Principal Network Architect - Global Infrastructure & Cyber Resilience
Role details
Job location
Tech stack
Job description
As a Principal Network Architect at Commvault, you will play a critical role in shaping and evolving our global network strategy while remaining closely connected to implementation and execution.
This is a highly impactful, hands-on leadership role responsible for defining the long-term vision and architecture of our global connectivity environment. You will design and guide the implementation of secure, scalable network solutions-from Zero Trust and multi-cloud architectures to global routing and automation frameworks-ensuring they align with business and security objectives.
Success in this role requires a blend of strategic thinking and deep technical expertise. You will partner with senior leaders to influence direction, establish best practices and standards, and provide guidance on complex technical challenges. At the same time, you will stay engaged with the engineering teams-supporting troubleshooting, contributing to critical initiatives, and ensuring designs are executable and operationally sound., 1. Architectural Strategy & Hands-On Execution
- The First Build: Take primary accountability for translating business requirements into technical blueprints, leading the hands-on engineering and physical rollout of global SD-WAN and cloud network nodes.
- Network-as-Code (NetDevOps): Personally develop, review, and maintain programmatic infrastructure playbooks (via Terraform and Ansible) to automate the global environment, ensuring you drive execution rather than merely suggesting it.
- Deep-Dive Escalations: Serve as the absolute tier-4 engineering authority for complex network outages, leading rigorous Root Cause Analysis (RCA) sessions that translate technical failures into structural business improvements.
- Multi-Cloud & SD-WAN Sovereignty
- Cloud Routing & Transit: Architect, build, and optimize transit gateways, VPC/VNet peering, and high-speed dedicated interconnects powering a high-availability multi-cloud ecosystem across Google Cloud Platform (GCP) and Microsoft Azure .
- Zero Trust Integration: Implement functional, secure micro-segmentation and rigorous identity-based access controls across our hybrid footprint, shifting away from legacy edge assumptions to a mature ZTNA framework.
- Edge & Policy Management: Take the absolute lead in configuring secure web gateways and Next-Generation Firewalls (NGFWs). Own the global policy sets, SSL decryption strategies, and threat prevention profiles.
- Technical Governance & Mentorship
- Architectural Guardrails: Drive architectural reviews and intake processes, ensuring all business technology initiatives align with enterprise network standards and security compliance requirements.
- Vendor and Executive Interface: Lead deep technical evaluations and Quarterly Business Reviews (QBRs) with core technology providers (Palo Alto, Zscaler, Microsoft, Google) while translating highly complex technical "war stories" into clear, risk-mitigated executive summaries for BT leadership.
- Upskill the Core: Actively mentor, coach, and elevate senior and mid-level network engineers, building a high-performance culture rooted in technical precision and engineering discipline.
Requirements
- Experience: 12+ years of progressive experience in Network Architecture and Engineering within complex, global enterprise environments, with a career trajectory that proves you have retained your hands-on edge.
- Security & Edge Mastery: Proven track record of designing and deploying enterprise SD-WAN topologies alongside native, production-level ZTNA implementations.
- Core Protocol Expertise: Expert-level mastery of foundational routing, switching, and data center transport protocols, including BGP, EVPN, and VXLAN, as well as complex stateful firewall configurations.
- Cloud Architecture: Deep experience designing and managing cloud-native network systems that span multiple public cloud environments (specifically GCP and Azure), with a keen eye on operability, security, and cost efficiency.
- Automation Fluency: Strong proficiency utilizing Python, Terraform, or Ansible for production infrastructure deployment and configuration management.
- Communication Style: Exceptional written and verbal communication. You possess the executive presence to present risk profiles to senior leadership and the tactical clarity to guide a bridge call during a critical incident.
Preferred Skills & Experience
- Security/SD-WAN: Palo Alto PCNSE/PCCSE or Zscaler certifications (ZTDA/ZTDE).
- Cloud Engineering: Azure Network Engineer Associate (AZ-700). Or Google / AWS equivalent.
- General: CCIE (Route/Switch or Security) is highly valued but not required if equivalent deep architectural experience can be demonstrated.
You'll love working here because...
- Continuous professional development, product training, and career pathing
Benefits & conditions
- An inclusive company culture, opportunity to join our Employee Groups
- Generous benefits supporting your health, financial security, and work-life balance
- Employee stock purchase plan (ESPP)