Network Security Architect

Chalmette, La
Houston, TX, United States
1 day ago
Apply on ptsadvance.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

JavaScript (Programming Language) Computer-Aided Design Google AdWords Application Firewall Microsoft Azure Network Analysis Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Information Systems Computer Networks
+31 more
DDoS Mitigation Software Design Patterns Domain Name System Security Extensions Google Analytics Identity and Access Management Intrusion Detection and Prevention Virtual Private Networks (VPN) Information Systems Security Architecture Professional JavaScript Libraries Network Security Network Architecture Routing Remote Access Technology Zero Trust Network Access Web Application Security Security Information and Event Management Software Engineering Wide Area Networks Data Logging Network Access Control Technical Debt HybridCloud Firewalls (Computer Science) Information Technology Process Control Systems Palo Alto Networks Operational Systems Fortinet CIS Benchmarks Firewall Services Module Cisco

Job description

The Network Security Architect is responsible for defining, designing, and governing the enterprise network security architecture that protects Delek US’s corporate, refinery, pipeline, terminal, retail, and cloud environments. This role establishes strategic network security direction, develops enterprise security standards, and ensures security architectures support business objectives while reducing cyber risk across Information Technology (IT), Operational Technology (OT), and cloud environments.

The Network Security Architect partners closely with Infrastructure, Network Engineering, Cloud Engineering, Security Operations, Enterprise Architecture, Operations Technology (OT), Engineering, and business stakeholders to develop secure, scalable, and resilient network architectures aligned with Zero Trust principles, regulatory requirements, and industry best practices., · Develop reference architectures, security standards, and design patterns for enterprise networking.

· Ensure network security architectures align with enterprise architecture principles.

· Support security architecture reviews for infrastructure, cloud, and operational technology initiatives.

· Develop long-term strategies for secure network modernization.

· Champion Zero Trust architecture across enterprise environments.

· Define enterprise firewall architecture and segmentation strategy.

· Establish secure connectivity standards for corporate, cloud, retail, refinery, pipeline, and terminal environments.

· Define enterprise network segmentation strategies for IT and Operational Technology (OT).

· Establish standards for VPN, remote access, third-party connectivity, and secure vendor access.

· Define architecture standards for SD-WAN and hybrid cloud connectivity.

· Evaluate and recommend emerging network security technologies.

· Provide architectural guidance for:

o Next-Generation Firewalls (NGFW)

o Intrusion Detection Systems (IDS)

o Intrusion Prevention Systems (IPS)

o Network Access Control (NAC)

o Secure Web Gateways

o DNS Security

o Web Application Firewalls (WAF)

o DDoS Protection

o Secure Remote Access

o Network Detection and Response (NDR)

o Network Microsegmentation

· Provide governance and technical oversight for implementation teams responsible for deployment and administration.

· Develop security architecture for refinery, pipeline, terminal, and industrial control system environments.

· Define secure architectures for IT/OT convergence.

· Establish segmentation strategies between enterprise and industrial environments.

· Develop secure remote access architectures for vendors and contractors.

· Ensure OT security architectures align with ISA/IEC 62443 and NIST guidance.

· Partner with Engineering and Operations teams to secure industrial environments while maintaining operational reliability.

· Develop architecture standards for Azure networking including:

o Azure Firewall

o Network Security Groups (NSGs)

o Application Gateway

o Private Endpoints

o Azure Virtual WAN

o ExpressRoute

o Azure DDoS Protection

o Secure Hybrid Networking

· Develop secure connectivity strategies between cloud and on-premises environments.

· Provide architectural oversight for network security implementations.

· Review proposed firewall policies and segmentation designs.

· Participate in infrastructure and application design reviews.

· Ensure implementations conform to enterprise architecture standards.

· Guide engineering teams on secure network design and implementation.

· Review technology exceptions and recommend risk-based solutions.

· Define architectural requirements for network visibility and monitoring.

· Collaborate with Security Operations to improve network detection capabilities.

· Guide development of SIEM detection use cases.

· Recommend improvements to logging, telemetry, and network analytics.

· Support major incident investigations as a network security subject matter expert.

· Develop network security standards and security baselines.

· Ensure architectural alignment with:

o NIST Cybersecurity Framework (CSF)

o ISA/IEC 62443

o SOX

o CIS Critical Security Controls

· Participate in enterprise risk assessments.

· Support internal and external audits.

· Conduct architecture risk assessments for new technologies.

· Serve as the enterprise subject matter expert for network security architecture.

· Mentor security engineers and network engineers.

· Lead technology evaluations and proof-of-concepts.

· Develop multi-year network security roadmaps.

· Present architectural recommendations to technical leadership.

· Drive continuous improvement of enterprise security capabilities.

· Provide technical leadership and architectural guidance across the organization.

· Partner closely with Enterprise Architecture, Infrastructure Services, Network Engineering, Cloud Engineering, Security Operations, Identity & Access Management, Operations Technology (OT), Refinery Engineering, Third- party vendors and Application Development.

SUCCESS MEASURES

· Enterprise network security architecture supports business growth and digital transformation.

· Security architectures are consistently adopted across enterprise initiatives.

· Reduced enterprise cyber risk through effective network security design.

· Successful implementation of Zero Trust architecture principles., Essential cookies enable basic functions and are necessary for the proper function of the website. Name, This cookie is used to identify a unique visitor to enhance the user experience by enabling personalized features and content based on the visitor’s preferences and browsing history. 4 weeks ipaddress This cookie is used to store the IP address of the visitor to facilitate website functionality by providing a more personalized experience. 1 day Cookie Preferences This cookie is used to store the user’s cookie consent preferences. 30 days Statistics

Statistics cookies collect information anonymously. This information helps us understand how visitors use our website. Google Analytics

Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.

Service URL: policies.google.com (opens in a new window) Name, Duration gali Used by Google Analytics to determine which links on a page are being clicked 30 seconds _ga ID used to identify users 2 years gid ID used to identify users for 24 hours after last activity 24 hours _gat Used to monitor number of Google Analytics server requests when using Google Tag Manager 1 minute _gac Contains information related to marketing campaigns of the user. These are shared with Google AdWords / Google Ads when the Google Ads and Google Analytics accounts are linked together. 90 days __utma ID used to identify users and sessions 2 years after last activity __utmt Used to monitor number of Google Analytics server requests 10 minutes __utmb Used to distinguish new sessions and visits. This cookie is set when the GA.js javascript library is loaded and there is no existing __utmb cookie. The cookie is updated every time data is sent to the Google Analytics server. 30 minutes after last activity __utmc Used only with old Urchin versions of Google Analytics and not with GA.js. Was used to distinguish between new sessions and visits at the end of a session. End of session (browser) __utmz Contains information about the traffic source or campaign that directed user to the website. The cookie is set when the GA.js javascript is loaded and updated when data is sent to the Google Anaytics server 6 months after last activity __utmv Contains custom information set by the web developer via the _setCustomVar method in Google Analytics. This cookie is updated every time new data is sent to the Google Analytics server. 2 years after last activity __utmx Used to determine whether a user is included in an A / B or Multivariate test. 18 months _ga ID used to identify users 2 years Cookie Policy

Requirements

The successful candidate will possess deep expertise in enterprise network security architecture, industrial control system (ICS) security, cloud networking, and security strategy, with the ability to translate business requirements into secure architectural solutions., · Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field; or equivalent combination of education and experience.

· 8+ years of progressive experience in network security, cybersecurity architecture, or enterprise infrastructure.

· 3+ years designing enterprise network security architectures.

· Experience designing and governing enterprise firewall architectures (Palo Alto, Fortinet, Cisco, etc.).

· Experience designing secure cloud networking architectures (Microsoft Azure preferred).

· Experience with enterprise routing, switching, and SD-WAN architectures.

· Experience securing large multi-site enterprise environments.

· Experience with industrial control systems (ICS) and Operational Technology (OT) security is strongly preferred.

· Experience leading cross-functional technology initiatives and influencing technical direction across multiple teams.

PREFERRED CERTIFICATIONS

· Palo Alto Networks Certified Network Security Engineer (PCNSE)

· Cisco Certified Network Professional (CCNP) Security

· Cisco Certified CyberOps Professional

· Fortinet NSE Certification

· CISSP, · Successful completion of audits with minimal findings.

· Improved network visibility and threat detection capabilities.

· Reduction in architectural exceptions and technical debt.

· Increased standardization of network security technologies.

· High stakeholder satisfaction with architectural guidance and strategic direction.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on ptsadvance.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Fortinet firewall administrative passwords leaked on the dark net

Chris Heilmann +1 · LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:51 min

Overview of the three Google Maps routing applications

Germán Álvarez · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all