
Network Architect
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in Mexico.
• Develop a globally uniform network architecture that enhances security, resilience, cloud readiness, operational simplicity, and business continuity while addressing the specific needs of manufacturing sites.
• Take ownership and evolve global reference architectures for WAN, LAN, WLAN, internet edge, firewalls, remote access, cloud connectivity, and network services.
• Convert business, security, and operational requirements into actionable roadmaps, design principles, approved patterns, and lifecycle standards.
• Define the target architecture for SASE, SD-WAN, Zero Trust network access, and secure branch connectivity, including the transition and coexistence from legacy services.
• Establish a standard site blueprint for manufacturing, R&D, distribution, and corporate locations, incorporating resilient connectivity tiers, segmentation patterns, and technology selection criteria.
• Serve as the design authority for significant network changes, ensuring that solutions are supportable, cost-effective, secure, and aligned with global strategy.
• Design robust Azure network architectures, including hub-and-spoke connectivity, routing domains, BGP policy, VPN/ExpressRoute integration, cloud firewalls, load-balancing dependencies, and high availability across regions.
• Identify and address routing asymmetry, overlapping paths, failover, and convergence risks across cloud hubs, branch connectivity, and security enforcement points.
• Define secure connectivity patterns between Azure, AWS, SaaS platforms, business partners, internet-facing services, and the global enterprise network.
• Collaborate with Cloud, Cybersecurity, and Application teams to ensure that network architecture meets availability, performance, observability, and recovery requirements.
• Architect firewall, VPN, and remote access solutions utilizing Palo Alto Networks technologies and associated cloud-delivered security services.
• Develop scalable IT/OT segmentation and zone-based security patterns for manufacturing environments in partnership with Cybersecurity and OT stakeholders.
• Enhance network access control and identity-based access using technologies such as Cisco ISE, 802.1X, and complementary edge-security controls.
• Ensure designs adhere to least-privilege, defense-in-depth, and secure-by-design principles while remaining practical for local operations.
• Define and maintain standards for switching, routing, and wireless solutions across a mixed Cisco and Meraki environment.
• Design resilient branch connectivity using optimal combinations of DIA, broadband, private connectivity, cellular/5G, and satellite services based on site criticality and regional availability.
• Guide wireless architecture and optimization, including RF design fundamentals, capacity, coverage, client steering, authentication, and troubleshooting complex user experience issues.
• Create repeatable deployment patterns for new sites, acquisitions, site expansions, technology refreshes, and data center exit activities.
• Establish architecture requirements for availability, failover, monitoring, capacity, and performance; verify that implemented solutions align with the intended design.
• Enhance observability using platforms such as SolarWinds, cloud-native telemetry, vendor portals, logs, flow data, and APIs.
• Lead technical root cause analysis for major or recurring incidents and transform findings into lasting architecture, configuration, and process improvements.
• Optimize application experience for collaboration, voice, video, and other business-critical traffic through effective routing, QoS, path selection, and security-service design.
• Provide senior technical escalation support during high-impact incidents and planned migrations when architecture-level decisions are necessary.
• Produce clear high-level designs, low-level designs, diagrams, bills of material, decision records, standards, migration strategies, test plans, and operational handover documentation.
• Conduct architecture reviews, technical workshops, proofs of concept, and vendor evaluations; present recommendations, trade-offs, risks, and investment requirements to technical and business stakeholders.
• Collaborate with Network Engineering, Cybersecurity, Cloud, Infrastructure, Enterprise Architecture, local IT, and external service providers throughout the solution lifecycle.
• Mentor engineers, enhance troubleshooting discipline, and improve the quality and consistency of network design and documentation within the team.
• Support commercial and lifecycle decisions through technical due diligence, total-cost evaluations, licensing analysis, and vendor performance assessment.
• Remain actively involved to review configurations, validate routing and security behavior, test failover, and assist with challenging implementation issues.
• Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field, or equivalent relevant experience.
• Typically 8+ years of progressive enterprise network engineering experience, including at least 3 years in architecture, lead design, or principal-level responsibilities.
• Proven experience in designing networks for a global, multi-site enterprise; experience in manufacturing or other business-critical operational environments is highly valued.
• Expert-level understanding of TCP/IP, IPv4/IPv6, BGP, OSPF, route redistribution and policy, QoS, NAT, VPN technologies, high availability, failure domains, and asymmetric routing.
• Strong hands-on experience with enterprise firewalls and secure remote access, preferably with Palo Alto Networks and Prisma Access technologies.
• Extensive cloud networking experience in Microsoft Azure, including hybrid connectivity, routing, security controls, load-balancing dependencies, and multi-region resiliency.
• Solid experience with enterprise routing, switching, and wireless technologies; familiarity with Cisco and/or Meraki is preferred.
• Practical knowledge of SASE, SD-WAN, Zero Trust, network segmentation, NAC, and identity-aware access.
• Ability to produce high-quality architecture documentation and convey complex technical decisions clearly to engineers, leaders, and non-technical stakeholders.
• Professional proficiency in English and Spanish, both written and spoken, to facilitate global collaboration and effective partnership with the Matamoros site.
• Willingness to participate in planned off-hours changes or critical incident support as business needs dictate.
• Competitive compensation and benefits.
• Performance-based incentives.
• Flexible work arrangements.
• Development opportunities.
TensorWave
fal
CrowdStrike
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.