Technical Architect, Segmentation Orchestration Services
About Asimily
Asimily is the Proactive Cyber Asset Defense Platform empowering your teams to reduce risk as fast as possible across your entire cyber asset attack surface – IoT, OT, IoMT and IT.
Most security programs stall between knowing what’s at risk and doing something about it: policies are written but never deployed, segmentation is a priority but never fully implemented, and manual workflows can’t keep pace with dynamic networks. Asimily eliminates every one of those gaps.
Headquartered in Sunnyvale, California, Asimily is trusted globally by leading organizations across industries including healthcare, manufacturing, utilities, government, critical infrastructure, and enterprise organizations.
About You
Asimily is seeking a Technical Architect, Segmentation Services to provide hands-on technical leadership and operationalization support across multiple enterprise customer segmentation implementations. This role unifies deep enterprise routing, switching, and Network Access Control (NAC) design with Asimily’s proprietary device intelligence.
As the primary architectural authority, you will own the end-to-end technical lifecycle: discovery, network capability assessments, policy design, pre-production validation, deployment planning, and deep-dive troubleshooting for network based segmentation projects. You will collaborate closely with customer network and security architects, internal Services teams, and Engineering to translate complex IoT, IoMT, and OT intelligence into resilient, least-privilege segmentation policies that align with customer infrastructure, operational feasibility, and service scope.
Success is measured by the ability to independently evaluate complex enterprise networks, architect robust segmentation policies that avoid operational disruption, proactively identify hardware and policy constraints prior to production rollouts, and drive successful project milestones across concurrent customer engagements while cementing trusted technical partnerships.
Essential Responsibilities
Network Assessment & Technical Discovery
- Lead architectural discovery sessions with customer network and security teams to map routing topologies, switching fabrics, firewalls, and existing access controls.
- Audit switch platforms, OS/firmware versions, TCAM/memory capacity, and hardware-level ACL limits to identify enforcement bottlenecks and define feasible deployment options.
- Author comprehensive assessment deliverables outlining topology findings, technical constraints, deployment prerequisites, and recommended segmentation architectures.
NAC Architecture & Segmentation Policy Implementation
- Serve as the technical Subject Matter Expert (SME) across enterprise NAC solutions, including Cisco ISE, Extreme Site Engine, Forescout, and Aruba ClearPass.
- Ingest Asimily asset intelligence and packet-level flow data to profile legitimate communications and build context-aware, least-privilege policies using the Asimily Segmentation Orchestration.
- Design and refine downloadable ACLs (dACLs), dynamic VLAN assignment, and role-based access controls (e.g., Cisco TrustSec / SGTs) matched to client hardware capabilities.
- Partner with Asimily Engineering to address platform integration nuances and optimize policy-generation mechanisms.
Deployment Architecture, Governance & Remediation
- Lead technical sequencing, change-control reviews, pre-flight staging, and rollback strategies across parallel customer deployments.
- Coordinate scheduled deployment windows, oversee pre-/post-change validation, and support configuration changes on customer environments within contracted scope boundaries.
- Spearhead escalation-level root-cause analysis (RCA) for policy enforcement anomalies, dynamic authorization failures, and transient connectivity drops.
- Mentor Services engineers, driving knowledge transfer and establishing standardized implementation playbooks.
Traffic Analysis, Documentation & Cross-Functional Leadership
- Lead technical presentations with customer enterprise architects and security directors, clearly conveying technical findings, risks, and architectural trade-offs.
- Maintain accurate technical records, policy specifications, validation runs, exception registries, and runbooks.
- Collaborate across distributed customer engineering teams and internal cross-functional groups.
Required Qualifications
- 5–8+ years of hands-on enterprise networking, network security, or infrastructure engineering experience with a primary focus on access enforcement and segmentation.
- Production NAC Expertise: Substantial hands-on experience designing, deploying, and troubleshooting at least one enterprise NAC platform: Cisco ISE, Extreme Site Engine, Forescout, or Aruba ClearPass.
- Advanced Protocol Knowledge: Deep understanding of TCP/IP, switching, dynamic routing, VLAN architectures, subnetting, 802.1X, RADIUS, MAB, and CoA mechanics.
- Hardware Enforcement Literacy: Demonstrated capability to evaluate switch platform limitations, memory/TCAM capacity, and hardware ACL scalability.
- Packet-Level Diagnostics: Experience analyzing flow telemetry (NetFlow/sFlow), SPAN/mirror sessions, OR packet captures to isolate complex connectivity or enforcement issues.
- Implementation Ownership: Proven track record leading technical change windows, risk assessments, and rollback planning across complex enterprise environments.
- Communication & Documentation: Excellent stakeholder-facing communication, technical documentation, and cross-functional problem-solving skills.
Preferred Qualifications
- Certifications: CCNP, CCIE, or equivalent advanced enterprise networking/security credentials.
- Multi-Vendor Environments: Practical experience managing heterogeneous networks (e.g., mixed Cisco, Extreme, or Aruba environments).
- Identity-Based Segmentation: Experience deploying large-scale micro-segmentation, Cisco TrustSec (SGTs), or Zero Trust network architectures.
- Automation & Scripting: Hands-on exposure to Python, Ansible, or REST APIs for switch configuration validation and workflow automation.