Principal Network Automation Architect

Flexential Corp.
$200,000 - $230,000Remote

About The Position

The Principal Network Automation Architect is a hands-on technical leadership role accountable for the architecture, engineering, and operation of the API-driven network automation platform beneath Flexential’s customer self-service portal. This platform enables customers to order and provision network services on demand. It exposes service catalog, feasibility, ordering, provisioning, and lifecycle APIs for L3VPN, Data Center Interconnect (DCI), IP Transit, Layer 2 transport, and cloud on-ramp connectivity, and executes those orders across Flexential’s nationwide multi-service backbone. This is a senior individual contributor role reporting to the Vice President, Network Services. The Principal Architect owns the technical vision, architectural standards, and multi-year roadmap for a custom, Python-based network-as-code platform. This platform is original software developed in-house, rather than a packaged or open-source product that is deployed and configured. The role holds design authority across the network automation function, is positioned to assume formal team leadership as the function scales and remains directly accountable for building and operating the platform. This is a high-visibility, high-impact role. The platform is the control plane behind an on-demand network services product, and its behavior is customer-visible: order-to-activation interval, provisioning success rate, and platform availability are experienced by customers through the portal. The Principal Architect is accountable for platform reliability, security posture, change safety, and delivery timelines, and partners with IT Platform Engineering to extend enterprise observability and AIOps capabilities into the network domain.

Requirements

  • 10+ years of relevant technical experience, including 3+ years in a principal, staff, or lead architect role holding design authority across a technical function.
  • Platform / Software Engineering - 8+ years: end-to-end ownership of a production software platform; Python service development (Flask or equivalent), API contract design, data modeling, and release engineering.
  • Network and Security Domain Depth - 8+ years: working expertise in MPLS L3VPN, BGP (including MP-BGP/VPNv4), EVPN-VXLAN, OSPF/IS-IS, Data Center Interconnect, IP transit, and multi-vendor firewall policy, sufficient to model these services as code and validate automated change.
  • Network Automation and Orchestration - 6+ years: network-as-code, intent-driven provisioning, state reconciliation, and drift remediation across multi-vendor estates.
  • GitOps / CI/CD - 5+ years: pipeline authoring, automated validation and test gates, configuration-as-code delivery with tested rollback.
  • Network Security Engineering - 4+ years: firewall and policy automation, RBAC design, secrets management, change authorization, and audit evidence.
  • Technical Leadership - 4+ years: setting architectural standards, governing design review, and mentoring senior engineers across a technical function.
  • Data Engineering - 3+ years: document, graph, and timeseries data models for network state, source of truth, and automation metadata.
  • Systems Engineering and NMS - 3+ years: Linux systems administration, network management systems, and operational tooling integration.
  • Frontend Development - 2+ years: JavaScript with Angular or React and Bootstrap.
  • Other training and experience may be substituted for the job requirements at the discretion of the manager.

Nice To Haves

  • Experience integrating network automation platforms with ServiceNow (Change, CMDB, Service Catalog).
  • Experience operating automation at scale in service-provider, carrier, or multi-site enterprise environments.
  • Experience applying AI/ML to operations, anomaly detection, event correlation, alert noise reduction, or agentic workflows.
  • Experience with Open Telemetry, Prometheus, or Grafana-based observability integrated into automation workflows.
  • Experience with Kubernetes, Helm, and container-based deployment of platform services.
  • Experience mentoring or leading engineers in a hands-on technical role.

Responsibilities

  • Own the end-to-end architecture of the network automation platform, including application, orchestration, data, integration, and security layers, as a production software product with defined availability targets, release cadence, and support model.
  • Design, build, and maintain a Python-based network-as-code platform, with Ansible and Terraform used as supporting technologies where appropriate.
  • Build the platform as original software: the provisioning engine, service models, API layer, and data architecture are developed in-house, with open-source components consumed selectively as libraries rather than constituting the platform itself.
  • Develop backend services using Python (Flask) as the primary application framework and contribute to frontend development using JavaScript with Angular or React and Bootstrap.
  • Define and govern API-first architectures, including service contracts, versioning, authentication, and authorization for internal platform consumers.
  • Design and evolve platform data models across document, graph, and timeseries databases to represent network state, service intent, topology relationships, and source of truth.
  • Establish engineering standards through hands-on development, code review, automated testing, and technical design review.
  • Own the northbound API contract consumed by the customer self-service portal, service catalog, feasibility and validation, order submission, provisioning status, and lifecycle operations.
  • Design tenant isolation, authentication, authorization, and rate-limiting models appropriate to a control plane fulfilling customer-initiated orders submitted through the portal.
  • Define idempotency, retry, compensation, and reconciliation semantics, so customer-initiated orders remain safe and consistent under partial failure.
  • Partner with Product Management and portal engineering on service definitions, API contracts, and customer-visible status and error semantics.
  • Establish measurement of order-to-activation interval, provisioning success rate, and platform availability as service levels customers experience through the portal.
  • Own the automated service lifecycle for customer-facing network services, including L3VPN, Data Center Interconnect, IP Transit, and Layer 2 transport. This includes service modeling, intent capture, provisioning orchestration, pre- and post-change validation, and decommissioning.
  • Architect orchestration workflows spanning the multi-service backbone: MPLS L3VPN and EVPN service instantiation, BGP peering and routing policy automation, segment routing policy, and DCI provisioning.
  • Design service abstractions that allow the self-service portal, Service Delivery, and Network Operations to deliver customer services without device-level interaction.
  • Design and maintain a vendor-abstraction layer and device driver framework spanning Arista, Cisco, and Fortinet, with Arista CloudVision Portal integrated as one of several southbound controllers.
  • Implement state reconciliation, configuration drift detection, and automated remediation across the managed estate.
  • Extend the service catalog to cloud connectivity: dynamic provisioning of hosted connections to AWS Direct Connect, Microsoft Azure ExpressRoute, and Google Cloud Interconnect, including integration with cloud provider partner APIs and lifecycle management of customer cloud onramps.
  • Automate firewall policy provisioning, change, and validation across the security estate, including rule lifecycle management and compliance verification.
  • Ensure the platform supports the in-flight 400G backbone modernization, including automated turn-up, validation, and migration of customer services onto upgraded infrastructure.
  • Hold design authority for the network automation platform: set architectural standards, approve technical designs, and govern engineering practice across the network automation function.
  • Provide technical direction while remaining directly involved in delivery; serve as the escalation point for complex technical and architectural challenges.
  • Set and enforce expectations for code quality, reliability, security, testability, and operational readiness.
  • Mentor senior engineers and lead technical design review, growing the engineering capability of the function through direct contribution and coaching.
  • Define the platform support model and participate in on-call rotation and incident response for automation-driven change events.
  • Establish and enforce platform security posture: secrets management (CyberArk, Conjur, Vault, or equivalent), RBAC design, credential lifecycle, mTLS, and least-privilege access to production network infrastructure.
  • Design change authorization, blast-radius control, dry-run, and rollback mechanisms for automated changes to production customer-facing services.
  • Produce audit and compliance evidence for automated change in support of customer, regulatory, and internal control requirements.
  • Define and maintain the multi-year platform roadmap in alignment with Network Services, Service Delivery, and Product Management.
  • Drive integration with enterprise platforms, including ServiceNow for automated change records, CI enrichment, and CMDB correlation of network state.
  • Define extensibility patterns for AI-assisted network operations: intent translation, closed-loop remediation, anomaly-driven workflows, agentic workflows, and MCP-based tool integration.
  • Partner with IT Platform Engineering to extend the enterprise observability platform into the network domain, ensuring automation outcomes are measurable and operationally supportable.
  • Represent network automation in cross-functional architecture reviews and executive-level program updates.
  • Perform other management and technical duties as required for team and operational resilience.

Benefits

  • Medical, Telehealth, Dental and Vision
  • 401(k)
  • Health Savings Accounts (HSA) and Flexible Spending Accounts (FSA)
  • Life and AD&D
  • Short Term and Long-Term disability
  • Flex Paid Time Off (PTO)
  • Leave of Absence
  • Employee Assistance Program
  • Wellness Program
  • Rewards and Recognition Program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service