Job Title: Network Security Architect
Location: NYC (Onsite) Hybrid role
Job Type: Contract
Job Description :
Skill Cluster : AIMS-Security-NetSec.
Primary Skill : Network Security, MPLS, Azure
- Looking for only Local to NYC Security Architecture & Strategy Design
- Design and deliver comprehensive, secure network frameworks using trust domain segregation, Zero Trust Architecture (ZTA), and secure zoning principles.
- Develop technical solutions and integration strategies across LANs, WANs, SD-WAN, MPLS, data centers, and multi-cloud environments.
- Establish baseline configurations for network infrastructure, including Next-Generation Firewalls (NGFW), Intrusion Detection/Prevention Systems (IDS/IPS), and Network Access Control (NAC).Risk Assessment & Vulnerability Management Conduct routine gap analyses and security risk assessments against recognized frameworks like NIST, SANS, and CIS.
- Evaluate proposed acquisitions and software interfaces to determine how they impact the organization's overarching network security posture.
- Plan and oversee regular vulnerability scanning, penetration testing, and ethical hacking exercises.3. Access Control & Data Protection
- Define and implement secure identity federation, Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Public Key Infrastructure (PKI) systems.
- Enforce Role-Based Access Control (RBAC) to limit network access strictly by corporate necessity and specific employee roles.
- Architect data-in-transit encryption paths (IPsec/SSL VPNs) and Data Loss Prevention (DLP) parameters to mitigate data leakage.
- Required Technical Skills & Knowledge Proficient in IP routing, MPLS, BGP, SD-WAN, Wireless networks, and advanced data centre architectures.
- Security Hardware/Software: Extensive experience deploying Checkpoint, Palo Alto, or Cisco NGFWs, SIEM monitoring platforms, and Endpoint Detection and Response (EDR) solutions.
- Cloud Architecture: Hands-on experience mapping secure network perimeters inside AWS, Azure, or Google Cloud Platform (GCP) environments.
- Frameworks & Methodologies: Deep familiarity with SABSA, TOGAF, COBIT, ITIL, and DoDAF architecture frameworks.
- Automation & Scripting: Capability to write code in Python or PowerShell to automate network provisioning and logging configurations..
- Certifications (Highly Preferred):Certified Information Systems Security Professional (CISSP) or Information Systems Security Architecture Professional (CISSP-ISSAP).Cisco Certified Internetwork Expert (CCIE) or Cisco Certified Design Professional (CCDP).Certified Information Security Manager (CISM) or SABSA Chartered Security Architect