Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
TI

Senior Network Architect

TEKFORTUNE INC
Posted 4 days ago
🇨🇦Canada🏠Remote📁Engineering & Development
Is this job info correct?

Job Description: Network Architect

Location: Remote (Canada Only)

Duration: Long term Contract


Company Overview

Client is a leader in design, manufacturing, and supply chain solutions. Our Hardware Platform Solutions (HPS) team designs and delivers cutting-edge, high-performance computing, storage, and networking hardware. To support our advanced engineering efforts, we operate highly secure, air-gapped Research and Development Labs (RDL) globally.


Must have:

  • linux command line-Understanding is good
  • Set up and Air Gap Environment (Isolated
  • Have Zscaler
  • Automation (Python, Ansible)
  • Sonic (Open Source)
  • Designing the network from Scratch. Multi geography



Position Summary

We are seeking a highly experienced and meticulous Lead Network & Security Architect to join the IT Support team for the Hardware Platform Solutions (HPS) group. In this role, you will take ownership of our global Research and Development Lab (RDL) reference architecture and drive its deployment, management, and scaling across all current and future HPS Design Centers (including Silicon Valley, Richardson, Thailand, and other global hubs).

The successful candidate will be responsible for implementing and maintaining a completely isolated, air-gapped network environment that operates independently of standard corporate IT networks. You will manage complex secure access paths, isolated VLAN provisioning, private full-mesh SD-WAN overlays, and a multi-tiered global data package replication and distribution system. You will also serve as the key enablement architect, helping project teams quickly spin up new project-specific instantiations of the RDL network model while adhering to strict security constraints.


Core Responsibilities

1. Architectural Implementation & Governance

● Deploy Reference Architecture: Standardize and implement the RDL reference design across all global HPS design locations (San Jose, Richardson, Thailand, Shanghai, SongShan Lake, Penang, Chennai and future locations).

● Support New Instantiations: Act as the primary technical design authority to spin up new RDL network instances (allocating subnets, configuring dedicated VLANs, establishing local jump hosts, and defining user authentication parameters) for upcoming HPS design

projects.

● Strict Constraint Enforcement: Maintain absolute isolation of the RDL environments. Ensure zero direct or indirect public internet connectivity and guarantee that out-of-scope systems or agents (e.g., CrowdStrike, Threat Locker, Big Fix, ServiceNow Agents, ClearPass NAC, and Windows Domain joins) are strictly excluded from the lab network.


2. Network Infrastructure & Security

● SD-WAN & Routing: Design, configure, and maintain the private, full-mesh SD-WAN overlay connecting global RDL sites.

● Secure Firewalling: Configure and administer enterprise-grade firewalls (Checkpoint 3980) protecting the perimeter of each localized lab, defining strict ingress/egress filtering rules.

● Switching & Segmentation: Manage core and access layer switches (Cisco Catalyst 9400/9200 series, Client DS2000, ES1500 switches) to segment the RDL into logical, multi-tenant VLAN environments—specifically separating Export Controlled and Non-Export Controlled network zones.


3. Identity and Remote Access Management

● Remote Customer Access: Oversee the implementation and administration of CyberArk vPAM (Virtual Privileged Access Management) for remote customer connections.

● Corporate Remote Access: Configure and maintain Zscaler ZTNA (Zero Trust Network Access) and App Connectors to terminate connections securely on Linux-based local jump hosts.

● Decentralized Authentication: Design and maintain a secure user management protocol on jump hosts and local RDL nodes. As the RDL operates without Windows Active Directory, you will define standard operating procedures for the manual/programmatic creation of local system accounts and localized role-based access control (RBAC).


4. Secure Data Package Management & DevOps Repo Architecture

● Repository Architecture: Maintain the multi-tier secure data distribution system:

1. IT Repository Server: Internet-facing ingestion nodes (running on Hyper-V/Dell PowerEdge) to securely pull packages, drivers, and applications.

2. Global Repository Server: The middle-layer relay that acts as a secure, scanned transit point between the corporate IT network and the isolated RDL network.

3. RDL Local Repository Server: Localized instances inside the labs that pull from the Global Repo and host files locally over HTTP/HTTPS at /var/www/html/repo/.

● Workflow Automation: Ensure seamless, secure, programmatically validated transfer of "transfer bundles" containing operating system packages (Rocky, Ubuntu, CentOS, etc.) across the air gap.

● Security Scans & Compliance: Coordinate with corporate IT and security teams to execute periodic vulnerability scanning and patching of repository servers, ensuring all packages undergo integrity checks before reaching the inner RDL networks.


Technical Qualifications

Education & Experience

● Bachelor’s degree in network engineering, Computer Science, Cybersecurity, or a related technical field.

● Minimum of 8+ years of experience in network architecture, with a heavy emphasis on securing air-gapped or highly isolated enterprise environments.


Required Technical Skills

● Hardware & OS Competencies: Hands-on experience with Checkpoint Firewalls (Checkpoint 3980 preferred), Cisco Catalyst 9400/9200 switches, and SilverPeak SD-WAN solutions.

● Security & Identity Tools: Expert-level understanding of CyberArk (PVWM/vPAM) and Zscaler ZTNA/Zscaler App Connectors.

● Virtualization & Systems: Solid administration experience in VMware vSphere Enterprise and/or Microsoft Hyper-V running on bare-metal systems (e.g., Dell PowerEdge R670).

● Linux Administration: Strong proficiency with Linux environments (Rocky Linux, Ubuntu, CentOS) for jump host configuration and secure HTTP/HTTPS local web repository servers (Nginx/Apache).

● Network Segmentation & Protocols: Expert in VLAN tagging, inter-VLAN routing, subnetting, IP address management (IPAM), and secure file transfer protocols.

● Automated Data Pipelines: Familiarity with script-based file synchronization and automated extraction/integrity validation mechanisms (e.g., hashing, checksums) for software deployment across isolated boundaries.


Strongly Preferred Certifications

● Checkpoint Certified Security Expert (CCSE) or Master (CCSM)

● Cisco Certified Network Professional (CCNP) - Enterprise or Security

● CyberArk Certified Defender or Sentry

● Certified Information Systems Security Professional (CISSP)


Soft Skills & Working Style

● Detailed Documentation: Proven track record of generating flawless High-Level Designs (HLD) and Low-Level Designs (LLD), block diagrams, and standard operating procedures (SOPs).

● Strategic Problem Solver: Comfortable working around strict operational boundaries where typical modern agents and automated tools are banned for security compliance.

● Cross-functional Partner: Ability to collaborate closely with HPS Design Engineers, Project Managers, Corporate IT Security, and external Customers.

● Financial Stewardship: Ability to work closely with procurement to specify, justify, and size bill of materials (BOM) for both upgrading existing sites and provisioning new infrastructure.

Similar jobs

Similar jobs

MO

Architect, Network Infrastructure

Moneris

🇨🇦Canada1 weeks ago
Miratech logo

Network Security Architect

Miratech

🌍Canada, Latin America, Poland1 weeks ago
Tech Talent International logo

Network Architect - Bilingual

Tech Talent International

🇨🇦Canada2 weeks ago
Tech Talent International logo

Network Architect

Tech Talent International

🇨🇦Canada2 weeks ago
Telesat logo

Senior IP Network Architect

Telesat

🇨🇦CanadaJun 2, 2026, 4:44 AM UTC
Honeywell logo

Lead Field Service Technician

Honeywell

🌍Australia, Canada, United States7 hours ago