pasadena**Department**... 

SIMEDHealth

PRN Medical Assistant Job at SIMEDHealth

 ...Join Our Patient-Focused Team as a PRN Medical Assistant in Ocala and Lady Lake/The Villages! Multiple shifts are available and are flexible based on your schedule. Employees should be able to commit to 8-16 hours per week. SIMEDHealth is looking for compassionate... 

Bluestone Physician Services

Behavioral Health Care Manager / Dementia Case Manager - Part-time 24 hrs/week Job at Bluestone Physician Services

 ...Behavioral Health Care Manager / Dementia Case Manager Bluestone Physician Services delivers great outcomes by bringing exceptional care to patients living with complex, chronic conditions and disabilities. Our unique, robust model of care goes beyond primary care services... 

Himalaya Wellness Company

Demand Planner Job at Himalaya Wellness Company

 ...pioneer in scientifically validated herbal healthcare. About the Role Reporting to the Operations Manager, the Demand-Supply Planner plays a crucial role in managing and...  ...Excel skills. ~ Degree in Supply Chain Management, Statistics, or business-related... 

AWH Logistics

Class C Driver Job at AWH Logistics

 ...PLEASE FOLLOW THIS LINK TO FILL OUT A MOTOR VEHICLE REPORT: AWH Logistics, LLC is looking for experienced Class C Box Truck drivers for lift gate route delivery in Leetsdale, PA. You are the key to keeping our commitment to exceed customer expectations and ensuring...