Senior Network Architect — Zero-Trust & Micro-Segmentation Lead
Listed on 2026-07-08
-
IT/Tech
Cybersecurity, Network Engineer, Systems Engineer, Network Security
Job Description
Note:
Fidelity is not providing immigration sponsorship for this position.
Job Description
Note:
Fidelity is not providing immigration sponsorship for this position.
The Role
Visionary and highly technical Network Architect to protect critical assets, and enforce zero-trust principles. This architect will specialize in Network Segmentation technologies to design, implement, and evolve our next-generation enterprise network security architecture. In this role, you will be the primary blueprint contributor to define how our global network separates networks, isolates endpoint threats, and segments workloads.
You will lead the strategic shift from traditional flat networks to highly secure, micro-segmented environments across on-premises data centers, global offices, and multi-cloud infrastructure.
The Expertise and Skills You Bring
Architecture And Strategy Design Zero-Trust Frameworks
- Define the overarching architectural strategy for macro- and micro-segmentation solutions across various areas of the Fidelity Multiservice Network: global WAN, regional centers, domestic and international satellite sites, data centers, colocation centers, investor centers, and public cloud environments (AWS, Azure).
- Evaluate, pilot, and select enterprise-grade segmentation technologies, including Software-Defined Access (SD-Access), Software-Defined WAN (SD-WAN), Zero Trust Network Access (ZTNA), Next-Generation
- Develop and maintain network and security standards, reference architectures, blueprint designs and Fact Sheets, and design templates. Engineering and Implementation Micro-Segmentation Deployment:
Architect and oversee the deployment of host-based and fabric-based micro-segmentation solutions to protect critical workloads and applications.
- Integrate network segmentation policies with enterprise identity providers (IdP) and Network Access Control (NAC) systems to enforce dynamic, identity-aware access controls.
- Design secure, seamless, yet segmented connectivity between on-premise and cloud environments.
- Partner closely with partners in Enterprise Cybersecurity and Network Engineering teams to translate architectural visions, strategies, and blueprints into deployment plans.
- Ensure network architectures comply with all relevant policies, standards and guidelines.
- Provide technical leadership and mentorship to network engineering and operations teams, ensuring smooth operational handoffs.
- Network engineering and architecture. Focus on network security and segmentation initiatives.
- BGP, OSPF, EVPN-VXLAN, MPLS, VRF-Lite, and VLAN design.
- Hands-on experience and architectural design using technologies such as Cisco Trust Sec/ISE, Cisco Tetration/Secure Workload, Akamai Guardicore, Illumio, and/or Palo Alto Networks NGFW/App-.
- Strong understanding of Zero-Trust Network Access (ZTNA), Secure Access Service Edge (SASE) architectures, and stateful firewalling. In-depth knowledge of L3/4 protocols such as TCP,UDP, ICMP, and L7 protocols such as DNS, DHCP, Kerberos/NTLM, LDAP, SSH, RDP, DTLS, SMB, IKE, ISAKMP, HTTP/s, SIP, SNMP, Syslog, etc.
Fidelity’s Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.
Certifications
Category:
Information Technology
Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.#J-18808-Ljbffr
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).