Hands-On Technical RequirementsCandidates must be able to demonstrate direct, hands-on experience with the following technologies - not just oversight or vendor management, but actual design, build, and operational experience: Azure Virtual Networks (VNet) - design, peering, hub-and-spoke topology, route table management, private endpoints, and service endpoints in production enterprise environmentsAWS VPC - subnet design, routing, VPC peering, PrivateLink, security groups, and network ACLs across multi-account AWS environmentsAWS Transit Gateway - multi-VPC and multi-account connectivity, route table segmentation, inter-region peering, and centralized inspection architecturesNetwork Security Groups (NSGs) - rule design, governance, and automated enforcement across Azure environments at enterprise scaleGuardicore (Akamai Segmentation) - microsegmentation policy design, ring-fencing, label-based policy enforcement, and visibility map analysis across hybrid environmentsZero Trust network access (ZTNA) - hands-on implementation and ongoing operations, not just roadmap ownershipPalo Alto Networks - next-generation firewall administration (PAN-OS, Panorama), policy management, and threat prevention across enterprise environmentsSilver Peak (Aruba EdgeConnect) SD-WAN - overlay design, path conditioning, and QoS across distributed corporate and restaurant sitesTerraform - authoring and maintaining production-grade network infrastructure modules for both Azure and AWS; remote state, workspaces, and pipeline integrationCloud network observability - flow logs, network watcher, traffic analytics, and automated alerting in multi-cloud environments. Experience in the QSR, franchise, or hospitality industry with multi-site network management at scale (10,000+ locations)Hands-on experience migrating from legacy VPN to ZTNA architectures in an enterprise environmentTerraform at scale: modular codebases, remote state management, and automated drift detection across multi-cloud environmentsExperience with Zero Trust maturity frameworks (CISA, Forrester, or NIST SP 800-207) and demonstrated progress implementing Zero Trust controlsWorking knowledge of PCI-DSS network segmentation requirements for payment card environmentsFamiliarity with AI-assisted network operations - including AIOps platforms, AI-driven anomaly detection, or the use of generative AI tooling to accelerate network automation, runbook creation, and operational troubleshooting.