Senior Architect Perimeter & DMZ

Bank of AmericaChandler, AZ
Onsite

About The Position

This job is responsible for defining an architectural vision and solution that supports the strategic outcomes of the Business' Products and Services. Key responsibilities include defining the target operating environment, designing for client resiliency, assisting with solution design, and defining non-functional requirements. Job expectations include working with stakeholders and service providers aligned to the Business' strategic objectives, evaluating the impact of strategic design decisions, and contributing to the architecture roadmap. This role leads the network security architecture for perimeter services, external connectivity, and modern DMZ design. It ensures secure exposure of workloads and services across internet, partner, and third-party channels in line with the evolving access patterns and zero trust principles.

Requirements

  • 10+ years of progressive infrastructure / network / security engineering experience with 5+ years in architecture or senior technical leadership roles
  • Must have experience taking ownership of perimeter security and DMZ architectures for large-scale, high-availability enterprise environments
  • Proven delivery experience in regulated industries (financial services strongly preferred) with strong understanding of audit, risk, and control expectations
  • Strong experience leading cross-functional initiatives involving Network, Security, App teams, IAM, SRE/Operations, and Governance/Risk/Compliance (GRC)
  • Deep expertise designing and implementing segmented DMZ and perimeter architectures.
  • Experience embedding security measures.
  • Familiarity with threat modeling for internet-facing applications and partner connectivity
  • Demonstrated ability to create and enforce reference architectures, standards, patterns, and guardrails.

Nice To Haves

  • Hands-on experience with one or more of: Palo Alto, Fortinet, Check Point, Cisco, Juniper SRX F5, HAProxy, NGINX, cloud LBs, Akamai/Cloudflare (WAF/DDoS/CDN), Imperva, API gateways (Apigee, Kong, Mulesoft, AWS API Gateway / Azure APIM)
  • SIEM integrations (Splunk, Sentinel, QRadar)
  • Security/network certifications such as: CISSP / CCSP (security architecture), PCNSE/CCNP Security, GIAC (e.g., GSEC, GCIA), or equivalent

Responsibilities

  • Works across the business, operations and technology to create the solution intent and architectural vision for complex solutions and prioritize functional and non-functional requirements into a technology backlog to enable the technology roadmap and functionality to support evolving capabilities and services
  • Contributes to the creation of the architecture roadmap of defined domains (Business, Application, Data, and Technology) in support of the product roadmap and the development of best practices including standardized templates
  • Clarifies the architecture, assists with system design to support implementation, and provides solution options to resolve any architectural impediments
  • Facilitates solution driven discussions, leads the design of complex architectures, and finds creative solutions through knowledge of domain, practical experiments, and proof of concepts while ensuring architecture is flexible, modular, and adaptable
  • Educates team members on the technology practices, standardization strategies, and best practices to create innovative solutions
  • Supports the team as needed to select the technology stack required for solutions and helps select preferred technology products
  • Performs design and code reviews to ensure all non-functional requirements are sufficiently met (for example, security, performance, maintainability, scalability, usability, and reliability)
  • Defines scalable and secure designs for ingress/egress. Internet facing services, B2B integration, and third-party access. The role drives the modernization of perimeter controls including firewalls, proxies, segmentation, and decentralized internet breakout strategies.
  • Designs secure architecture for inbound and outbound services, including zero trust ingress.
  • Acts as a design authority across programs involving network segmentation, partner access, and external service hosting.
  • Develops reusable frameworks to standardize policy enforcement, inspection, and observability
  • Partners with security, infrastructure, and application teams to embed security into network and perimeter designs.
  • Provides thought leadership, influences product direction, and ensures adoption of approved patterns.
  • Acts as mentor to engineering and security teams, embedding “secure by design” principles across delivery

Benefits

  • affordable, competitive and flexible benefits
  • support for teammates’ physical, emotional, and financial wellness
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service