Must Have Technical/Functional Skills
• Proven experience defining enterprise network-security architectures across data centers, colocation facilities, points of presence, cloud, branch, third-party, internet edge, and industrial or manufacturing environments.
• Architecture experience across Check Point and Palo Alto firewalls, LAN switching, load balancing, WAF, secure remote access, Zero Trust/Zscaler, cloud ingress and egress, and OT network segmentation.
• Ability to lead discovery, current-state assessment, architecture-gap analysis, target-state design, design reviews, deployment governance, validation, stabilization, and handover to operations.
• Experience developing and approving HLDs, LLDs, network and security diagrams, traffic and data-flow diagrams, bills of materials, implementation roadmaps, migration strategies, architecture standards, and decision records.
• Strong knowledge of network segmentation, zones, routing, BGP/OSPF, NAT, VPN/IPsec, high availability, resilient design, secure management, DNS, certificates, reverse proxies, and application-delivery dependencies.
• Experience designing security patterns for Site Vault, firewall build and operations, third-party connectivity, Zero Trust, internet ingress/egress, WAF, cloud security, and Secure Connected Shops.
• Experience defining policy governance, firewall-rule assurance, access-control standards, configuration baselines, RBAC, least privilege, segregation of duties, and compliance boundaries.
• Experience reviewing architecture and changes for operational risk, availability, resilience, performance, implementation dependencies, testing, rollback, outage, and maintenance-window requirements.
• Knowledge of AWS and Azure network-security services, load balancers, edge controls, infrastructure as code, SIEM/logging, ServiceNow, CMDB, monitoring, and automation integration.
• Experience supporting incident, problem, vulnerability, change, lifecycle refresh, platform optimization, reliability, and continuous-improvement activities from an architecture perspective.
• Working knowledge of ITAR/export-control, CUI or EC environments, FedRAMP, China data-residency separation, secure administration, audit evidence, and regulated delivery models.
• Relevant certifications such as CISSP, CCNP Security/CCIE Security, PCNSE, Check Point CCSE/CCSM, Zscaler, AWS/Azure Security, TOGAF, or SABSA are preferred.
Roles & Responsibilities
• Own and govern the network-security architecture across assigned secure-network workstreams and global site deployments.
• Lead discovery and assessment of existing physical and logical networks, security platforms, connectivity, traffic flows, remote-access paths, cloud interfaces, operational dependencies, and architecture gaps.
• Define target-state architectures and reusable patterns for Site Vault, firewall platforms, third-party connectivity, Zero Trust, internet ingress/egress, WAF, cloud edge, and Secure Connected Shops.
• Create, review, approve, and maintain HLDs, LLDs, Visio diagrams, traffic-flow diagrams, bills of materials, migration approaches, implementation timelines, standards, and configuration requirements.
• Provide architecture oversight for Check Point, Palo Alto, Cisco, load balancers, Cloudflare WAF, Zscaler, CyberArk, AWS/Azure edge services, Nozomi, SIEM, CMDB, and ITSM integrations as applicable.
• Ensure designs align with approved customer architectures, cybersecurity policies, deployment processes, compliance boundari es, and operational-support requirements.
• Lead or participate in architecture and design reviews, documenting decisions, risks, assumptions, exceptions, dependencies, technical debt, and required remediation actions.
• Review proposed production changes and evaluate security, availability, resilience, performance, dependency, testing, rollback, and maintenance-window risks before implementation.
• Validate implementation against approved designs through configuration review, testing support, evidence checks, cutover assurance, post-implementation review, and as-built documentation.
• Provide cross-tower technical leadership for complex incidents, vulnerabilities, problems, migrations, platform lifecycle activities, and major changes requiring architecture analysis.
• Define reference architectures, guardrails, templates, playbooks, and standardized deployment patterns to support consistent execution across sites and delivery pods.
• Guide operational readiness, monitoring requirements, support-model alignment, knowledge transfer, SOP development, stabilization, and handover to L1/L2/L3 operations.
• Collaborate with network, firewall, cloud, endpoint, identity, application, SOC, OT, site, compliance, service-management, procurement, and vendor stakeholders.
• Identify opportunities for architecture simplification, automation, policy optimization, reliability improvement, and lifecycle modernization while preserving compliance and service continuity.
Generic Managerial Skills, If any
Strong architecture leadership, stakeholder influence, workshop facilitation, technical writing, cross-tower coordination, design governance, and risk-based decision-making in global regulated environments.
Salary Range: $120,000 - $140,000 per year
TCS Employee Benefits Summary:
Discretionary Annual Incentive.
Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.
Family Support: Maternal & Parental Leaves.
Insurance Options: Auto & Home Insurance, Identity Theft Protection.
Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement.
Time Off: Vacation, Time Off, Sick Leave & Holidays.
Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.
More Information
Application Details
- Organization DetailsTCS / Tata Consultancy Services


Recommended Comments
There are no comments to display.
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.