Network Security Architect
Location: Montreal, QC – Hybrid, 4 days onsite / 1 day remote
Employment Type: Full-Time, Permanent
Salary: $90,000–$130,000 CAD, with flexibility for exceptional architecture-level experience
Language: Fluent French and English required
About the Role
We are looking for an experienced Network Security Architect to design, implement, and evolve secure enterprise network environments. This is a hands-on technical architecture role combining network security, routing and switching, firewalls, VPN, Zero Trust, cloud networking, IDS/IPS and secure network design.
The successful candidate will work across network, cloud, application and cybersecurity teams to design secure, scalable solutions and reduce network-security risk.
Key Responsibilities
- Design and implement enterprise network-security architectures, including firewalls, IDS/IPS, secure routing, VPNs, Zero Trust, SD-WAN and SASE.
- Assess existing network architectures, identify security gaps and recommend remediation and hardening measures.
- Design secure solutions across routing, switching, remote access, proxies and enterprise network infrastructure.
- Support cloud networking across AWS and Azure.
- Identify emerging network threats and develop controls to detect, prevent and respond to them.
- Act as an SME and escalation point for complex network-security incidents.
- Support SIEM, EDR and network anomaly-detection integrations.
- Work with network-level identity and access technologies including NAC, 802.1X and RADIUS/TACACS+.
- Collaborate with cloud, infrastructure, application and cybersecurity teams on end-to-end security architecture.
- Mentor technical team members and provide guidance on secure network design and implementation.
- Assess network-security risks and communicate technical recommendations clearly to business and technical stakeholders.
Must-Have Requirements
- CCNA and/or CCNP certification.
- 5+ years of network-security experience.
- Strong hands-on knowledge of routing, switching, VPN technologies and Zero Trust.
- Strong experience with firewalls, proxies, remote access and associated security controls.
- Experience with IDS/IPS, secure routing and network traffic analysis.
- Strong understanding of enterprise network protocols and secure network architecture.
- Bachelor's degree in Computer Science, IT, Engineering or related field, or equivalent education, professional experience and certifications.
- Fluent written and spoken French and English.
Strong Assets
Experience with cloud networking (AWS/Azure), Operational Technology (OT), SANS/GIAC certifications, SIEM/EDR integrations, CMMC, SASE, SD-WAN and enterprise audio/video network environments would be considered strong assets.
Candidates must also be eligible to obtain the required security clearance and Controlled Goods Program assessment.