Skip to main content
IS3 logo

Senior Cisco Secure Workload Engineer / Architect

IS3
2 days ago
Remote
Web Development

The Senior Secure Workload Engineer will provide hands-on planning, implementation, operationalization, and knowledge transfer for an enterprise workload visibility and segmentation initiative. The consultant will establish a repeatable, application-aligned Cisco Secure Workload approach, support phased adoption, produce clear documentation, and work collaboratively with the customer team to build sustainable operational capability.

Responsibilities:

  • Define and execute a repeatable Cisco Secure Workload implementation roadmap using a controlled pilot and phased, application-aligned rollout.
  • Assess the existing Secure Workload deployment across a diverse enterprise environment and recommend practical next steps for broader adoption.
  • Map application components, dependencies, and traffic patterns to support workload visibility and segmentation decisions.
  • Plan and implement agent deployment across supported enterprise systems while identifying alternative visibility approaches where agents are not appropriate.
  • Develop segmentation policies and validate application communications before progressing through staged enforcement.
  • Coordinate with infrastructure, security, identity, network, and application stakeholders throughout planning and implementation.
  • Create implementation documentation, operational procedures, and a repeatable onboarding approach for future applications.
  • Work side by side with customer team members, emphasizing hands-on coaching and sustainable knowledge transfer. Qualifications:
  • Senior-level hands-on experience with Cisco Secure Workload or a comparable workload visibility and microsegmentation platform.
  • Experience planning application-based segmentation and mapping application dependencies and traffic patterns.
  • Experience implementing workload agents across Windows and Linux enterprise environments.
  • Understanding of enterprise networking, identity services, shared services, security policy, and application communication flows.
  • Experience developing, validating, and operationalizing segmentation policies in complex environments.
  • Ability to produce clear technical documentation and establish repeatable implementation and operating procedures.
  • Strong customer-facing communication, facilitation, collaboration, and hands-on knowledge-transfer skills. Tools and Technologies:
  • Cisco Secure Workload
  • Cisco Cloud Protection Suite
  • Workload visibility and micro segmentation
  • Windows and Linux operating systems
  • Enterprise networking, identity, and shared services
  • Application dependency and traffic-flow analysis Partner Information:
  • Please inform candidates that this is a contract role with your company and will be assigned to a third-party customer of World Wide Technology.
  • We're committed to pay transparency. We ask that when posting a role with WWT please include a clear salary or pay range to support fairness and informed decisions
  • Please ensure that all end-client information is removed from any job postings or candidate communications. Before sharing or posting a role externally, confirm with the Resource Management team to ensure alignment and approval. Why WWT?

World Wide Technology is looking for a Senior Secure Workload Engineer. This role is part of WWT's Strategic Resourcing services and is a contract role. The candidate will be supporting a WWT customer and will be employed by one of WWT's preferred partners. The partner will provide full compensation and benefit information prior to employment with the partner.

Want to work with highly motivated individuals on high-performance teams? Join WWT today!

Who we are https://www.wwt.com/corporate/who-we-are/overview

What will you be doing?

Position Overview:

The Senior Secure Workload Engineer will provide hands-on planning, implementation, operationalization, and knowledge transfer for an enterprise workload visibility and segmentation initiative. The consultant will establish a repeatable, application-aligned Cisco Secure Workload approach, support phased adoption, produce clear documentation, and work collaboratively with the customer team to build sustainable operational capability.

Responsibilities:

  • Define and execute a repeatable Cisco Secure Workload implementation roadmap using a controlled pilot and phased, application-aligned rollout.
  • Assess the existing Secure Workload deployment across a diverse enterprise environment and recommend practical next steps for broader adoption.
  • Map application components, dependencies, and traffic patterns to support workload visibility and segmentation decisions.
  • Plan and implement agent deployment across supported enterprise systems while identifying alternative visibility approaches where agents are not appropriate.
  • Develop segmentation policies and validate application communications before progressing through staged enforcement.
  • Coordinate with infrastructure, security, identity, network, and application stakeholders throughout planning and implementation.
  • Create implementation documentation, operational procedures, and a repeatable onboarding approach for future applications.
  • Work side by side with customer team members, emphasizing hands-on coaching and sustainable knowledge transfer. Qualifications:
  • Senior-level hands-on experience with Cisco Secure Workload or a comparable workload visibility and microsegmentation platform.
  • Experience planning application-based segmentation and mapping application dependencies and traffic patterns.
  • Experience implementing workload agents across Windows and Linux enterprise environments.
  • Understanding of enterprise networking, identity services, shared services, security policy, and application communication flows.
  • Experience developing, validating, and operationalizing segmentation policies in complex environments.
  • Ability to produce clear technical documentation and establish repeatable implementation and operating procedures.
  • Strong customer-facing communication, facilitation, collaboration, and hands-on knowledge-transfer skills. Tools and Technologies:
  • Cisco Secure Workload
  • Cisco Cloud Protection Suite
  • Workload visibility and micro segmentation
  • Windows and Linux operating systems
  • Enterprise networking, identity, and shared services
  • Application dependency and traffic-flow analysis

Responsibilities:

  • Global Network Strategy & Execution: Own the end-to-end lifecycle and 24/7 operational performance of enterprise WAN, SD-WAN, LAN, Wi-Fi, and GCP cloud networking environments.
  • Software-Defined & Intent-Based Networking: Drive the transition toward Intent-Based Networking (IBN) and artificial intelligence for IT operations (AIOps), translating business policies into declarative network state and automated closed-loop assurance.
  • GCP Cloud & SASE Architecture: Optimize resilient, low-latency connectivity between on-premises sites, factory-edge nodes, and GCP using Cloud Interconnect, Cloud Router, and Shared Virtual Private Clouds (VPCs), along with Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) frameworks.
  • Data Center Fabric Right-Sizing: Deliver modern Ethernet VPN and Virtual Extensible LAN (EVPN-VXLAN) leaf-spine data center fabrics; manage the compression and optimization of on-premises hardware footprints as workloads migrate into GCP.
  • Network Automation & IaC: Lead a Network as Code strategy, driving continuous integration and automated change management through Terraform, Ansible, Python, and GitOps workflows.
  • IT/OT Convergence & Manufacturing Integration: Partner with manufacturing and OT security teams to deploy, segment, and protect shop-floor networks using the Purdue Model, industrial firewalls, and plant-floor compute nodes.
  • Governance & Global Team Leadership: Direct and mentor a team of high-performing network engineers across regions. Establish operational standards, service level objectives (SLOs), service level agreements (SLAs), observability metrics, and seamless escalation paths with the Global Network Operations Center (NOC).
  • Carrier & Vendor Management: Manage commercial contracts, SLAs, and relationships with global internet service provider (ISP) carriers, telecom providers, colocation facilities, and hardware vendors.

Qualifications:

  • Bachelor's degree in Computer Science, Information Systems, Network Engineering, or a related field.
  • 5+ years of related experience in enterprise network engineering required.
  • Proven track record leading enterprise-wide SD-WAN transformations, such as Cisco, Fortinet, or Palo Alto Networks, and SASE/ZTNA deployments, such as Prisma.
  • Deep functional and technical knowledge of GCP cloud-native networking, including Shared VPCs, Cloud Interconnect, Cloud Router, and VPC Service Controls.
  • Demonstrated experience designing EVPN-VXLAN leaf-spine topologies, micro-segmentation, and right-sizing hybrid/on-premises data center networks during active cloud migrations.
  • Proficiency managing network infrastructure through automation pipelines using Infrastructure as Code (IaC) tools such as Terraform, Ansible, Python, and Git/GitOps.
  • Expert knowledge of core protocols including Border Gateway Protocol (BGP), Open Shortest Path First (OSPF), Multiprotocol BGP (MP-BGP), VXLAN overlays, and IPv4/IPv6 enterprise addressing schemes.
  • Excellent analytical, problem-solving, and communication skills, with the ability to synthesize complex network requirements into clear conceptual guidance for executive leadership.
  • Preferred: Master's degree in a relevant field.
  • Preferred: 10+ years of progressive experience in IT.
  • Preferred: 3+ years of experience in a technical leadership or engineering management role overseeing distributed global teams.
  • Preferred: Experience with industrial/manufacturing OT network security concepts and standards, including IEC 62443, industrial firewalls, and plant-floor LAN/Wi-Fi.
  • Preferred: Experience with Digital Experience Monitoring (DEM) and full-stack observability tools such as ThousandEyes, Dynatrace, or Wireshark.
  • Preferred: GCP Professional Cloud Network Engineer or Cisco Certified Internetwork Expert (CCIE) certification.
  • Preferred: Hands-on expertise with Cisco Enterprise Networking solutions, including Cisco Application Centric Infrastructure (ACI) and Cisco Catalyst Center, formerly DNA Center.
  • Preferred: Experience managing enterprise-grade Cisco Voice/Unified Communications (UC) architectures.
  • Preferred: Proficiency with Palo Alto Networks Next-Generation Firewalls (NGFW) and security management platforms.

Tools and Technologies:

  • Google Cloud Platform (GCP): Shared VPC, Cloud Interconnect, Cloud Router, VPC Service Controls
  • Networking: SD-WAN, SASE, ZTNA, IBN, AIOps, EVPN-VXLAN, leaf-spine, BGP, OSPF, MP-BGP, IPv4/IPv6
  • Automation and IaC: Terraform, Ansible, Python, Git, GitOps
  • Enterprise and Security: Cisco ACI, Cisco Catalyst Center, Cisco Voice/UC, Palo Alto Networks NGFW, Prisma
  • Observability: ThousandEyes, Dynatrace, Wireshark
  • OT/Manufacturing: Purdue Model, IEC 62443, industrial firewalls, plant-floor LAN/Wi-Fi