{"id":1405469,"url":"https://alion.io/job/delan-associates-network-security-architect","title":"Network Security Architect","company":{"id":690244,"name":"Delan Associates","domain":"delanhq.com","url":"https://alion.io/company/delanhq","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"staffing","is_intermediary":false,"listed_via":null,"ats_vendor":"Breezy","truth_index":{"grade":"B","score":80,"open_postings":12,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":12,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"contractor","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["New York, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":139000,"max_usd":289000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":255},"experience_years_min":13,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agile","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"BGP","optional":false},{"name":"DLP","optional":false},{"name":"GCP","optional":false},{"name":"ITIL","optional":false},{"name":"MPLS","optional":false},{"name":"PKI","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"VPN","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-09-28T17:12:39Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-30T21:42:13Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"Position: Network Security Architect - Overall 10+yrs experience needed.\nLocation: NYC, NY (Hybrid- 3 days a week) - face to face is must. Look for candidate from drivable distance as f2f is must.\nDuration: 6 - 12 months\nIndustry- Banking & Financial client\nPhone Interview followed by an in-person round of interview.\nMust have 13+ years of experience and must attend F2F interview.\nSkills: IP routing, MPLS, BGP, SD-WAN, Wireless Network, Data Centre architecture, Palo Alto, Cisco NGFWs, SIEM, EDR, AWS, Azure, GCP, SABSA, TOGAF, COBIT, ITIL, DODAF, Automation\nIdeal Candidate:\nSenior Network Security Architect + strong enterprise networking/security architecture + hands-on PQC knowledge (FIPS 203/204/205) + experience assessing PQC readiness and its impact on Firewalls, WAF, NAC, Proxy, VPN/PKI and perimeter security. \nRole Overview\nWe are looking for a Senior Network Security Architect who can design and secure large enterprise network environments across on-prem, data center, and multi-cloud platforms.\nThe most important differentiator for this role is Post-Quantum Cryptography (PQC) expertise, specifically NIST FIPS 203, FIPS 204, and FIPS 205, and how PQC impacts network security technologies.\nA Network Security Architect is a senior-level IT professional responsible for planning, designing, testing, and overseeing the implementation of secure enterprise network configurations to protect an organization from cyber threats. Acting as the strategic blueprint designer, this role ensures that all local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and cloud integrations align with business objectives and stringent security standards.\nSubject Matter expert / domain specialist related to post-quantum cryptography (NIST FIPS 203, 204, 2052) will be required to cover Firewalls, Web Application Security, NAC, Proxy and Perimeter Mail areas within Network Security.\nStrong familiarity with NIST Post-Quantum Cryptography standards (FIPS 203, 204, 205) and their applicability to network security infrastructure\nUnderstanding of financial industry regulatory frameworks (e.g., FFIEC, DORA, SEC cybersecurity guidance) as they relate to cryptographic standards\nExperience supporting PQC readiness assessments in regulated industries\nAwareness of 'harvest now, decrypt later' threat vectors and their implications for financial data\nAbility to incorporate industry-standard compliance frameworks into the RFP deliverables and final recommendations\nThe Network Security Architect leads the creation of robust, layered defense infrastructures. They analyze existing security postures, identify structural vulnerabilities, perform gap analyses, and design end-to-end network security solutions. They collaborate closely with project managers, security engineers, and executive stakeholders to translate complex business demands into highly resilient, secure technical realities. \nCore Responsibilities\n1. Security Architecture & Strategy Design: Design and deliver comprehensive, secure network frameworks using trust domain segregation, Zero Trust Architecture (ZTA), and secure zoning principles. Develop technical solutions and integration strategies across LANs, WANs, SD-WAN, MPLS, data centers, and multi-cloud environments. Establish baseline configurations for network infrastructure, including Next-Generation Firewalls (NGFW), Intrusion Detection/Prevention Systems (IDS/IPS), and Network Access Control (NAC).\n2. Risk Assessment & Vulnerability Management: Conduct routine gap analyses and security risk assessments against recognized frameworks like NIST, SANS, and CIS. Evaluate proposed acquisitions and software interfaces to determine how they impact the organization's overarching network security posture. Plan and oversee regular vulnerability scanning, penetration testing, and ethical hacking exercises.\n3. Access Control & Data Protection: Define and implement secure identity federation, Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Public Key Infrastructure (PKI) systems. Enforce Role-Based Access Control (RBAC) to limit network access strictly by corporate necessity and specific employee roles. Architect data-in-transit encryption paths (IPsec/SSL VPNs) and Data Loss Prevention (DLP) parameters to mitigate data leakage.\n4. Incident Response & Business Continuity: Design disaster recovery plans, data backup strategies, and conduct routine breach-of-security simulation drills. Provide escalation support during critical network intrusions or unauthorized system access. Conduct comprehensive post-event analyses to determine exact root causes and update network models to mitigate future risks. \nRequired Technical Skills & Knowledge\nNetwork Technologies: Proficient in IP routing, MPLS, BGP, SD-WAN, Wireless networks, and advanced data center architectures.\nSecurity Hardware/Software: Extensive experience deploying Checkpoint, Palo Alto, or Cisco NGFWs, SIEM monitoring platforms, and Endpoint Detection and Response (EDR) solutions.\nCloud Architecture: Hands-on experience mapping secure network perimeters inside AWS, Azure, or Google Cloud Platform (GCP) environments.\nFrameworks & Methodologies: Deep familiarity with SABSA, TOGAF, COBIT, ITIL, and DoDAF architecture frameworks.\nAutomation & Scripting: Capability to write code in Python or PowerShell to automate network provisioning and logging configurations. \nExperience & Education Requirements\nEducation: Bachelor’s or Master's degree in Cybersecurity, Computer Science, Information Technology, or a closely related technical discipline.\nExperience: 8+ years of core IT networking experience alongside 3+ years specifically focused on advanced enterprise cybersecurity architecture.\nIT Infra\nMulti Cloud\nNetworking\nAutomation\nSecurity\nAgile\nComplex problem-solving skills\nCertifications (Highly Preferred):\nCertified Information Systems Security Professional (CISSP) or Information Systems Security Architecture Professional (CISSP-ISSAP).\nCisco Certified Internetwork Expert (CCIE) or Cisco Certified Design Professional (CCDP).\nCertified Information Security Manager (CISM) or SABSA Chartered Security Architect.","description_format":"text","description_chars":6200,"description_truncated":false,"requirements":{"experience_years_min":13,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Network Security","Stablecoins"],"lifecycle":[{"event":"open","at":"2026-09-28T17:29:51Z"}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":1,"expected_fill_days":12,"reasons":["conf:3","stale_co","velocity","win:early","comp:brand"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/delan-associates-network-security-architect","json_url":"https://alion.io/job/delan-associates-network-security-architect.json","meta":{"generated_at":"2026-10-01T03:58:40Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3293,"day_limit":5000,"remaining_today":1707,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}