Network Architect
il y a 2 jours
Lyon
Title: Network Architect Location: Lyon, France (Hybrid) Employment Contract. Job Description: 20 Years Exp. Required Profile & Skills: Technical Expertise Network Architecture • Strong experience designing enterprise-scale network architectures across Campus, Data Centre, WAN, WLAN, Cloud and Hybrid Connectivity environments., • Ability to define architecture principles, standards, patterns and target-state designs., • Strong understanding of enterprise network resilience, scalability, segmentation, performance and operational supportability. Routing, Switching & WLAN • Deep knowledge of Cisco environments across Campus and Data Centre domains., • Strong understanding of Aruba network environments, including Aruba Central, switch deployment, Wi-Fi access points and standard network protocols., • Excellent knowledge of STP, VLANs, IP addressing, Radius, routing, switching and network access control principles. Dynamic Routing, WAN & SD-WAN • Strong architectural understanding of WAN and SD-WAN models., • Advanced knowledge of BGP and OSPF., • Ability to design and govern routing across multi-vendor and multi-environment landscapes, including Cisco, Aruba, Fortinet, Palo Alto and Azure/AWS cloud environments. Network Security & Firewalling • Strong understanding of security architecture principles applied to network infrastructure., • Good knowledge of Fortinet technologies, including FortiManager and FortiGate architecture and integration principles., • Good knowledge of Palo Alto firewalling and traffic filtering design., • Ability to define secure connectivity models, filtering principles, segmentation patterns, VPN architecture and cloud security integration. Data Centre & Advanced Network Technologies • Strong understanding of Cisco ACI architecture and data centre network design., • Ability to provide guidance on complex routing, segmentation and data centre interconnect scenarios., • Knowledge of F5 load balancing concepts would be an advantage., • Knowledge of Zscaler proxy architecture would be an advantage. DDI, Monitoring & Tooling • Solid understanding of DDI architecture, ideally with Efficient IP., • Ability to define IP addressing, DNS/DHCP integration and dependency models., • Experience defining network monitoring, observability and operational-readiness requirements., • Familiarity with network automation, configuration governance and Network as Code approaches., • Knowledge of Cisco Catalyst Center automation capabilities would be beneficial. Soft Skills & Languages Mandatory English – Fluent • Fluent written and spoken English is essential for operating in an international context., • Ability to write clear architecture documentation, design principles, decision records and technical standards in English., • Ability to collaborate with local IT teams and global stakeholders across multiple countries. Leadership & Communication • Strong ability to explain complex network architecture topics clearly to technical and non-technical stakeholders., • Ability to influence technical decisions without direct hierarchical authority., • Proven ability to work with architects, engineers, operations teams, security teams and project managers. Governance & Documentation • Strong rigour in producing structured, high-quality architecture documentation., • Ability to maintain architecture consistency across projects, regions and technology domains., • Comfortable contributing to technical committees, steering committees and architecture review boards. Team Spirit & Pedagogy • Ability to integrate quickly into an existing technical organization., • Strong knowledge-transfer mindset., • Ability to guide engineers and local IT teams during design, deployment, migration and transition phases. Optional Skills • Experience with F5 load balancing architecture., • Knowledge of Zscaler proxy and secure internet access architectures., • Familiarity with Cisco Catalyst Center for automation and network assurance., • Experience with cloud networking on Azure and/or AWS., • Experience contributing to NIS 2, cybersecurity resilience or infrastructure compliance programmes. Experience leading architecture reviews, design boards or technical governance forums. Key Responsibilities and Activities 1. Network Architecture, Strategy & Design Authority • Architecture Definition: Define target network architectures for on-premise, data centre, campus, WAN, WLAN, cloud and hybrid connectivity environments., • Design Authority: Act as a technical design authority for network infrastructure projects, ensuring that proposed solutions are robust, secure, scalable and aligned with enterprise standards., • Architecture Governance: Review and validate high-level designs, low-level designs, migration approaches, technical patterns and implementation choices proposed by engineering or project teams., • Technology Roadmap: Contribute to the evolution of the network technology roadmap, including routing, switching, SD-WAN, WLAN, cloud networking, firewalling, segmentation and automation., • Standardization: Define and maintain network architecture standards, reference designs, design principles and reusable technical patterns across Groupe SEB’s global environments. 1. Network Security & Compliance Architecture • Security-by-Design: Integrate security requirements into network architecture, including segmentation, filtering, access control, VPN, firewalling, cloud connectivity and secure remote access., • Firewall & Security Architecture: Define architectural principles and target designs for Palo Alto, Fortinet/FortiManager/FortiGate, vRouters and related security platforms., • Regulatory Alignment: Ensure network architecture takes account of regulatory and security requirements, including NIS 2-related resilience, traceability, segmentation and operational control expectations., • Risk Management: Identify architecture risks, technical debt, non-standard implementations and resilience gaps; propose mitigation plans and prioritized remediation actions., • Operational Security: Work with cybersecurity and operations teams to ensure that network designs can be monitored, operated, audited and maintained securely. 1. Campus, Data Centre, WAN, WLAN & Cloud Network Architecture • Campus & WLAN Architecture: Define architecture standards for Cisco and Aruba-based LAN/WLAN environments, including switching, wireless access, VLAN design, STP, Radius integration and access policies., • Data Centre Architecture: Provide architecture expertise for data centre network environments, including Cisco technologies, Cisco ACI and complex routing designs., • WAN / SD-WAN Architecture: Define and govern WAN and SD-WAN architectures, including dynamic routing, connectivity models and integration across global sites., • Dynamic Routing: Provide architectural guidance on routing protocols such as BGP and OSPF across multi-technology environments including Cisco, Aruba, Fortinet, Palo Alto and public cloud platforms., • Cloud Networking: Support the design of secure and resilient connectivity between on-premise environments and public/private cloud platforms, including Azure and AWS., • DDI Integration: Define architectural principles for DDI services, including Efficient IP integration, IP addressing, DNS/DHCP design and operational dependencies. 1. Automation, Monitoring & Network Industrialization • Network as Code Strategy: Define architecture principles for automated network deployment, configuration management, compliance checking and repeatable infrastructure delivery., • Automation Governance: Support the industrialization of network build and change processes through automation tooling, including potential use of Cisco Catalyst Center and other orchestration platforms., • Monitoring Architecture: Define monitoring requirements, key metrics, alerting principles, and observability expectations for network services., • Operational Readiness: Ensure that monitoring, logging, performance indicators and support procedures are included in network architecture deliverables before production release., • Tooling Alignment: Work with engineering and operations teams to align network tooling with architecture principles, operational requirements and security expectations. 1. Project Support, Technical Leadership & Transition to RUN • Architecture Support to Projects: Provide architecture support to deployment, migration, security and transformation projects across global network infrastructures., • Technical Leadership: Guide network engineers and project teams on complex design decisions, particularly around Cisco ACI, dynamic routing, SD-WAN, segmentation, firewalling and cloud connectivity., • Design Documentation: Produce and validate architecture documentation, including high-level designs, architecture decision records, network diagrams, design standards and technical principles., • Transition to RUN: Ensure that solutions are production-ready by validating runbooks, DEX documentation, operational procedures, support models and knowledge transfer materials., • International Enablement: Support and guide local IT teams during deployment, migration or transformation phases, ensuring consistent understanding of the target architecture., • Technical Committees: Participate in architecture boards, technical committees, steering committees and project governance forums., • Project Tracking: Contribute to technical planning, dependency tracking and delivery governance using tools such as Jira. Expected Deliverables The Network Architect will be expected to produce or contribute to: • Network architecture principles and standards., • High-level designs and target-state architecture documents., • Network reference architectures and reusable design patterns., • Architecture decision records., • Security and segmentation design principles., • WAN, SD-WAN, LAN, WLAN, data centre and cloud connectivity designs., • Routing and IP addressing standards., • Network diagrams and architecture views., • Operational-readiness checklists., • Transition-to-RUN validation inputs., • Technical risk assessments and mitigation recommendations., • Contributions to Jira tracking, technical committees and steering governance.