{"schemaVersion":"jobsearcher.job.v1","id":"f88e33a2587d4e4e162ac4cb","url":"https://jobsearcher.com/jobs/f88e33a2587d4e4e162ac4cb","canonicalUrl":"https://jobsearcher.com/jobs/f88e33a2587d4e4e162ac4cb","title":"Lead Architect - Network Security","description":"Lead Architect - Network Security\n\nReports to: Director - Network Technologies\nLocation: In Office , Orange CT\n\nThe base salary range for this position is dependent upon experience and location, ranging from:\n\n$128,320 - $160,400\n\nWhat We Offer:\n\nCompetitive benefits and growth opportunities\nGenerous performance‑based bonuses\n12% 401(k) match\nComprehensive health, dental, and vision insurance\nTuition reimbursement\nProfessional development and clear career‑advancement pathways\n\nFor more information, please visit: Benefits - Avangrid\n\nJob Summary\n\nThe Lead Architect – Network Security role serves as the senior-most technical and architectural resource for enterprise Network Security. This individual contributor defines the long-term Network Security architecture, strategy, standards, design patterns, and technology roadmap; translates business, operational, regulatory, and security requirements into secure, resilient, scalable, and supportable architectures; and leads modernization and transformation initiatives using current and emerging technologies. The role serves as the senior technical authority and highest escalation point for complex Network Security issues, major incidents, high-risk changes, projects, and technical recovery activities. The Lead Architect provides technical leadership, mentoring, and knowledge transfer to internal engineers, global counterparts, vendors, and contracted support resources without direct people-management responsibility.\n\nKey Responsibilities\n\nOwns enterprise Network Security reference architectures, engineering standards, design patterns, implementation patterns, and technology roadmaps aligned with Avangrid and Iberdrola global standards.\n\nLeads architecture and technical design for firewalls, secure web gateways, web application firewalls, SD-WAN security, network segmentation, Internet and intranet security, cloud connectivity security, and related Network Security platforms.\n\nProvides architecture governance and reviews project designs, lifecycle plans, technical standards, and high-risk changes for alignment with business requirements, security requirements, supportability, resiliency, and global standards.\n\nServes as senior technical authority and highest escalation point for complex troubleshooting, root-cause analysis, major incidents, break/fix issues, lifecycle upgrades, technical recovery activities, and critical Network Security changes.\n\nLeads Network Security modernization, automation, standardization, resiliency improvement, lifecycle management, technical-debt reduction, and continuous improvement of Internet, intranet, and enterprise security infrastructure.\n\nEvaluates emerging Network Security technologies and recommends adoption, replacement, or retirement decisions based on business value, risk, operational impact, supportability, lifecycle position, and strategic alignment.\n\nDirects technical execution for complex projects and high-risk changes by translating business, operational, regulatory, and security requirements into secure Network Security architectures and process designs.\n\nProvides technical direction, mentoring, and documented knowledge transfer to internal engineers, global counterparts, outsourced service providers, and contracted support resources while retaining internal architecture accountability.\n\nManages technical relationships with technology vendors and outsourced service providers, coordinates design and implementation activities, and ensures technical deliverables are executed according to approved architecture and standards.\n\nPartners with Cybersecurity, Infrastructure, Cloud, Applications, Audit, Compliance, Network Engineering, and global counterparts on architecture decisions, security investigations, risk assessments, audits, and regulatory requirements where Network Security expertise is required.\n\nProduces and maintains architecture diagrams, engineering standards, design decisions, implementation patterns, troubleshooting procedures, operational runbooks, recovery documentation, and resolution scripts.\n\nOwns or governs administration, configuration, optimization, and lifecycle activities for enterprise Network Security platforms, including firewall policy management, high-availability design, firmware upgrades, secure web gateway policies, web application firewall tuning, SD-WAN security, SIEM integration, and automation integration where applicable.\n\nRequired Qualifications\n\nBachelor’s degree in Computer Science, Information Systems, Engineering, Cybersecurity, or a related field; an equivalent combination of education and experience may be considered.\n\nAt least eight (8) years of progressively responsible enterprise Network Security experience.\n\nDemonstrated experience leading the architecture, design, implementation, lifecycle management, and operational support of complex enterprise Network Security environments.\n\nAdvanced hands-on troubleshooting, root-cause analysis, and incident-resolution experience across enterprise Network Security infrastructure.\n\nExperience providing technical leadership across internal teams, global counterparts, vendors, and contracted service providers.\n\nExperience creating technology roadmaps, architecture standards, modernization plans, operational runbooks, and technical documentation.\n\nPreferred Qualifications\n\nExperience with enterprise firewall platforms such as Fortinet/FortiGate, Palo Alto Networks, and Check Point.\n\nExperience with secure web gateway technologies such as Zscaler and web application firewall technologies such as Akamai.\n\nExperience with SD-WAN security, network segmentation, high-availability design, firmware lifecycle management, and security policy optimization.\n\nExperience with SIEM integration, network automation, troubleshooting procedures, resolution scripts, and operational runbook development.\n\nRelevant vendor certifications such as Fortinet NSE, Palo Alto PCNSE, Check Point CCSA/CCSE, Zscaler Certified Professional, or Akamai Security certifications.\n\n#LI-Onsite\n\n#LI-VF1\n\nCompany:\n\nAVANGRID MANAGEMENT COMPANY, LLC.\n\nMobility Information\n\nPlease note that any applicant who is not a citizen of the country of the vacancy will be subject to compliance with the applicable immigration requirements to legally work in that country.\n\nAt Avangrid we provide fair and equal employment and advancement opportunities for all employees and candidates regardless of race, color, religion, national origin, gender, sexual orientation, age, marital status, disability, protected veteran status or any other status protected by federal, state, or local law.\nIf you are an individual with a disability or a disabled veteran who is unable to use our online tool to search for or to apply for jobs, you may request a reasonable accommodation by contacting our People and Organization department at careers@avangrid.com .\n\nAvangrid employees may be assigned a system emergency role and in the event of a system emergency, may be required to work outside of their regular schedule/job duties. This is applicable to employees that will work in Connecticut, Maine, Massachusetts, and New York within Avangrid Network and Corporate functions. This does not include those that will work for Avangrid Power.\n\nAvangrid employees may also be assigned a NERC Reliability Standards compliance role supporting Critical Infrastructure Protection (CIP) and/or Operations and Planning (O&P) responsibilities. This is applicable to employees that will work in electric transmission, operations, and cyber security business areas in Connecticut, Maine, Massachusetts, and New York within Avangrid Network and Corporate business areas. NERC Reliability Standards compliance roles and responsibilities may include additional access protections, training, audit engagement, and required evidence retention, and will be communicated by the employee’s management.\n\nJob Posting End Date:\n\nSeptember-18-2026","company":"Avangrid","rawCompany":"avangrid","city":"New Haven","state":"CT","isRemote":false,"isActive":false,"createdAt":"2026-08-19T12:52:56.564Z","occupations":[{"code":"15-1241.00","title":"Computer Network Architects","slug":"computer-network-architects"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541330","title":"Engineering Services","slug":"engineering-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Architect - Network Security","description":"Lead Architect - Network Security\n\nReports to: Director - Network Technologies\nLocation: In Office , Orange CT\n\nThe base salary range for this position is dependent upon experience and location, ranging from:\n\n$128,320 - $160,400\n\nWhat We Offer:\n\nCompetitive benefits and growth opportunities\nGenerous performance‑based bonuses\n12% 401(k) match\nComprehensive health, dental, and vision insurance\nTuition reimbursement\nProfessional development and clear career‑advancement pathways\n\nFor more information, please visit: Benefits - Avangrid\n\nJob Summary\n\nThe Lead Architect – Network Security role serves as the senior-most technical and architectural resource for enterprise Network Security. This individual contributor defines the long-term Network Security architecture, strategy, standards, design patterns, and technology roadmap; translates business, operational, regulatory, and security requirements into secure, resilient, scalable, and supportable architectures; and leads modernization and transformation initiatives using current and emerging technologies. The role serves as the senior technical authority and highest escalation point for complex Network Security issues, major incidents, high-risk changes, projects, and technical recovery activities. The Lead Architect provides technical leadership, mentoring, and knowledge transfer to internal engineers, global counterparts, vendors, and contracted support resources without direct people-management responsibility.\n\nKey Responsibilities\n\nOwns enterprise Network Security reference architectures, engineering standards, design patterns, implementation patterns, and technology roadmaps aligned with Avangrid and Iberdrola global standards.\n\nLeads architecture and technical design for firewalls, secure web gateways, web application firewalls, SD-WAN security, network segmentation, Internet and intranet security, cloud connectivity security, and related Network Security platforms.\n\nProvides architecture governance and reviews project designs, lifecycle plans, technical standards, and high-risk changes for alignment with business requirements, security requirements, supportability, resiliency, and global standards.\n\nServes as senior technical authority and highest escalation point for complex troubleshooting, root-cause analysis, major incidents, break/fix issues, lifecycle upgrades, technical recovery activities, and critical Network Security changes.\n\nLeads Network Security modernization, automation, standardization, resiliency improvement, lifecycle management, technical-debt reduction, and continuous improvement of Internet, intranet, and enterprise security infrastructure.\n\nEvaluates emerging Network Security technologies and recommends adoption, replacement, or retirement decisions based on business value, risk, operational impact, supportability, lifecycle position, and strategic alignment.\n\nDirects technical execution for complex projects and high-risk changes by translating business, operational, regulatory, and security requirements into secure Network Security architectures and process designs.\n\nProvides technical direction, mentoring, and documented knowledge transfer to internal engineers, global counterparts, outsourced service providers, and contracted support resources while retaining internal architecture accountability.\n\nManages technical relationships with technology vendors and outsourced service providers, coordinates design and implementation activities, and ensures technical deliverables are executed according to approved architecture and standards.\n\nPartners with Cybersecurity, Infrastructure, Cloud, Applications, Audit, Compliance, Network Engineering, and global counterparts on architecture decisions, security investigations, risk assessments, audits, and regulatory requirements where Network Security expertise is required.\n\nProduces and maintains architecture diagrams, engineering standards, design decisions, implementation patterns, troubleshooting procedures, operational runbooks, recovery documentation, and resolution scripts.\n\nOwns or governs administration, configuration, optimization, and lifecycle activities for enterprise Network Security platforms, including firewall policy management, high-availability design, firmware upgrades, secure web gateway policies, web application firewall tuning, SD-WAN security, SIEM integration, and automation integration where applicable.\n\nRequired Qualifications\n\nBachelor’s degree in Computer Science, Information Systems, Engineering, Cybersecurity, or a related field; an equivalent combination of education and experience may be considered.\n\nAt least eight (8) years of progressively responsible enterprise Network Security experience.\n\nDemonstrated experience leading the architecture, design, implementation, lifecycle management, and operational support of complex enterprise Network Security environments.\n\nAdvanced hands-on troubleshooting, root-cause analysis, and incident-resolution experience across enterprise Network Security infrastructure.\n\nExperience providing technical leadership across internal teams, global counterparts, vendors, and contracted service providers.\n\nExperience creating technology roadmaps, architecture standards, modernization plans, operational runbooks, and technical documentation.\n\nPreferred Qualifications\n\nExperience with enterprise firewall platforms such as Fortinet/FortiGate, Palo Alto Networks, and Check Point.\n\nExperience with secure web gateway technologies such as Zscaler and web application firewall technologies such as Akamai.\n\nExperience with SD-WAN security, network segmentation, high-availability design, firmware lifecycle management, and security policy optimization.\n\nExperience with SIEM integration, network automation, troubleshooting procedures, resolution scripts, and operational runbook development.\n\nRelevant vendor certifications such as Fortinet NSE, Palo Alto PCNSE, Check Point CCSA/CCSE, Zscaler Certified Professional, or Akamai Security certifications.\n\n#LI-Onsite\n\n#LI-VF1\n\nCompany:\n\nAVANGRID MANAGEMENT COMPANY, LLC.\n\nMobility Information\n\nPlease note that any applicant who is not a citizen of the country of the vacancy will be subject to compliance with the applicable immigration requirements to legally work in that country.\n\nAt Avangrid we provide fair and equal employment and advancement opportunities for all employees and candidates regardless of race, color, religion, national origin, gender, sexual orientation, age, marital status, disability, protected veteran status or any other status protected by federal, state, or local law.\nIf you are an individual with a disability or a disabled veteran who is unable to use our online tool to search for or to apply for jobs, you may request a reasonable accommodation by contacting our People and Organization department at careers@avangrid.com .\n\nAvangrid employees may be assigned a system emergency role and in the event of a system emergency, may be required to work outside of their regular schedule/job duties. This is applicable to employees that will work in Connecticut, Maine, Massachusetts, and New York within Avangrid Network and Corporate functions. This does not include those that will work for Avangrid Power.\n\nAvangrid employees may also be assigned a NERC Reliability Standards compliance role supporting Critical Infrastructure Protection (CIP) and/or Operations and Planning (O&P) responsibilities. This is applicable to employees that will work in electric transmission, operations, and cyber security business areas in Connecticut, Maine, Massachusetts, and New York within Avangrid Network and Corporate business areas. NERC Reliability Standards compliance roles and responsibilities may include additional access protections, training, audit engagement, and required evidence retention, and will be communicated by the employee’s management.\n\nJob Posting End Date:\n\nSeptember-18-2026","datePosted":"2026-08-19T12:52:56.564Z","dateModified":"2026-08-19T12:52:56.564Z","hiringOrganization":{"@type":"Organization","name":"Avangrid","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New Haven","addressRegion":"CT","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f88e33a2587d4e4e162ac4cb"},"url":"https://jobsearcher.com/jobs/f88e33a2587d4e4e162ac4cb"}}