Sr Lead Architect - PUB SEC
Listed on 2026-03-13
-
IT/Tech
Systems Engineer, Cybersecurity
About Lumen
Lumen connects the world. We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and company from the people up – committed to teamwork, trust and transparency. People power progress.
We’re looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future.
The RoleThe Sr. Lead Architect specializing in Customer Network Architect is responsible for designing, implementing, and overseeing the end-to-end network architecture that supports a hybrid connectivity model — combining internet, private networking, and SD-WAN overlay — in a fully managed operations environment for both Managed Network and Managed Security Services. This role is pivotal in ensuring scalability, reliability, performance, and security requirements are accomplished across thousands of distributed customer endpoint locations.
This role demands a blend of deep technical expertise, strategic foresight, and strong communication skills. The Sr. Lead Architect is not only a designer but also a steward of operational excellence, ensuring that the network evolves in alignment with business needs and customer expectations.
The Main Responsibilities Daily Operational Tasks- Network Health Monitoring:
Oversee real-time monitoring of SD-WAN fabric, transport links, and edge devices using tools like Cisco vManage, Forti Manager, Solar Winds, ITSM, and Net Flow. - Incident Response & Troubleshooting:
Lead root cause analysis for complex network outages or performance degradation; coordinate with NOC and engineering teams. - Configuration Management:
Work with A&E and operations to validate and approve changes to configuration templates, policies, and routing configurations. - Customer Engagement:
Lead technical point of contact for technical interaction, escalations, providing insights and updates on network performance and incidents.
- Scalability Design:
Architect solutions to support growth from 4,000 to 5,000+ sites, ensuring bandwidth, redundancy, and policy scalability. - Technology Road mapping:
Partner with Solution Architecture and sales to evaluate emerging technologies (e.g., SASE, AI-driven analytics, 5G integration) and propose adoption strategies. - Network Architecture:
Design and engineer network services, application, and architecture in addition to network diagrams, modeling and solutions to meet the customer's needs. - Security Architecture:
Integrate secure edge capabilities, zero-trust principles, and segmentation strategies into the SD-WAN design. - Cloud Integration:
Design optimized paths to cloud services (Azure, AWS, GCP) using direct internet access and cloud on-ramp features. - Customer Assessment:
Assessment of network strengths, weaknesses and vulnerabilities. Capacity and traffic pattern analysis on current and projected traffic loads. Measured assessment of network performance and availability.
- Network Engineering:
Work closely with engineering teams to validate designs, test new features, and troubleshooting complex issues. - Dev Ops & Automation:
Partner with automation teams to streamline provisioning, monitoring, and compliance using APIs and other IT integration systems. - Security Teams:
Align with cybersecurity teams to enforce policy compliance, threat detection, and secure tunneling.
- Architecture Reviews:
Conduct regular design and performance reviews with customer stakeholders. - Change Advisory Board (CAB):
Participate in CAB meetings to assess impact and risk of proposed changes. - Training & Enablement:
Provide technical guidance and documentation to customer IT teams for operational awareness.
- Latency and jitter across diverse transport types (MPLS, MTIPS, broadband, LTE)
- Packet loss due to underlay instability or misconfigured QoS
- Policy conflicts in centralized vs. local breakout scenarios
- Template and policy scalability across thousands of devices
- WAN transport…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).