Lead Network & Security Architect
Celestica International LP
Req ID: 137432
Region: Americas
Country: USA
State/Province: Texas
City: Richardson
Summary
We are seeking a highly experienced and meticulous Lead Network & Security Architect to join the IT Support team for the Hardware Platform Solutions (HPS) group. In this role, you will take ownership of our global Research and Development Lab (RDL) reference architecture and drive its deployment, management, and scaling across all current and future HPS Design Centers (including Silicon Valley, Richardson, Thailand, and other global hubs).
The successful candidate will be responsible for implementing and maintaining a completely isolated, air-gapped network environment that operates independently of standard corporate IT networks. You will manage complex secure access paths, isolated VLAN provisioning, private full-mesh SD-WAN overlays, and a multi-tiered global data package replication and distribution system. You will also serve as the key enablement architect, helping project teams quickly spin up new project-specific instantiations of the RDL network model while adhering to strict security constraints.
Core Responsibilities
1. Architectural Implementation & Governance
- Deploy Reference Architecture: Standardize and implement the RDL reference design across all global HPS design locations (San Jose, Richardson, Thailand, Shanghai, SongShan Lake, Penang, Chennai and future locations).
- Support New Instantiations: Act as the primary technical design authority to spin up new RDL network instances (allocating subnets, configuring dedicated VLANs, establishing local jump hosts, and defining user authentication parameters) for upcoming HPS design projects.
- Strict Constraint Enforcement: Maintain absolute isolation of the RDL environments. Ensure zero direct or indirect public internet connectivity and guarantee that out-of-scope systems or agents (e.g., CrowdStrike, Threat Locker, Big Fix, ServiceNow Agents, ClearPass NAC, and Windows Domain joins) are strictly excluded from the lab network.
2. Network Infrastructure & Security
- SD-WAN & Routing: Design, configure, and maintain the private, full-mesh SD-WAN overlay connecting global RDL sites.
- Secure Firewalling: Configure and administer enterprise-grade firewalls (Checkpoint 3980) protecting the perimeter of each localized lab, defining strict ingress/egress filtering rules.
- Switching & Segmentation: Manage core and access layer switches (Cisco Catalyst 9400/9200 series, Celestica DS2000, ES1500 switches) to segment the RDL into logical, multi-tenant VLAN environments—specifically separating Export Controlled and Non-Export Controlled network zones.
3. Identity and Remote Access Management
- Remote Customer Access: Oversee the implementation and administration of CyberArk vPAM (Virtual Privileged Access Management) for remote customer connections.
- Corporate Remote Access: Configure and maintain Zscaler ZTNA (Zero Trust Network Access) and App Connectors to terminate connections securely on Linux-based local jump hosts.
- Decentralized Authentication: Design and maintain a secure user management protocol on jump hosts and local RDL nodes. As the RDL operates without Windows Active Directory, you will define standard operating procedures for the manual/programmatic creation of local system accounts and localized role-based access control (RBAC).
4. Secure Data Package Management & DevOps Repo Architecture
- Repository Architecture: Maintain the multi-tier secure data distribution system:
- IT Repository Server: Internet-facing ingestion nodes (running on Hyper-V/Dell PowerEdge) to securely pull packages, drivers, and applications.
- Global Repository Server: The middle-layer relay that acts as a secure, scanned transit point between the corporate IT network and the isolated RDL network.
- RDL Local Repository Server: Localized instances inside the labs that pull from the Global Repo and host files locally over at /var/
- Workflow Automation: Ensure seamless, secure, programmatically validated transfer of "transfer bundles" containing operating system packages (Rocky, Ubuntu, CentOS, etc.) across the air gap.
- Security Scans & Compliance: Coordinate with corporate IT and security teams to execute periodic vulnerability scanning and patching of repository servers, ensuring all packages undergo integrity checks before reaching the inner RDL networks.
Knowledge/Skills/Competencies
Required Technical Skills
- Hardware & OS Competencies: Hands-on experience with Checkpoint Firewalls (Checkpoint 3980 preferred), Cisco Catalyst 9400/9200 switches, and SilverPeak SD-WAN solutions.
- Security & Identity Tools: Expert-level understanding of CyberArk (PVWM/vPAM) and Zscaler ZTNA/Zscaler App Connectors.
- Virtualization & Systems: Solid administration experience in VMware vSphere Enterprise and/or Microsoft Hyper-V running on bare-metal systems (e.g., Dell PowerEdge R670).
- Linux Administration: Strong proficiency with Linux environments (Rocky Linux, Ubuntu, CentOS) for jump host configuration and secure local web repository servers (Nginx/Apache).
- Network Segmentation & Protocols: Expert in VLAN tagging, inter-VLAN routing, subnetting, IP address management (IPAM), and secure file transfer protocols.
- Automated Data Pipelines: Familiarity with script-based file synchronization and automated extraction/integrity validation mechanisms (e.g., hashing, checksums) for software deployment across isolated boundaries.
Strongly Preferred Certifications
- Checkpoint Certified Security Expert (CCSE) or Master (CCSM)
- Cisco Certified Network Professional (CCNP) - Enterprise or Security
- CyberArk Certified Defender or Sentry
- Certified Information Systems Security Professional (CISSP)
Soft Skills & Working Style
- Detailed Documentation: Proven track record of generating flawless High-Level Designs (HLD) and Low-Level Designs (LLD), block diagrams, and standard operating procedures (SOPs).
- Strategic Problem Solver: Comfortable working around strict operational boundaries where typical modern agents and automated tools are banned for security compliance.
- Cross-functional Partner: Ability to collaborate closely with HPS Design Engineers, Project Managers, Corporate IT Security, and external Customers.
- Financial Stewardship: Ability to work closely with procurement to specify, justify, and size bill of materials (BOM) for both upgrading existing sites and provisioning new infrastructure.
Physical Demands
- Duties of this position are performed in a normal office environment.
- Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.
Typical Education and Experience
Bachelor’s degree in Network Engineering, Computer Science, Cybersecurity, or a related technical field.
Minimum of 8+ years of experience in network architecture, with a heavy emphasis on securing air-gapped or highly isolated enterprise environments.
Notes
This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.
Celestica is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.
This policy applies to hiring, promotion, discharge, pay, fringe benefits, job training, classification, referral and other aspects of employment and also states that retaliation against a person who files a charge of discrimination, participates in a discrimination proceeding, or otherwise opposes an unlawful employment practice will not be tolerated. All information will be kept confidential according to EEO guidelines.
Celestica is an E-Verify employer.
COMPANY OVERVIEW:
Celestica, Inc. (NYSE: CLS; TSX: CLS) is a technology leader dedicated to driving customer success and market advancements. With deep expertise in design, engineering, manufacturing, supply chain, and platform solutions, Celestica enables critical data center infrastructure for AI, cloud, and hybrid cloud and advances technologies in high-growth markets. With a talented team and a strategic global network, Celestica helps its customers achieve competitive advantages.
Today, Celestica delivers innovative supply chain solutions globally to customers in strategic two operating and reporting segments: Advanced Technology Solutions (ATS) and Connectivity and Cloud Solutions (CC):
ATS: This segment serves customers in complex, regulated and high-reliability markets such as Industrial & Smart Energy, Aerospace & Defense, Semiconductor Capital Equipment, and HealthTech. It is engineering led, with deep expertise in design, manufacturing and lifecycle solutions.
CCS: This segment focuses on high-performance technology solutions and services for the data center, serving hyperscalers, digital native customers and enterprises. Celestica's Platform Solutions offering provides innovative and customizable computing, storage and networking solutions enabling AI-driven growth.
Built on a legacy of trust and performance, Celestica has earned its reputation by delivering results in complex and fast-changing markets. Celestica exceeds customer expectations by identifying trends and staying ahead of the curve. Backed by comprehensive capabilities and a global network across North America, Europe and Asia, Celestica helps customers gain competitive advantage with the quality, flexibility and resiliency they need to respond quickly to shifts in demand. Guided by a bold vision to accelerate market advancements, Celestica delivers innovative solutions and technologies that turn complexity into opportunity. Anchored in teamwork and commitment, Celestica strives to be the most trusted partner to its customers and colleagues worldwide.
Celestica would like to thank all applicants, however, only qualified applicants will be contacted.
Celestica does not accept unsolicited resumes from recruitment agencies or fee based recruitment services.
- ...environment designed for top achievers. As a Senior Lead Cybersecurity Architect at JPMorgan Chase within the Corporate... ...and skills Formal training or certification on security architecture practices in the network domain concepts and 5+ years applied experience....SuggestedFor contractors
- ...Senior Network Security Architect Date: General Overview Functional Area: Information Technology (ITM) Career Stream: IT Risk & Compliance (RAC) Role: Senior Technical Lead (SRT) Job Title: Senior Technical Lead, Information Security Job Code: SRT-ITM-SECR Job Level: Level...SuggestedWork at officeNight shift
- ..., design, and implementation of global network security solutions. This role reports into the Corporate... ...but not limited to, the following: Architects, designs, and oversees the deployment... ...Zscaler Zero Trust implementations. Leads the product selection process for new...SuggestedWork at officeNight shift
- ...A leading technology solutions provider is seeking a Senior Network Security Architect to design and oversee enterprise security solutions. This role requires extensive experience in architecting and implementing Checkpoint firewalls and Zscaler Zero Trust solutions....Suggested
- A leading financial services company seeks a Senior Lead Cybersecurity Architect to develop high-quality cybersecurity solutions for software applications. The ideal... ...experience in cybersecurity architecture and network security. Responsibilities include guiding...Suggested
$155.51k - $222.16k
...Optimum is seeking a Senior Enterprise Security Architect to provide subject matter expertise in security direction across enterprise platforms. This role involves technical leadership, collaborating with architects and engineers to ensure secure, scalable solutions....- Associate Enterprise Security Architect Who We Are At Upbound Group, we are committed to elevating... ...operating units include industry-leading brands such as Rent‑ACenter, Acima and... ...reference architectures and designs (identity, network segmentation, endpoint, cloud,...Work at officeLocal areaRemote workWork visaMonday to Friday
$155.51k - $222.16k
...Optimum is for you! Job Summary The Senior Enterprise Security Architect is responsible for providing subject matter expertise in... ...collaborate with other security architects, security engineers, network engineers, and application architects to ensure deployment...Local area- ...a cybersecurity specialist in Plano, Texas. The role involves leading the design and implementation of advanced cybersecurity solutions... ...systems. Candidates will need extensive experience in security practices and must be able to provide technical leadership and...
- A leading financial institution is seeking a Senior Lead Security Engineer to enhance their mobile security posture. This role focuses on collaborating with in-house mobile development teams, ensuring secure coding practices, and managing mobile security tools. The ideal...
- ...financial industry. As a Cybersecurity Architect at JPMorgan Chase within the Cybersecurity... ...application and architecture domains to lead complex projects and initiatives, understand... ...: Conduct technology and cyber security evaluations for potential target acquisitions...
$124k - $208k
...GlobalFoundries: GlobalFoundries is a leading full-service semiconductor foundry... ...deployment, and operation of large-scale Network Attached Storage (NAS) and high-... ...workloads. This role is responsible for architecting resilient, secure, and high-performing storage platforms...Local area- A financial services provider in Richardson, TX is looking for a highly experienced Master Network Engineer. This role involves designing, implementing, and supporting enterprise networking infrastructures across on-premise and cloud platforms. Candidates should have expertise...Full timeContract work
- ...PlacingIT is seeking a Principal Infrastructure Architect Lead (Linux) in Richardson, TX. This role demands extensive experience in enterprise... ...should have significant experience and a passion for delivering scalable, secure infrastructure solutions. #J-18808-Ljbffr...
- A leading financial institution is seeking a Lead Cybersecurity Architect - AWS Cloud to enhance their cybersecurity solutions. The role involves engaging with various... ...knowledge of automation tools and cloud security practices, and familiarity with the financial services...
- ...Texas Capital Bank in Richardson, TX, is looking for a Director of Cyber Security responsible for the enterprise cybersecurity architecture and leading a team of security architects. This role includes managing integrations of security technologies into the existing infrastructure...
- ...Upbound Group Inc. seeks a Principal Network Engineer in Plano, Texas. This role involves leading the design and management of networking solutions, requiring deep... ...automation, and a strong understanding of network security and performance tuning. Attractive benefits...
- ...Summit Tech Partners is looking for an experienced Senior Network Engineer to lead the design and improvement of our enterprise network. The ideal... ...engineers and developing resilient network solutions while maintaining security and performance standards. #J-18808-Ljbffr...
- ...ARKRAY AMERICA, INC is seeking a Security Officer responsible for overseeing measures to protect the company's physical and digital security... ...field, along with 10+ years of experience in systems and network security. A master’s degree is preferred. ARKRAY offers a comprehensive...
- ...partners maximize our products' potential. Work closely with our Product and Engineering teams to develop, integrate, and implement network security and endpoint solutions. Serve as a customer advocate, driving product adoption by influencing the product roadmap, leveraging...3 days per week
- ...A leading technology partner seeks a Chief Enterprise Architect specializing in security to drive business outcomes through expert architecture solutions. This pivotal role combines technical leadership with business acumen in a dynamic environment. Candidates should...
- ...Upbound Group Inc. is hiring an Associate Enterprise Security Architect in Plano, Texas. This role focuses on developing and maintaining enterprise security architecture standards while collaborating closely with various IT and security teams. The ideal candidate should...
- ...DATA in Plano, Texas is seeking a Disaster Recovery Manager to lead the IT resilience program ensuring business continuity during... ...disaster recovery and risk management, with strong knowledge in network security and systems administration. Join us in maintaining...
- ...Principal Software Security Architect Homecare Homebase is seeking a hands-on, engineering-first... ...using both traditional techniques and leading-edge AI technology. Security... ...image standards, runtime protections, network segmentation, and least-privileged service...Full timePart timeWork at office
- ...Be Doing Design and implement cloud data lake architecture for security telemetry ingestion and retention. Build and manage container orchestration... ...strategies, scaling policies. Handle secrets management, network architecture, and security controls for the platform itself....
- ...A leading technology partner is seeking a Chief Architect in Plano, Texas. The ideal candidate will be a Cisco Network expert with over 5 years of presales experience. Responsible for driving the Go to Market strategy and providing technical solutions, this role requires...
$160k - $200k
A leading independent technology partner is seeking a Security Chief Enterprise Architect in Plano, Texas. The ideal candidate will drive security solutions, design and propose architectures for enterprise networks, and support business goals through effective communication...- ...Enterprise Architect Role Summary The Enterprise Architect shapes and... ...integration, technology, and security , establishes standards and... ...architecture model : cloud, network, security, commerce, mobile,... ...leadership (matrix influence) Lead enterprise architecture outcomes...Work visa
$180.2k - $270.4k
...software development engineering, technical security and QA design and certification. Work on... ...organizations, and vendors focusing on network security hardening and implementation of... ...and utilizing Azure, AWS and Google. Our Lead Member of Technical Staff earn between $1...Temporary workLocal area- Upbound Group in Plano, Texas is looking for an Associate Enterprise Security Architect to contribute to the security architecture across the organization. This role involves working with various teams to define security standards and ensure security compliance. Candidates...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Network & Security Architect. Be the first to apply!
- network architect Richardson, TX
- infrastructure architect Richardson, TX
- rn network Richardson, TX
- network cabling Richardson, TX
- IT network Richardson, TX
- network operations center manager Richardson, TX
- senior cloud network engineer Richardson, TX
- network operations center technician Richardson, TX
- staffing network Richardson, TX
- network operations center Richardson, TX

