Current Job Openings

Network Security Architect

Apply Now Back to Search Results

JOB SUMMARY

The Network Security Architect is responsible for defining, designing, and governing the enterprise network security architecture that protects Delek US's corporate, refinery, pipeline, terminal, retail, and cloud environments. This role establishes strategic network security direction, develops enterprise security standards, and ensures security architectures support business objectives while reducing cyber risk across Information Technology (IT), Operational Technology (OT), and cloud environments.

The Network Security Architect partners closely with Infrastructure, Network Engineering, Cloud Engineering, Security Operations, Enterprise Architecture, Operations Technology (OT), Engineering, and business stakeholders to develop secure, scalable, and resilient network architectures aligned with Zero Trust principles, regulatory requirements, and industry best practices.

The successful candidate will possess deep expertise in enterprise network security architecture, industrial control system (ICS) security, cloud networking, and security strategy, with the ability to translate business requirements into secure architectural solutions.

EDUCATION AND EXPERIENCE

· Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related field; or equivalent combination of education and experience.

· 8+ years of progressive experience in network security, cybersecurity architecture, or enterprise infrastructure.

· 3+ years designing enterprise network security architectures.

· Experience designing and governing enterprise firewall architectures (Palo Alto, Fortinet, Cisco, etc.).

· Experience designing secure cloud networking architectures (Microsoft Azure preferred).

· Experience with enterprise routing, switching, and SD-WAN architectures.

· Experience securing large multi-site enterprise environments.

· Experience with industrial control systems (ICS) and Operational Technology (OT) security is strongly preferred.

· Experience leading cross-functional technology initiatives and influencing technical direction across multiple teams.

PREFERRED CERTIFICATIONS

· Palo Alto Networks Certified Network Security Engineer (PCNSE)

· Cisco Certified Network Professional (CCNP) Security

· Cisco Certified CyberOps Professional

· Fortinet NSE Certification

· CISSP

· Microsoft Certified: Azure Security Engineer Associate (AZ-500)

JOB REQUIREMENTS

· Define and maintain the enterprise network security architecture and technology roadmap.

· Develop reference architectures, security standards, and design patterns for enterprise networking.

· Ensure network security architectures align with enterprise architecture principles.

· Support security architecture reviews for infrastructure, cloud, and operational technology initiatives.

· Develop long-term strategies for secure network modernization.

· Champion Zero Trust architecture across enterprise environments.

· Define enterprise firewall architecture and segmentation strategy.

· Establish secure connectivity standards for corporate, cloud, retail, refinery, pipeline, and terminal environments.

· Define enterprise network segmentation strategies for IT and Operational Technology (OT).

· Establish standards for VPN, remote access, third-party connectivity, and secure vendor access.

· Define architecture standards for SD-WAN and hybrid cloud connectivity.

· Evaluate and recommend emerging network security technologies.

· Provide architectural guidance for:

o Next-Generation Firewalls (NGFW)

o Intrusion Detection Systems (IDS)

o Intrusion Prevention Systems (IPS)

o Network Access Control (NAC)

o Secure Web Gateways

o DNS Security

o Web Application Firewalls (WAF)

o DDoS Protection

o Secure Remote Access

o Network Detection and Response (NDR)

o Network Microsegmentation

· Provide governance and technical oversight for implementation teams responsible for deployment and administration.

· Develop security architecture for refinery, pipeline, terminal, and industrial control system environments.

· Define secure architectures for IT/OT convergence.

· Establish segmentation strategies between enterprise and industrial environments.

· Develop secure remote access architectures for vendors and contractors.

· Ensure OT security architectures align with ISA/IEC 62443 and NIST guidance.

· Partner with Engineering and Operations teams to secure industrial environments while maintaining operational reliability.

· Develop architecture standards for Azure networking including:

o Azure Firewall

o Network Security Groups (NSGs)

o Application Gateway

o Private Endpoints

o Azure Virtual WAN

o ExpressRoute

o Azure DDoS Protection

o Secure Hybrid Networking

· Develop secure connectivity strategies between cloud and on-premises environments.

· Provide architectural oversight for network security implementations.

· Review proposed firewall policies and segmentation designs.

· Participate in infrastructure and application design reviews.

· Ensure implementations conform to enterprise architecture standards.

· Guide engineering teams on secure network design and implementation.

· Review technology exceptions and recommend risk-based solutions.

· Define architectural requirements for network visibility and monitoring.

· Collaborate with Security Operations to improve network detection capabilities.

· Guide development of SIEM detection use cases.

· Recommend improvements to logging, telemetry, and network analytics.

· Support major incident investigations as a network security subject matter expert.

· Develop network security standards and security baselines.

· Ensure architectural alignment with:

o NIST Cybersecurity Framework (CSF)

o ISA/IEC 62443

o SOX

o CIS Critical Security Controls

· Participate in enterprise risk assessments.

· Support internal and external audits.

· Conduct architecture risk assessments for new technologies.

· Serve as the enterprise subject matter expert for network security architecture.

· Mentor security engineers and network engineers.

· Lead technology evaluations and proof-of-concepts.

· Develop multi-year network security roadmaps.

· Present architectural recommendations to technical leadership.

· Drive continuous improvement of enterprise security capabilities.

· Provide technical leadership and architectural guidance across the organization.

· Partner closely with Enterprise Architecture, Infrastructure Services, Network Engineering, Cloud Engineering, Security Operations, Identity & Access Management, Operations Technology (OT), Refinery Engineering, Third- party vendors and Application Development.

SUCCESS MEASURES

· Enterprise network security architecture supports business growth and digital transformation.

· Security architectures are consistently adopted across enterprise initiatives.

· Reduced enterprise cyber risk through effective network security design.

· Successful implementation of Zero Trust architecture principles.

· Secure and resilient connectivity across enterprise, cloud, and OT environments.

· Successful completion of audits with minimal findings.

· Improved network visibility and threat detection capabilities.

· Reduction in architectural exceptions and technical debt.

· Increased standardization of network security technologies.

· High stakeholder satisfaction with architectural guidance and strategic direction.

· Delivery of network security roadmaps aligned with business and cybersecurity objectives.


#INDG