Back to job search
ET

Network Security Architect

• Analyze current DMZ architecture, firewall rules, and security controls. • Assist in planning and executing the migration of servers and applications into a new or redesigned DMZ. • Identify and mitigate risks associated with exposing services to external networks. • Validate secure configurations during migration (network segmentation, access control, routing). • Design and enforce network segmentation strategies between DMZ, internal, and external zones. • Review and implement firewall policies (e.g., Palo Alto, Versa Networks). • Configure and validate NAT, ACLs, VPNs, and load balancers…

  • On-site
  • ALBERTA
  • Posted Jul 23, 2026
  • Apply by Aug 22, 2026
  • 1 position

Job summary

• Analyze current DMZ architecture, firewall rules, and security controls. • Assist in planning and executing the migration of servers and applications into a new or redesigned DMZ. • Identify and mitigate risks associated with exposing services to external networks. • Validate secure configurations during migration (network segmentation, access control, routing). • Design and enforce network segmentation strategies between DMZ, internal, and external zones. • Review and implement firewall policies (e.g., Palo Alto, Versa Networks). • Configure and validate NAT, ACLs, VPNs, and load balancers. • Ensure secure communication between tiers (web, app, database). • Assess existing firewall rules and eliminate redundant or risky rules. • Create least-privilege access rules for new DMZ architecture. • Perform rule recertification and documentation. • Maintain detailed documentation of Network diagrams (current and future state), Firewall rule sets, Security controls implemented, Provide migration runbooks and rollback plans.

What you’ll do

The role involves designing and enforcing network segmentation strategies and managing firewall policies to secure DMZ, internal, and external zones. You will also be responsible for migrating servers to new architectures and maintaining detailed security documentation and runbooks.

Requirements

The candidate must be able to analyze and mitigate risks associated with external network exposure and validate secure configurations during migrations. Expertise in configuring network components like VPNs, NAT, and load balancers is essential.

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Network Security Architecture
  • DMZ Architecture
  • Firewall Management
  • Palo Alto
  • Versa Networks
  • Network Segmentation
  • Access Control
  • Routing
  • NAT
  • ACLs
  • VPNs
  • Load Balancers
  • Risk Mitigation
  • Least-privilege Access
  • Network Diagramming
  • Security Controls

Additional details

Minimum experience
5+ years
Apply by
Aug 22, 2026