- Company Name
- Bath & Body Works
- Job Title
- Network Security Architect
- Job Description
-
**Job Title:** Network Security Architect
**Role Summary**
Design, implement, and oversee secure network architectures across on-premises, cloud, and hybrid environments. Serve as a strategic advisor on security architecture, collaborate with cross-functional teams, and ensure compliance with regulatory and technical standards to mitigate evolving threats.
**Expectations**
8+ years in enterprise network security architecture/engineering. Advanced expertise in frameworks (NIST, ISO, PCI-DSS), modern security technologies (Zero Trust, micro-segmentation), and cloud security controls (ASGs/NSGs). Proficiency in threat modeling, vulnerability assessments, and incident response.
**Key Responsibilities**
- Design secure networks with Zero Trust, micro-segmentation, and compliance integration.
- Advise on security architecture for projects; participate in design reviews and threat modeling.
- Evaluate and deploy network security tools (firewalls, WAFs, DNS, SIEMs) for visibility and threat protection.
- Develop and maintain security policies, documentation, and data flow architectures.
- Partner with engineering teams to embed security into network and application layers.
- Conduct risk assessments, vulnerability testing, and mitigation strategies.
- Configure and validate network components (VPN gateways, load balancers) for security compliance.
- Mentor junior staff and align security strategies with business and regulatory goals.
- Monitor global security trends and support incident response as needed.
**Required Skills**
- Network security design (firewalls, WAFs, IDS/IPS, DLP).
- Cloud security (SASE, ASGs/NSGs, IaaS/PaaS/SaaS).
- Regulatory compliance (NIST, ISO 17799, GDPR, PCI-DSS, HIPAA).
- Cybersecurity tools (SIEM, SOAR, DLP, SIEM, network forensics).
- Network protocols, authentication, and CI/CD pipelines.
- Scripting/query languages (e.g., KQL).
- Communication skills to explain technical concepts to stakeholders.
**Required Education & Certifications**
- Bachelor’s in cybersecurity, computer science, or engineering.
- Certifications: CISSP, CCSP, GSEC, GDSA, Network+; vendor-specific (Palo Alto, Cisco) preferred.