Network Security Architect – Zero Trust / Cisco Secure Workload
Location: 100% Remote – Continental U.S.
Schedule: Wednesday–Sunday or Thursday–Monday
Employment: Full-Time
About the Opportunity
We are seeking an experienced Network Security Architect to support a major Zero Trust architecture implementation for a high-end financial services environment.
This is not traditional steady-state NOC work. The position is centered around high-impact weekend cutovers, Zero Trust policy enforcement, application dependency mapping, and real-time troubleshooting where technical depth, preparation, and composure are equally important.
You'll work alongside another architect and a broader technical team to ensure critical changes are properly planned, executed, validated, and—when necessary—rolled back without compromising service availability.
What You'll Do
- Execute readiness checks before scheduled cutovers and policy-enforcement windows.
- Validate configurations, dependencies, risks, and rollback procedures prior to go-live.
- Lead and support Zero Trust policy changes and network cutovers during scheduled maintenance windows.
- Perform application dependency mapping using Cisco Secure Workload (CSW).
- Use dependency data to support policy design, cutover planning, and risk assessment.
- Perform post-change validation of network functionality and security-policy enforcement.
- Troubleshoot complex issues in real time during live cutover events.
- Execute rollback procedures when necessary to protect service availability.
- Document readiness assessments, implementation results, and post-event findings.
- Communicate technical status, risks, and issues clearly to technical and business stakeholders.
- Maintain accurate project and time-tracking documentation.
Required Qualifications
- 3+ years of hands-on experience designing, operating, and troubleshooting Zero Trust data-center security environments.
- Strong experience with technologies such as:
- Microsegmentation
- Next-Generation Firewalls
- Network Access Control
- Layer 3–7 security technologies
- In-depth understanding of data-center networking protocols and principles.
- CCNP Route/Switch, CCNP Security, or equivalent demonstrated technical experience.
- Strong understanding of network-security concepts and architecture.
- Ability to troubleshoot complex network and security issues during high-pressure production events.
- Ability to communicate technical status and risk effectively to non-technical stakeholders.
- Ability to work a Wednesday–Sunday or Thursday–Monday schedule supporting weekend cutovers.
- U.S. citizenship and continental U.S. residency.
- Ability to successfully complete the required Tier II-Credit Check Enhanced federal background investigation and pre-employment drug screening.
- Strong documentation and time-management discipline.
Highly Preferred
- 3+ years of hands-on Cisco Secure Workload (CSW) experience.
- Cisco Application Centric Infrastructure (ACI) experience.
- Network/security automation, scripting, or orchestration experience.
- Advanced understanding of security protocols and architecture.
- Experience managing Cisco TAC escalations through resolution.
- Experience gathering and analyzing diagnostic evidence independently.
- Previous experience supporting financial services or other highly regulated environments.
- Previous federal background investigation or Public Trust experience.
Schedule & Engagement
This is a full-time permanent position, not a fixed-term contract.
The weekend cutover schedule is expected to continue through approximately June 2027, after which the schedule is expected to transition toward standard business hours.
The position will operate as part of a broader technical team, with two architects supporting the weekend rotation—one primarily focused on Cisco Secure Workload and the counterpart focused on Cisco ACI.
What Makes This Opportunity Different
This role is built for an engineer who performs well when the stakes are high.
You'll be working on scheduled, high-consequence infrastructure and security events where preparation matters, downtime matters, and your technical judgment matters.
You'll have significant autonomy during live events while operating within a structured readiness → cutover → validation → rollback methodology.
If your background combines data-center networking, Zero Trust, microsegmentation, Cisco technologies, and the ability to stay composed during critical production changes, this could be an excellent next step.