Principal Architect, Technology - Subscriber Edge

Ziply Fiber
$155,000 - $230,000Remote

About The Position

The Principal Architect for Subscriber Edge is Ziply Fiber's technical authority for how subscribers connect, authenticate, and experience the internet. This role owns the BNG architecture, cloud-hosted RADIUS platform, DHCP/DNS, CGNAT, IPv6, Speed Test infrastructure, and the subscriber policy systems — Walled Garden, DDoS mitigation, and business service IP management — that operate at the scale of over a million broadband subscribers across copper and fiber networks. This is a deeply hands-on senior independent contributor role with broad operational scope. Reporting to the VP, Network Architecture & Engineering, this role serves as the senior Subscriber Edge architecture authority responsible for setting standards, influencing technical direction, and guiding engineering teams through complex design, migration, and production-readiness decisions without direct people-management responsibility. This role is expected to lead through technical influence by creating repeatable architecture patterns, decision records, reference designs, governance models, and operational readiness expectations that allow subscriber-edge platforms to scale consistently across existing and future markets.

Requirements

  • High school diploma or GED.
  • Bachelor’s degree in Engineering, Computer Science, Information Technology, Telecommunications, or a related field, or equivalent combination of education and directly relevant subscriber-edge architecture experience.
  • 10+ years of broadband, ISP, service provider, or telecommunications network architecture experience with deep expertise in subscriber-edge platforms, BNG, RADIUS, DHCP/DNS, CGNAT, IPv6, subscriber policy, DDoS mitigation, and large-scale migration or modernization programs.
  • Demonstrated senior independent contributor experience setting Subscriber Edge architecture standards, influencing technical direction, mentoring engineers, and driving cross-functional architecture decisions without direct people-management responsibility.
  • Proven experience designing, modernizing, or migrating large-scale RADIUS or subscriber authentication platforms, including cloud-hosted or highly available deployments, for broadband environments spanning fiber, copper, or related subscriber access networks.
  • Strong BNG expertise: PPPoE/IPoE session management, subscriber authentication, RADIUS integration, and large-scale aggregation routing design.
  • Hands-on IPv6 experience: dual-stack architecture, DHCPv6-PD, SLAAC, and lab-to-production validation workflows.
  • Experience designing and operating subscriber policy systems: Walled Garden, CGNAT, DHCP/DNS, and business service IP management.
  • Track record running vendor RFPs for network equipment: requirements definition, vendor evaluation, procurement coordination, and deployment documentation.
  • Experience with DDoS mitigation platforms (Arbor or equivalent): detection, scrubbing, and operational runbook development.
  • Strong technical documentation skills — able to produce deployment guides, architecture standards, and tooling requirements that engineering and planning teams can execute against.

Nice To Haves

  • Experience with anycast routing for distributed infrastructure (Speed Test, DNS, or CDN use cases).
  • Familiarity with Ookla Speedtest platform integration and 100G server network design.
  • Background in network automation for subscriber edge: NETCONF/YANG, gNMI, or Ansible-based configuration management for BNG and aggregation routers.
  • Experience with programmable or disaggregated BNG (vBNG) architectures.
  • JNCIE-SP, CCIE-SP, or equivalent certification.
  • Experience supporting subscriber environments at or near 1M+ broadband subscribers.
  • Experience presenting Subscriber Edge, RADIUS, BNG, IPv6, CGNAT, DDoS, or subscriber-experience architecture strategy to VP-level or executive audiences.
  • Experience with compliance-sensitive subscriber systems, including CGNAT logging, lawful request support processes, abuse-management workflows, or equivalent production controls.

Responsibilities

  • Design and own the BNG architecture supporting PPPoE and IPoE session models for residential and business subscribers across fiber and copper access networks.
  • Define aggregation routing architecture: lead vendor RFPs, evaluate equipment, coordinate with procurement, and produce installation and deployment documentation for engineering and planning teams.
  • Own IPv6 dual-stack and IPv6-only transition architecture: DHCPv6-PD, SLAAC, and lab validation prior to production rollout.
  • Design and maintain CGNAT architecture: NAT44, port-block allocation, logging compliance, and capacity planning.
  • Own the RADIUS platform architecture for subscriber authentication and management — including cloud-hosted deployments (Google Cloud or equivalent) at the scale of 1M+ broadband subscribers.
  • Lead large-scale RADIUS migrations: design, implementation, tooling requirements, and full cutover execution across both copper and fiber subscriber bases.
  • Design and implement Walled Garden solutions using RADIUS-based policy enforcement to block and redirect subscribers to self-service and billing portals.
  • Own DHCP and DNS infrastructure: high-availability topology, policy enforcement, lease management, and integration with provisioning and OSS/BSS systems.
  • Design and own static IP offerings for business services: IP address management (IPAM), allocation policy, provisioning workflows, and supporting tooling requirements.
  • Define subscriber IP edge design standards for business and enterprise services, including layer 2 and layer 3 handoff models and QoS policy frameworks.
  • Architect and own Ziply's Speed Test server network: 100 Gigabit distributed infrastructure with anycast routing, geographic placement across Internet drain locations, and Ookla platform integration.
  • Define Speed Test measurement methodology: test protocols, result accuracy standards, and capacity planning across a geographically diverse, highly available server footprint.
  • Ensure Speed Test infrastructure supports both subscriber self-service and network operations use cases, with integration into subscriber experience analytics and network performance platforms.
  • Own DDoS detection and mitigation architecture: Arbor (or equivalent) deployment, traffic monitoring, scrubbing center integration, and incident response playbooks.
  • Define subscriber edge security posture: traffic anomaly detection, abuse management, and coordination with the Security organization on edge-facing threats.
  • Performs other duties as required to support the business and evolving organization.

Benefits

  • Medical
  • dental
  • vision
  • 401k
  • flexible spending account
  • paid sick leave and paid time off
  • parental leave
  • quarterly performance bonus
  • training
  • career growth and education reimbursement programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service