Senior Architect Perimeter & Dmz

Bank of America Bank of America · Banking · Chandler, AZ

This role leads the network security architecture for perimeter services, external connectivity, and modern DMZ design, ensuring secure exposure of workloads and services across internet, partner, and third-party channels in line with evolving access patterns and zero trust principles. It involves defining architectural vision, designing secure architectures for inbound and outbound services, and partnering with various teams to embed security into network designs.

What you'd actually do

  1. Works across the business, operations and technology to create the solution intent and architectural vision for complex solutions and prioritize functional and non-functional requirements into a technology backlog to enable the technology roadmap and functionality to support evolving capabilities and services
  2. Contributes to the creation of the architecture roadmap of defined domains (Business, Application, Data, and Technology) in support of the product roadmap and the development of best practices including standardized templates
  3. Clarifies the architecture, assists with system design to support implementation, and provides solution options to resolve any architectural impediments
  4. Facilitates solution driven discussions, leads the design of complex architectures, and finds creative solutions through knowledge of domain, practical experiments, and proof of concepts while ensuring architecture is flexible, modular, and adaptable
  5. Educates team members on the technology practices, standardization strategies, and best practices to create innovative solutions

Skills

Required

  • 10+ years of progressive infrastructure / network / security engineering experience
  • 5+ years in architecture or senior technical leadership roles
  • experience taking ownership of perimeter security and DMZ architectures for large-scale, high-availability enterprise environments
  • Proven delivery experience in regulated industries (financial services strongly preferred)
  • strong understanding of audit, risk, and control expectations
  • Strong experience leading cross-functional initiatives involving Network, Security, App teams, IAM, SRE/Operations, and Governance/Risk/Compliance (GRC)
  • Deep expertise designing and implementing segmented DMZ and perimeter architectures
  • Experience embedding security measures
  • Familiarity with threat modeling for internet-facing applications and partner connectivity
  • Demonstrated ability to create and enforce reference architectures, standards, patterns, and guardrails

Nice to have

  • Palo Alto
  • Fortinet
  • Check Point
  • Cisco
  • Juniper SRX
  • F5
  • HAProxy
  • NGINX
  • cloud LBs
  • Akamai/Cloudflare (WAF/DDoS/CDN)
  • Imperva
  • API gateways (Apigee, Kong, Mulesoft, AWS API Gateway / Azure APIM)
  • SIEM integration

What the JD emphasized

  • perimeter security and DMZ architectures
  • regulated industries
  • zero trust principles
  • segmented DMZ and perimeter architectures
  • reference architectures, standards, patterns, and guardrails