The Role:We are seeking an experienced Network Analyst to play a role in a large-scale network segmentation and Zero Trust transformation initiative. This position is responsible for driving end-to-end traffic analysis, segmentation policy strategy, and application onboarding across data centers, global offices, and multi-cloud environments.
As a member of the team, you will operate with a high degree of autonomy, partnering closely with engineering, cybersecurity, and application teams to enable the transition from flat networks to highly controlled, micro-segmented environments. You will be accountable for ensuring segmentation policies are accurate, scalable, and aligned to business and security objectives.
Key Responsibilities:Design & Architecture Leadership
- Analysis of complex enterprise network flows to define segmentation and micro segmentation strategies
- Help drive development and refinement of Zero Trust-aligned segmentation models (application-centric, environment-based, hybrid)
- Translate business, application, and regulatory requirements into actionable segmentation design inputs
- Provide thought leadership on segmentation best practices, policy structures, and onboarding strategies
- Partner with engineering to ensure design intent is accurately implemented across platforms
Traffic Analysis & Policy Strategy- Application dependency mapping and traffic flow analysis across large-scale environments
- Partner to develop segmentation policy frameworks, including allow/deny models and least-privilege strategies
- Partner on policy lifecycle: discovery, simulation, validation, and enforcement readiness
- Identify systemic risks such as over-permissive access, shadow dependencies, and undocumented flows
- Establish standards for policy quality, reusability, and scalability across the organization
Implementation Oversight- Provide guidance for onboarding applications into segmentation platforms across on-prem and cloud environments
- Validate alignment across: segmentation platforms, firewalls and ACLs, and cloud-native security controls
- Ensure consistency between segmentation design, engineering implementation, and operational enforcement
Operations & Optimization- Define and track segmentation effectiveness metrics (policy accuracy, enforcement success, exception rates)
- Partner to drive continuous improvement of segmentation policy posture and operational processes
- Identify gaps in visibility, tooling, or automation and recommend strategic enhancements
Qualifications:7–10+ years of experience in:- Network/Data analysis, engineering, or network security
- Enterprise/data center networking environments
Advanced experience with:- Application dependency mapping and traffic flow analysis at scale
- East-west traffic visibility and segmentation policy design
Strong familiarity with:- Segmentation tools (Illumio, Guardicore/Akamai, Cisco Secure Workload/Tetration)
- Enterprise networking platforms (Cisco, Arista, Palo Alto, Check Point, Juniper)
High level understanding of:- TCP/IP, routing, and switching
- Network security principles, firewalls, and access control models
- Segmentation and Zero Trust architectures
Experience with:- Cloud networking (AWS, Azure, GCP)
- CMDB and asset inventory systems (e.g., ServiceNow)
Working knowledge of:- Automation/scripting (Python, PowerShell, APIs)
- Kubernetes/container networking (preferred)