Network Security Architect
CticonsultingJob Description
About This Opportunity
CTI Staffing is partnering with a leading transportation and logistics organization to find a Network Security Architect for their network security team, based in the Fort Worth, TX area (remote with periodic onsite).
This team owns secure network infrastructure across a hybrid on-prem and cloud environment — the person in this seat will shape how the organization connects, routes, and protects traffic at enterprise scale, not just maintain what's already built.
What You'll Do
- Design and architect secure network solutions aligned to organizational security policy and compliance requirements
- Implement and manage hybrid connectivity across on-premises and cloud environments
- Configure and optimize routing protocols for performance and redundancy
- Deploy and manage next-gen firewall solutions for threat protection
- Design DNS strategies for secure name resolution and traffic management
- Architect private networking solutions including network segmentation and zero-trust design
- Translate business requirements into secure network architecture alongside cross-functional teams
- Provide technical leadership and mentoring to network engineering staff
Requirements
What You Bring
Must-Have:
- Expertise establishing and managing secure hybrid connectivity (VPN, ExpressRoute or equivalent)
- Advanced knowledge of routing protocols (BGP, OSPF) and multi-path route optimization
- Hands-on experience configuring, managing, and troubleshooting next-generation firewall platforms
- Deep understanding of DNS architecture and security (DNSSEC, DNS filtering, DNS-based threat prevention)
- Experience designing private networks, network segmentation, and zero-trust architectures
- 5+ years of network security architecture experience
- Strong cross-functional communication — able to translate business needs into technical architecture
Nice-to-Have:
- CISSP, CEH, or equivalent network security certification
- Experience in a regulated or high-availability industry (transportation, finance, healthcare)
- Experience mentoring network engineering teams
- Cloud security architecture experience (Azure preferred)
Technical Environment:
- Palo Alto Networks, Azure Firewall
- BGP, OSPF
- Azure hybrid networking (VNets, ExpressRoute)
- DNS/DNSSEC
What Success Looks Like:
- Secure network architecture designed and documented for a major hybrid connectivity initiative
- Firewall and DNS security policy implemented and validated against compliance requirements
- Trusted technical voice in cross-functional design reviews within the first 90 days