Workday, Inc.-posted about 1 month ago
Full-time • Principal
Hybrid • Pleasanton, CA
5,001-10,000 employees
Professional, Scientific, and Technical Services

We are seeking a highly experienced and visionary Principal Network Engineer & Architect to lead the strategic development, design, and hands-on implementation of our global network infrastructure. This role requires an individual who can operate at a senior architectural level, defining our network roadmap, while still possessing deep technical expertise and a strong desire to be hands-on.

  • Instrumental in evolving our Zero Trust architecture and pioneering advanced cloud networking solutions, leveraging state of the art solutions and extensive automation.
  • Guide and mentor our network engineering teams and be responsible for driving consensus and managing expectations across diverse business and technical stakeholders.
  • Own and define the long-term, multi-year network strategy and architecture, aligning it with executive business objectives, security mandates, and future technology trends.
  • Architectural owner for our Zero Trust security model. This includes integrating and maximizing the capabilities of Zscaler (ZIA/ZPA), Palo Alto Networks Firewalls (including GlobalProtect), AWS Network Firewall to create an impenetrable security posture.
  • Lead the design and integration of all major networking technologies across our enterprise, with a specific focus on complex, multi-region cloud environments utilizing AWS Cloud WAN, VPCs, SD-WAN.
  • Maintain deep technical currency by remaining highly hands-on-designing, prototyping, and deploying core architectural components and complex automation frameworks.
  • Mandate, develop, and govern the use of automation for network provisioning, security policy deployment, and operations driving a true Infrastructure as Code (IaC) model
  • Establish global network engineering standards, perform critical design reviews, and provide technical sign-off for all major network changes and projects.
  • Serve as the primary network domain expert in discussions with Executive Leadership, translating highly technical designs into clear business impact, risk, and financial justification.
  • Drive consensus and secure investment for architectural transformation across Security, Finance, Application Development, and Cloud Operations teams through compelling presentations and strong technical advocacy.
  • Function as a Principal Mentor for the entire Network Engineering and Architecture organization, elevating the team's technical capabilities, leading complex technical deep dives, and delegating execution while retaining strategic oversight.
  • 12+ years of progressive enterprise experience within network engineering.
  • 5+ years operating as a Principal Architect or equivalent role with global responsibility.
  • 12+ years pioneering experience designing and implementing large-scale Zero Trust architectures.
  • 12 + years of expertise with the following security components:
  • Zscaler (ZIA/ZPA): Architecting global ZTNA and Secure Web Gateway solutions.
  • Palo Alto Networks: Expert with Firewalls (physical/virtual), Panorama, SD-WAN and GlobalProtect.
  • AWS Security: Deep knowledge of AWS Network Firewall and other native services
  • Proven, large-scale design and implementation experience with AWS Cloud WAN and advanced AWS networking.
  • Expert-level knowledge of F5 Big-IP (LTM/GTM).
  • Extensive architecture and deployment experience with Aruba ClearPass for Network Access Control (NAC)
  • Significant experience with modern campus/wireless platforms, including Cisco and Juniper Mist.
  • Expert proficiency in Python for network programming, API interaction, and security orchestration, alongside extensive experience leading Ansible automation projects.
  • Exceptional ability to influence without direct authority, manage high-level stakeholder expectations.
  • Ability to simplify complex technical concepts for non-technical audiences.
  • Executive-level strategic thinking combined with an expert-level, hands-on technical background across multiple network domains.
  • Open to 50% flex-hybrid reporting to Pleasanton campus.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service