- Location
- Penang 15, Penang, Malaysia · Bengaluru, Karnataka, India
- Workplace
- Remote, Hybrid
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Source
- Workday
Description
Job Details:
Job Description:
About the Role
This principal-level individual contributor serves as Altera’s senior technical authority for network security architecture and engineering. The role defines scalable security patterns, guides complex designs, and provides hands-on expertise to strengthen the resilience, integrity, and protection of Altera’s global infrastructure and data.
Department Description
Altera’s Information Security organization is responsible for:
- Incident response and digital forensics
- Threat hunting and event analysis
- Security policy, standards, and governance
- Risk assessments and advisory
- Security architecture and engineering support
- Threat detection, monitoring, and forensic capabilities
- Security awareness and education
- Endpoint, network, and cloud security
As Principal Network Security Engineer/Architect, you will shape, design, and improve the security of Altera’s on-premises, cloud, and hybrid network environments. You will operate as a hands-on technical lead and trusted advisor, influencing engineering teams through architecture, standards, technical decisions, and mentorship without direct people-management responsibility.
Technical Strategy & Architecture Ownership
- Define and evolve Altera’s enterprise network security strategy, target-state architecture, technical roadmap, and reusable reference patterns.
- Serve as the senior technical authority for complex network security decisions, design exceptions, and modernization initiatives.
- Drive adoption of Zero Trust, least-privilege access, micro-segmentation, and secure-by-design network principles.
- Establish architecture standards, decision criteria, and measurable outcomes for attack-path reduction, rule hygiene, segmentation coverage, resilience, and network visibility.
Network Security Architecture & Engineering
- Architect and review secure designs for data center, campus, laboratory, cloud, WAN, remote-access, and hybrid environments.
- Design segmentation and traffic-control models using security zones, VRFs, next-generation firewalls, secure routing, identity-aware access, and workload-level controls.
- Evaluate and guide adoption of ZTNA, SWG, SASE, SD-WAN, NDR, IDS/IPS, firewall, and network-security automation capabilities.
- Partner with network, cloud, platform, product security, and operations teams to translate security requirements into implementable designs.
- Validate architecture through design reviews, configuration analysis, packet and flow analysis, resilience testing, and post-implementation verification.
- Conduct ongoing firewall administration and operations including policy lifecycle management, rule administration, hardening, and exception governance.
Threat Detection, Monitoring, & Incident Response
- Provide senior technical expertise during investigations involving network intrusion, lateral movement, command-and-control activity, privilege misuse, and data exfiltration.
- Design and improve network telemetry, logging, detection coverage, and correlation across SIEM, NDR, firewalls, proxies, DNS, VPN, and cloud network services.
- Perform or guide packet capture, flow analysis, protocol troubleshooting, and root-cause analysis for complex security events.
- Act as a technical escalation point during major incidents and translate findings into architecture improvements, detection enhancements, and remediation plans.
Risk Management, Governance & Compliance
- Perform security architecture and risk assessments for new systems, cloud services, network changes, and exceptions.
- Author and maintain network security standards, reference architectures, technical guidelines, and control requirements.
- Align designs with relevant frameworks and requirements, including NIST CSF, NIST SP 800-53, NIST SP 800-207, and ISO/IEC 27001.
- Provide technical evidence and remediation guidance for audits, assessments, and control-validation activities.
Cross‑Functional Collaboration & Communication
- Serve as a trusted technical advisor to IT & Engineering teams including Network Engineering, Cloud, Infrastructure, DevOps, Product Security, Risk, Privacy, and Legal stakeholders.
- Facilitate architecture workshops and design reviews, clearly documenting decisions, risks, assumptions, and required controls.
- Translate complex technical risks into practical, business-aligned recommendations for engineering and executive audiences.
- Influence delivery teams without direct authority and mentor engineers through technical guidance, peer review, and knowledge sharing.
Qualifications:
Required Experience
- 8+ years of progressive experience in enterprise networking and cybersecurity, including substantial experience designing security architecture for large, distributed environments.
- Demonstrated success serving as a principal engineer, architect, or senior technical authority for complex network-security programs and transformations.
- Proven ability to own technical outcomes from discovery and requirements through design, implementation guidance, validation, and operational transition.
Technical Expertise
- Deep expertise in enterprise network architecture, TCP/IP, routing, switching, BGP, DNS, TLS, proxies, VPN, firewalls, IDS/IPS, segmentation, and Zero Trust.
- Hands-on experience with next-generation firewalls, firewall policy governance, ZTNA, SWG, SASE, SD-WAN, NDR, SIEM, and related network-security controls.
- Strong packet capture, protocol analysis, network-flow analysis, and complex troubleshooting skills.
- Experience designing secure network connectivity and controls across on-prem, cloud and hybrid environments.
- Experience with common enterprise platforms such as Cisco, Palo Alto Networks, Tufin, Azure, AWS, or comparable technologies.
- Strong understanding of high availability, failover, capacity, secure management planes, encrypted connectivity, and resilient architecture.
Operational & Strategic Skills
- Experience in firewall management, administration, and operations including firewall architecture, policy lifecycle management, rule recertification, configuration hardening, and operational governance.
- Ability to identify and reduce attack paths, improve rule hygiene, expand segmentation coverage, and strengthen network telemetry.
- Proficiency in network incident response, technical escalation, root-cause analysis, and remediation design.
- Ability to establish repeatable engineering processes, architecture review methods, validation criteria, and operational runbooks.
- Experience automating network-security analysis, policy management, validation, or reporting using Python, APIs, infrastructure-as-code, KQL, or similar technologies.
Communication & Influence
- Excellent executive‑level communication skills.
- Ability to translate technical concepts into business‑aligned recommendations.
- Strong stakeholder management across technical and non‑technical teams.