NTT DATA
Principal Network Architect - Cisco SD-Access & Enterprise Networking
NTT DATA, Los Angeles, California, United States, 90079
Principal-Level Network Architect
Continue to make an impact with a company that is pushing the boundaries of what is possible. At NTT DATA, we are renowned for our technical excellence, leading innovations, and making a difference for our clients and society. Our workplace embraces diversity and inclusion it's a place where you can continue to grow, belong, and thrive. Your career here is about believing in yourself and seizing new opportunities and challenges. It's about expanding your skills and expertise in your current role and preparing yourself for future advancements. That's why we encourage you to take every opportunity to further your career within our great global team. Your Day At Ntt Data
We are hiring principal-level network architects to lead design and delivery of multi-site Cisco Software-Defined Access (SD-Access) solutions at scale. You will set architecture direction, drive complex deployments across distributed campuses, and mentor engineers while partnering closely with security and operations. The ideal candidate holds an active CCIE and demonstrates deep, hands-on expertise across Cisco routing/switching, Cisco Catalyst Center (formerly Cisco DNA Center), Cisco ISE, Cisco FTD firewalls, and Cisco SD-WAN, with expert-level command of BGP, EIGRP, OSPF, and related enterprise routing protocols. What You'll Do (Key Responsibilities)
Own end-to-end SD-Access architecture for large, multi-site enterprises: fabric design (control/edge/border), transit options, segmentation (SGTs/TrustSec), identity policy, and integration with WAN and data center. Lead Catalyst Centerdriven automation: design templates, SDA workflows, network assurance, SWIM, and closed-loop operations aligned to reliability/SLOs. Design identity-centric security with ISE: policy sets, authorization profiles, posture, PxGrid integrations, wired/wireless 802.1X/MAB, guest/BYOD, and scalable group policies. Engineer secure edge and campus perimeters: Cisco FTD/Firepower policy design, NAT, VPN, IDS/IPS, SSL decryption strategy, and high availability. Architect SD-WAN underlay/overlay: transport independence, application-aware routing, DIA/Cloud on-ramp, security integration, and multi-region scale. Expert routing at scale: BGP (policy, route reflectors, communities), OSPF, EIGRP, ECMP, redistribution strategies, route filtering, summarization, and IPv6 planning. Drive modernization roadmaps: brownfield to SDA migration, hierarchical campus design, QoS, multicast, wireless controller (Catalyst 9800) alignment, and resiliency patterns. Deliver hands-on build and escalation leadership: lab validation, pilot, phased rollout, cutover plans, MOPs, change windows, and root-cause analysis for P1/P2 incidents. Mentor and uplift engineering teams: design reviews, standards, runbooks, and enablement sessions for operations and field engineers. Stakeholder leadership: collaborate with security, EUC, cloud, and application teams; translate business outcomes into technical architectures and measurable milestones. Documentation & governance: HLD/LLD, as-builts, standards, security exceptions, and compliance artifacts; contribute to reference architectures and reusable templates. Required Qualifications (Must-Have)
Active CCIE (any track; Enterprise Infrastructure and/or Security strongly preferred). 10+ years enterprise networking experience, including 35+ years leading SD-Access architecture and deployment across multiple sites. Proven, exceptional hands-on skills with Cisco routing/switching and Catalyst Center (formerly Cisco DNA Center) for SDA automation and assurance. Deep expertise with Cisco ISE (policy, 802.1X, SGT/TrustSec) and Cisco FTD (Firepower) firewalls (threat, access control, NAT/VPN, high availability). Strong experience with Cisco SD-WAN (design, policy/templating, security integration, operationalization). Expert-level knowledge of BGP, EIGRP, OSPF, redistribution, and route-policy design for large enterprises. Demonstrated success leading complex, multi-phase migrations and mentoring senior engineers. Preferred Qualifications
CCDE or dual CCIE; Cisco Certified Specialist certifications in SDA, ISE, or SD-WAN. Automation fluency (Ansible, Python, Terraform), Git-based workflows, and API integration with Catalyst Center/ISE/FTD/SD-WAN. Wireless (Catalyst 9800/Prime/Catalyst Center Assurance), QoS strategy, multicast, NAC posture, and Zero Trust segmentation. Cloud networking (Azure/AWS), hybrid connectivity, and DNS/DHCP/IPAM integration. Familiarity with data center and campus interconnect (e.g., ACI concepts beneficial but not required). Work Style & Travel
Must reside in the immediate Los Angeles metro area and be able to work onsite at client site in Downtown LA. Off-hours change windows as needed for critical migrations. Employment Type: Full-Time Contract (with potential for permanent conversion based on performance and business needs) Applicants must be legally authorized to work in the United States at the time of application and must not require sponsorship for employment visa status now or in the future. Where required by law, NTT DATA provides a reasonable range of compensation for specific roles. The starting hourly range for this onsite role is $75.00 to $85.00/hourly. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on several factors, including the candidate's actual work location, relevant experience, technical skills, and other qualifications. This position is eligible for company benefits that will depend on the nature of the role offered. Company benefits may include medical, dental, and vision insurance, flexible spending or health savings account, life, and AD&D insurance, short-and long-term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally required benefits. Workplace type: On-site Working Equal Opportunity Employer NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, color, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Accelerate your career with us. Apply today
Continue to make an impact with a company that is pushing the boundaries of what is possible. At NTT DATA, we are renowned for our technical excellence, leading innovations, and making a difference for our clients and society. Our workplace embraces diversity and inclusion it's a place where you can continue to grow, belong, and thrive. Your career here is about believing in yourself and seizing new opportunities and challenges. It's about expanding your skills and expertise in your current role and preparing yourself for future advancements. That's why we encourage you to take every opportunity to further your career within our great global team. Your Day At Ntt Data
We are hiring principal-level network architects to lead design and delivery of multi-site Cisco Software-Defined Access (SD-Access) solutions at scale. You will set architecture direction, drive complex deployments across distributed campuses, and mentor engineers while partnering closely with security and operations. The ideal candidate holds an active CCIE and demonstrates deep, hands-on expertise across Cisco routing/switching, Cisco Catalyst Center (formerly Cisco DNA Center), Cisco ISE, Cisco FTD firewalls, and Cisco SD-WAN, with expert-level command of BGP, EIGRP, OSPF, and related enterprise routing protocols. What You'll Do (Key Responsibilities)
Own end-to-end SD-Access architecture for large, multi-site enterprises: fabric design (control/edge/border), transit options, segmentation (SGTs/TrustSec), identity policy, and integration with WAN and data center. Lead Catalyst Centerdriven automation: design templates, SDA workflows, network assurance, SWIM, and closed-loop operations aligned to reliability/SLOs. Design identity-centric security with ISE: policy sets, authorization profiles, posture, PxGrid integrations, wired/wireless 802.1X/MAB, guest/BYOD, and scalable group policies. Engineer secure edge and campus perimeters: Cisco FTD/Firepower policy design, NAT, VPN, IDS/IPS, SSL decryption strategy, and high availability. Architect SD-WAN underlay/overlay: transport independence, application-aware routing, DIA/Cloud on-ramp, security integration, and multi-region scale. Expert routing at scale: BGP (policy, route reflectors, communities), OSPF, EIGRP, ECMP, redistribution strategies, route filtering, summarization, and IPv6 planning. Drive modernization roadmaps: brownfield to SDA migration, hierarchical campus design, QoS, multicast, wireless controller (Catalyst 9800) alignment, and resiliency patterns. Deliver hands-on build and escalation leadership: lab validation, pilot, phased rollout, cutover plans, MOPs, change windows, and root-cause analysis for P1/P2 incidents. Mentor and uplift engineering teams: design reviews, standards, runbooks, and enablement sessions for operations and field engineers. Stakeholder leadership: collaborate with security, EUC, cloud, and application teams; translate business outcomes into technical architectures and measurable milestones. Documentation & governance: HLD/LLD, as-builts, standards, security exceptions, and compliance artifacts; contribute to reference architectures and reusable templates. Required Qualifications (Must-Have)
Active CCIE (any track; Enterprise Infrastructure and/or Security strongly preferred). 10+ years enterprise networking experience, including 35+ years leading SD-Access architecture and deployment across multiple sites. Proven, exceptional hands-on skills with Cisco routing/switching and Catalyst Center (formerly Cisco DNA Center) for SDA automation and assurance. Deep expertise with Cisco ISE (policy, 802.1X, SGT/TrustSec) and Cisco FTD (Firepower) firewalls (threat, access control, NAT/VPN, high availability). Strong experience with Cisco SD-WAN (design, policy/templating, security integration, operationalization). Expert-level knowledge of BGP, EIGRP, OSPF, redistribution, and route-policy design for large enterprises. Demonstrated success leading complex, multi-phase migrations and mentoring senior engineers. Preferred Qualifications
CCDE or dual CCIE; Cisco Certified Specialist certifications in SDA, ISE, or SD-WAN. Automation fluency (Ansible, Python, Terraform), Git-based workflows, and API integration with Catalyst Center/ISE/FTD/SD-WAN. Wireless (Catalyst 9800/Prime/Catalyst Center Assurance), QoS strategy, multicast, NAC posture, and Zero Trust segmentation. Cloud networking (Azure/AWS), hybrid connectivity, and DNS/DHCP/IPAM integration. Familiarity with data center and campus interconnect (e.g., ACI concepts beneficial but not required). Work Style & Travel
Must reside in the immediate Los Angeles metro area and be able to work onsite at client site in Downtown LA. Off-hours change windows as needed for critical migrations. Employment Type: Full-Time Contract (with potential for permanent conversion based on performance and business needs) Applicants must be legally authorized to work in the United States at the time of application and must not require sponsorship for employment visa status now or in the future. Where required by law, NTT DATA provides a reasonable range of compensation for specific roles. The starting hourly range for this onsite role is $75.00 to $85.00/hourly. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on several factors, including the candidate's actual work location, relevant experience, technical skills, and other qualifications. This position is eligible for company benefits that will depend on the nature of the role offered. Company benefits may include medical, dental, and vision insurance, flexible spending or health savings account, life, and AD&D insurance, short-and long-term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally required benefits. Workplace type: On-site Working Equal Opportunity Employer NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, color, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Accelerate your career with us. Apply today