Network Architect (Security)

American IT SystemsRichmond, VA
Onsite

About The Position

We are seeking a highly experienced Network Architect with a specialization in Security to lead the design and implementation of our enterprise and cloud networking infrastructures. This role involves architecting secure, scalable connectivity solutions, managing next-generation firewalls, and optimizing routing and SD-WAN deployments. The ideal candidate will have deep expertise in BGP routing, Palo Alto Networks firewalls, and Cisco SD-WAN, with a proven track record in cloud networking (Azure, AWS, GCP). This is a contract-to-hire position with a duration of 3-6 months, based onsite in Richmond, VA.

Requirements

  • Architect level 15+ years of experience in enterprise networking.
  • Deep expertise in BGP routing and network design.
  • Strong hands-on experience with Palo Alto Networks firewalls.
  • Strong hands-on experience with Cisco SD-WAN (Viptela).
  • Strong hands-on experience with Cisco Meraki full stack.
  • Proven experience designing and implementing cloud networking architectures.
  • Strong troubleshooting skills across routing, firewall, and connectivity domains.
  • Experience working directly with telecom carriers and ISPs.

Nice To Haves

  • Experience with multi-tenant or multi-environment network consolidation.
  • CCNP/CCIE certification.
  • PCNSE (Palo Alto) certification.
  • Azure Network Engineer Associate (AZ-700) certification.
  • AWS Advanced Networking Specialty certification.

Responsibilities

  • Lead design and implementation of enterprise and cloud networking architectures (Azure, AWS, hybrid).
  • Develop and execute network consolidation strategies across multiple environments and business units.
  • Architect secure, scalable connectivity patterns including site-to-site and client VPNs, SD-WAN deployments, and cloud transit hubs/hub-and-spoke models.
  • Define standards for routing, segmentation, and high availability.
  • Design and manage networking in Azure and demonstrate familiarity with AWS and GCP.
  • Implement and maintain virtual networks (VNets/VPCs), peering and private connectivity (ExpressRoute, Direct Connect), and network security controls (NSGs, firewalls, routing tables).
  • Integrate on-prem and cloud environments.
  • Design and troubleshoot complex routing environments using BGP, OSPF/EIGRP.
  • Optimize routing policies for performance, failover, and traffic engineering.
  • Lead troubleshooting of latency, packet loss, and asymmetric routing issues.
  • Manage next-generation firewall solutions, primarily Palo Alto Networks firewalls (PAN-OS, Panorama).
  • Define and enforce security policies, NAT, and segmentation strategies.
  • Partner with security teams on threat mitigation and compliance requirements.
  • Design and support SD-WAN solutions using Cisco Viptela / Cisco SD-WAN.
  • Manage and optimize branch networking using Cisco Meraki (full stack: MX, MS, MR).
  • Ensure consistent policy, performance, and visibility across all sites.
  • Act as primary technical liaison with telecom carriers and ISPs.
  • Lead troubleshooting of circuit issues (latency, outages, routing anomalies).
  • Validate and design circuit turn-ups (DIA, MPLS, broadband, LTE/5G).
  • Coordinate with vendors during deployments, escalations, and outages.
  • Serve as Tier 3 escalation point for network-related incidents.
  • Mentor junior engineers and provide technical guidance.
  • Develop and maintain documentation, standards, and runbooks.
  • Participate in on-call rotation as needed.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service