Iberdrola

Lead Architect - Network Security

United States Of America, Connecticut, Orange · Posted 1h ago

$128-160Kleadpermanentonsite
firewallsSD-WANWAF

Job Description

Lead Architect - Network Security

Reports to: Director - Network Technologies
Location:
In Office, Orange CT

The base salary range for this position is dependent upon experience and location, ranging from:

  • $128,320 - $160,400

What We Offer:

  • Competitive benefits and growth opportunities
  • Generous performance‑based bonuses
  • 12% 401(k) match
  • Comprehensive health, dental, and vision insurance
  • Tuition reimbursement
  • Professional development and clear career‑advancement pathways

For more information, please visit: Benefits - Avangrid

Job Summary

The Lead Architect – Network Security role serves as the senior-most technical and architectural resource for enterprise Network Security. This individual contributor defines the long-term Network Security architecture, strategy, standards, design patterns, and technology roadmap; translates business, operational, regulatory, and security requirements into secure, resilient, scalable, and supportable architectures; and leads modernization and transformation initiatives using current and emerging technologies. The role serves as the senior technical authority and highest escalation point for complex Network Security issues, major incidents, high-risk changes, projects, and technical recovery activities. The Lead Architect provides technical leadership, mentoring, and knowledge transfer to internal engineers, global counterparts, vendors, and contracted support resources without direct people-management responsibility.

Key Responsibilities

  • Owns enterprise Network Security reference architectures, engineering standards, design patterns, implementation patterns, and technology roadmaps aligned with Avangrid and Iberdrola global standards.

  • Leads architecture and technical design for firewalls, secure web gateways, web application firewalls, SD-WAN security, network segmentation, Internet and intranet security, cloud connectivity security, and related Network Security platforms.

  • Provides architecture governance and reviews project designs, lifecycle plans, technical standards, and high-risk changes for alignment with business requirements, security requirements, supportability, resiliency, and global standards.

  • Serves as senior technical authority and highest escalation point for complex troubleshooting, root-cause analysis, major incidents, break/fix issues, lifecycle upgrades, technical recovery activities, and critical Network Security changes.

  • Leads Network Security modernization, automation, standardization, resiliency improvement, lifecycle management, technical-debt reduction, and continuous improvement of Internet, intranet, and enterprise security infrastructure.

  • Evaluates emerging Network Security technologies and recommends adoption, replacement, or retirement decisions based on business value, risk, operational impact, supportability, lifecycle position, and strategic alignment.

  • Directs technical execution for complex projects and high-risk changes by translating business, operational, regulatory, and security requirements into secure Network Security architectures and process designs.

  • Provides technical direction, mentoring, and documented knowledge transfer to internal engineers, global counterparts, outsourced service providers, and contracted support resources while retaining internal architecture accountability.

  • Manages technical relationships with technology vendors and outsourced service providers, coordinates design and implementation activities, and ensures technical deliverables are executed according to approved architecture and standards.

  • Partners with Cybersecurity, Infrastructure, Cloud, Applications, Audit, Compliance, Network Engineering, and global counterparts on architecture decisions, security investigations, risk assessments, audits, and regulatory requirements where Network Security expertise is required.

  • Produces and maintains architecture diagrams, engineering standards, design decisions, implementation patterns, troubleshooting procedures, operational runbooks, recovery documentation, and resolution scripts.

  • Owns or governs administration, configuration, optimization, and lifecycle activities for enterprise Network Security platforms, including firewall policy management, high-availability design, firmware upgrades, secure web gateway policies, web application firewall tuning, SD-WAN security, SIEM integration, and automation integration where applicable.

Required Qualifications

  • Bachelor’s degree in Computer Science, Information Systems, Engineering, Cybersecurity, or a related field; an equivalent combination of education and experience may be considered.

  • At least eight (8) years of progressively responsible enterprise Network Security experience.

  • Demonstrated experience leading the architecture, design, implementation, lifecycle management, and operational support of complex enterprise Network Security environments.

  • Advanced hands-on troubleshooting, root-cause analysis, and incident-resolution experience across enterprise Network Security infrastructure.

  • Experience providing technical leadership across internal teams, global counterparts, vendors, and contracted service providers.

  • Experience creating technology roadmaps, architecture standards, modernization plans, operational runbooks, and technical documentation.

Preferred Qualifications

  • Experience with enterprise firewall platforms such as Fortinet/FortiGate, Palo Alto Networks, and Check Point.

  • Experience with secure web gateway technologies such as Zscaler and web application firewall technologies such as Akamai.

  • Experience with SD-WAN security, network segmentation, high-availability design, firmware lifecycle management, and security policy optimization.

  • Experience with SIEM integration, network automation, troubleshooting procedures, resolution scripts, and operational runbook development.

  • Relevant vendor certifications such as Fortinet NSE, Palo Alto PCNSE, Check Point CCSA/CCSE, Zscaler Certified Professional, or Akamai Security certifications.

#LI-Onsite

#LI-VF1

Company:

AVANGRID MANAGEMENT COMPANY, LLC.

Mobility Information

Please note that any applicant who is not a citizen of the country of the vacancy will be subject to compliance with the applicable immigration requirements to legally work in that country.

At Avangrid we provide fair and equal employment and advancement opportunities for all employees and candidates regardless of race, color, religion, national origin, gender, sexual orientation, age, marital status, disability, protected veteran status or any other status protected by federal, state, or local law.
If you are an individual with a disability or a disabled veteran who is unable to use our online tool to search for or to apply for jobs, you may request a reasonable accommodation by contacting our People and Organization department at careers@avangrid.com.

Avangrid employees may be assigned a system emergency role and in the event of a system emergency, may be required to work outside of their regular schedule/job duties. This is applicable to employees that will work in Connecticut, Maine, Massachusetts, and New York within Avangrid Network and Corporate functions.  This does not include those that will work for Avangrid Power.

Avangrid employees may also be assigned a NERC Reliability Standards compliance role supporting Critical Infrastructure Protection (CIP) and/or Operations and Planning (O&P) responsibilities. This is applicable to employees that will work in electric transmission, operations, and cyber security business areas in Connecticut, Maine, Massachusetts, and New York within Avangrid Network and Corporate business areas. NERC Reliability Standards compliance roles and responsibilities may include additional access protections, training, audit engagement, and required evidence retention, and will be communicated by the employee’s management.

Job Posting End Date:

September-18-2026