The role acts as the architecture authority for network security, identity-based access, micro-segmentation, secure remote access, and connectivity services. Working closely with Security, Infrastructure, Operations, Service Owners, Product Teams, and Managed Service Providers, the architect develops target-state architectures, drives transformation initiatives, and ensures enterprise network services are secure, scalable, resilient, and aligned with business requirements.
A key responsibility is to design and implement Zero Trust network architectures that eliminate implicit trust through identity-aware access controls, continuous verification, policy-based segmentation, and integrated security controls.
Enterprise Network & Security Architecture
- Define and maintain enterprise network and security architecture standards, blueprints, and reference designs.
- Design secure architectures for campus, WAN, cloud, remote access, and enterprise connectivity services.
- Ensure network solutions align with enterprise security standards, regulatory requirements, and technology roadmaps.
- Develop scalable and reusable architecture patterns supporting global business operations.
Zero Trust Architecture & Security Transformation
- Lead the design and implementation of enterprise Zero Trust architecture strategies.
- Develop identity-based access models that continuously validate users, devices, applications, and network connections.
- Define security architectures that remove implicit trust and enforce least-privilege access principles.
- Establish architecture standards for:
- Zero Trust Network Access (ZTNA)
- Policy-Based Access Controls
- Identity-Aware Networking
- Continuous Verification Models
- Secure Remote Access
- Partner with Security, IAM, and Infrastructure teams to drive enterprise-wide Zero Trust adoption.
Network Segmentation & Micro-Segmentation
- Define enterprise segmentation and micro-segmentation architecture frameworks.
- Design security zones, trust boundaries, and east-west traffic protection models.
- Lead Zero Trust enforcement initiatives across campus, data center, cloud, and remote access environments.
- Act as architecture owner for common firewall ruleset governance and policy standardization.
- Establish reusable segmentation patterns supporting workload isolation and risk reduction.
- Ensure alignment between segmentation strategies and business security requirements.
Network Security & Secure Connectivity Services
- Define architecture standards for:
- Firewall Services
- Secure Routing
- Remote Access
- VPN Technologies
- Proxy Services
- Secure Internet Access
- Ensure consistent implementation of security controls across enterprise connectivity services.
- Drive modernization of secure access and connectivity solutions.
Product & Technology Ownership
Act as Product or Technology Owner for:
- Third-Party Access VPN (3PA)
- Secure Employee Access VPN (SEA-VPN)
- Proxy Services
- Additional enterprise connectivity services as assigned
Responsibilities include:
- Technology roadmap development
- Service lifecycle management
- Continuous improvement planning
- Service modernization initiatives
- Technology standardization
Service Delivery Governance
- Provide architectural oversight for delivery and operation of enterprise connectivity services.
- Partner with service owners and managed service providers to ensure service quality and compliance.
- Support service lifecycle activities including design, transition, operation, and optimization.
- Drive service performance improvements and operational maturity initiatives.
Network Transformation & Migration Design
- Define target-state architectures supporting network and security modernization programs.
- Develop migration strategies from legacy (brownfield) environments to future-state architectures.
- Design phased rollout plans, transition frameworks, and risk mitigation approaches.
- Support transformation programs involving segmentation, connectivity modernization, and Zero Trust implementation.
- Provide architecture leadership during deployment and operational transition activities.
Monitoring, Observability & Operational Intelligence
- Ensure observability requirements are incorporated into architecture designs.
- Utilize telemetry, traffic-flow analytics, performance metrics, and operational insights to support architecture decisions.
- Define architecture requirements for monitoring, visibility, and service assurance capabilities.
- Collaborate with operations teams to improve proactive detection, troubleshooting, and performance management.
Transformation & Rollout Steering
- Participate in transformation governance and rollout steering activities.
- Provide architecture leadership for global deployment initiatives.
- Ensure adherence to architecture standards during implementation.
- Support readiness assessments, implementation reviews, and deployment validation activities.
- Drive alignment between architecture, operations, security, and business stakeholders.
Provider & Regional Collaboration
- Collaborate with Managed Service Providers, security vendors, and regional IT teams.
- Support global rollout activities across APAC, EMEA, North America, and LATAM.
- Ensure consistent implementation of architecture standards and security controls globally.
- Provide technical leadership and architecture guidance throughout project lifecycles.
Documentation Governance & Knowledge Management
- Develop and maintain:
- High-Level Designs (HLD) & Low-Level Designs (LLD)
- Architecture Standards & Security Design Guidelines
- Reference Architectures & Best Practice Documentation
Govern architecture repositories and documentation standards.
- Bachelor's Degree in Computer Science, Information Technology, Telecommunications, Engineering, or related discipline.

