Network Architect
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Mission Overview:
Keystone Solutions is looking for a Network Architect / Engineer for one of its clients. Our client, a large international organisation operating critical infrastructure across multiple countries, is currently undergoing a major network transformation programme. Following a strategic acquisition and the growing need for stronger cybersecurity and operational resilience, they are looking for a senior Network Architect to help shape the future of their IT and Operational Technology (OT) environments.
Consultancy Model at Keystone Solutions:
As a Keystone Solutions consultant, you will work on site and in hybrid settings alongside client stakeholders, driving outcomes while benefiting from Keystone's community of experts. You will apply your expertise within the client's environment, bringing best practices, rigorous documentation, and pragmatic execution. This consultancy mission provides the opportunity to contribute to diverse challenges while Keystone Solutions supports your professional development and exposure to multiple engagements over time.
About the Role:
We are looking for a hands-on Lead Network Architect to drive the technical convergence of two major corporate networks (the client and an acquired company) and build a resilient, future-proof IT/OT infrastructure. This is not a theoretical or project management position: we need a pragmatic, deeply knowledgeable engineer-architect who designs concrete solutions, engineers complex fixes, and authors actionable implementation roadmaps. In this role, you will be the driving force behind two critical group-level challenges:
- Leading the Corporate Network Integration: the client and the acquired company currently operate overlapping IPv4 address spaces and disparate infrastructure. You will own the strategy and execution plan to resolve IP conflicts, design robust interconnection and routing topologies, and deliver seamless, secure integration across the group.
- Building the IT/OT Zero Trust Architecture from scratch: To meet the stringent resilience requirements of the NIS2 Directive (Essential Entity level), a legacy perimeter/VLAN approach will not suffice. The target IT/OT segmentation model does not exist yet. Working in close synergy with the client's Security Architect, you will co-author a group-wide model from a blank canvas, embedding Zero Trust principles and IEC 62443 zones and conduits directly into the fabric of IT and operational parking systems.
Key Responsibilities:
- Resolve the IP address overlap between the client and the acquired company: assess the scope and extent of the conflict between the two networks, and design a recommended resolution path (re-addressing, NAT, or identity-based access abstraction).
- Co-author a Zero-Trust-based IT/OT segmentation model: this is a from-scratch deliverable, not an existing artifact — define zones and conduits using the IEC 62443 structure, with Zero Trust principles (continuous verification, least privilege, assume breach) as the architectural cornerstone, in close collaboration with the client's Security Architect, who owns final approval of target security levels.
- Confirm SD-WAN alignment: as a secondary check — confirm the SD-WAN transport project does not undermine the Zero Trust segmentation design, escalating only if a conflict is found; SD-WAN is supporting infrastructure here, not the architectural driver.
- Deliver a validated pilot design: a working, documented reference design for a representative group of sites, ready for wider rollout.
- Document for handover: ensure the design and its reasoning are fully usable by the client's permanent teams once this engagement ends.
What We're Looking For (Must-Have Skills & Experience):
- Real, hands-on Zero Trust Architecture design experience: NIST SP 800-207 principles applied to network segmentation — not just Zero Trust Network Access for remote users, but continuous verification and least-privilege enforcement between network zones themselves. This is the architectural cornerstone of the role.
- Extremely strong, hands-on IPv4 expertise: addressing, subnetting, route summarization, and real-world experience resolving IP address-space conflicts between two merging corporate networks — essential for the integration work specifically.
- Proven network segmentation design experience: ideally across converged IT/OT environments, not IT alone.
- Working knowledge of IEC 62443 zone/conduit methodology (or an equivalent segmentation framework), with the ability to define a model from first principles rather than apply an existing one.
- Practical, enterprise-scale experience with VLANs, VRFs, routing, and firewall policy design.
- Comfortable working across both classic IT infrastructure and OT/industrial network environments.
- Strong documentation disc