Network Security Architect
Brentwood, TN - USA
Job Summary
JOB SUMMARY
The Network Security Architect is responsible for defining designing and governing the enterprise network security architecture that protects Delek USs corporate refinery pipeline terminal retail and cloud environments. This role establishes strategic network security direction develops enterprise security standards and ensures security architectures support business objectives while reducing cyber risk across Information Technology (IT) Operational Technology (OT) and cloud environments.
The Network Security Architect partners closely with Infrastructure Network Engineering Cloud Engineering Security Operations Enterprise Architecture Operations Technology (OT) Engineering and business stakeholders to develop secure scalable and resilient network architectures aligned with Zero Trust principles regulatory requirements and industry best practices.
The successful candidate will possess deep expertise in enterprise network security architecture industrial control system (ICS) security cloud networking and security strategy with the ability to translate business requirements into secure architectural solutions.
EDUCATION AND EXPERIENCE
Bachelors degree in Cybersecurity Computer Science Information Systems Engineering or a related field; or equivalent combination of education and experience.
8 years of progressive experience in network security cybersecurity architecture or enterprise infrastructure.
3 years designing enterprise network security architectures.
Experience designing and governing enterprise firewall architectures (Palo Alto Fortinet Cisco etc.).
Experience designing secure cloud networking architectures (Microsoft Azure preferred).
Experience with enterprise routing switching and SD-WAN architectures.
Experience securing large multi-site enterprise environments.
Experience with industrial control systems (ICS) and Operational Technology (OT) security is strongly preferred.
Experience leading cross-functional technology initiatives and influencing technical direction across multiple teams.
PREFERRED CERTIFICATIONS
Palo Alto Networks Certified Network Security Engineer (PCNSE)
Cisco Certified Network Professional (CCNP) Security
Cisco Certified CyberOps Professional
Fortinet NSE Certification
CISSP
Microsoft Certified: Azure Security Engineer Associate (AZ-500)
JOB REQUIREMENTS
Define and maintain the enterprise network security architecture and technology roadmap.
Develop reference architectures security standards and design patterns for enterprise networking.
Ensure network security architectures align with enterprise architecture principles.
Support security architecture reviews for infrastructure cloud and operational technology initiatives.
Develop long-term strategies for secure network modernization.
Champion Zero Trust architecture across enterprise environments.
Define enterprise firewall architecture and segmentation strategy.
Establish secure connectivity standards for corporate cloud retail refinery pipeline and terminal environments.
Define enterprise network segmentation strategies for IT and Operational Technology (OT).
Establish standards for VPN remote access third-party connectivity and secure vendor access.
Define architecture standards for SD-WAN and hybrid cloud connectivity.
Evaluate and recommend emerging network security technologies.
Provide architectural guidance for:
o Next-Generation Firewalls (NGFW)
o Intrusion Detection Systems (IDS)
o Intrusion Prevention Systems (IPS)
o Network Access Control (NAC)
o Secure Web Gateways
o DNS Security
o Web Application Firewalls (WAF)
o DDoS Protection
o Secure Remote Access
o Network Detection and Response (NDR)
o Network Microsegmentation
Provide governance and technical oversight for implementation teams responsible for deployment and administration.
Develop security architecture for refinery pipeline terminal and industrial control system environments.
Define secure architectures for IT/OT convergence.
Establish segmentation strategies between enterprise and industrial environments.
Develop secure remote access architectures for vendors and contractors.
Ensure OT security architectures align with ISA/IEC 62443 and NIST guidance.
Partner with Engineering and Operations teams to secure industrial environments while maintaining operational reliability.
Develop architecture standards for Azure networking including:
o Azure Firewall
o Network Security Groups (NSGs)
o Application Gateway
o Private Endpoints
o Azure Virtual WAN
o ExpressRoute
o Azure DDoS Protection
o Secure Hybrid Networking
Develop secure connectivity strategies between cloud and on-premises environments.
Provide architectural oversight for network security implementations.
Review proposed firewall policies and segmentation designs.
Participate in infrastructure and application design reviews.
Ensure implementations conform to enterprise architecture standards.
Guide engineering teams on secure network design and implementation.
Review technology exceptions and recommend risk-based solutions.
Define architectural requirements for network visibility and monitoring.
Collaborate with Security Operations to improve network detection capabilities.
Guide development of SIEM detection use cases.
Recommend improvements to logging telemetry and network analytics.
Support major incident investigations as a network security subject matter expert.
Develop network security standards and security baselines.
Ensure architectural alignment with:
o NIST Cybersecurity Framework (CSF)
o ISA/IEC 62443
o SOX
o CIS Critical Security Controls
Participate in enterprise risk assessments.
Support internal and external audits.
Conduct architecture risk assessments for new technologies.
Serve as the enterprise subject matter expert for network security architecture.
Mentor security engineers and network engineers.
Lead technology evaluations and proof-of-concepts.
Develop multi-year network security roadmaps.
Present architectural recommendations to technical leadership.
Drive continuous improvement of enterprise security capabilities.
Provide technical leadership and architectural guidance across the organization.
Partner closely with Enterprise Architecture Infrastructure Services Network Engineering Cloud Engineering Security Operations Identity & Access Management Operations Technology (OT) Refinery Engineering Third- party vendors and Application Development.
SUCCESS MEASURES
Enterprise network security architecture supports business growth and digital transformation.
Security architectures are consistently adopted across enterprise initiatives.
Reduced enterprise cyber risk through effective network security design.
Successful implementation of Zero Trust architecture principles.
Secure and resilient connectivity across enterprise cloud and OT environments.
Successful completion of audits with minimal findings.
Improved network visibility and threat detection capabilities.
Reduction in architectural exceptions and technical debt.
Increased standardization of network security technologies.
High stakeholder satisfaction with architectural guidance and strategic direction.
Delivery of network security roadmaps aligned with business and cybersecurity objectives.
Required Experience:
Staff IC
About Company
PTS Advance is the largest specialist provider of technical talent to the United States’ Oil, Gas & Chemicals, Power & Renewables, Life Sciences, Construction & Infrastructure, and Manufacturing industries.