About this opportunity
Fidelity Investments Inc. lists this Principal Network Engineer – Network Segmentation - Akamai Guardicore, Illumio, Cisco Secure Workload opportunity in durham, North Carolina. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Fidelity will not provide immigration sponsorship for this position.
Job Description:
The Role
Fidelity Investments is seeking a Principal Network Engineer to help lead the implementation of network segmentation and Zero Trust architectures across our enterprise infrastructure. This role focuses on designing, deploying, and optimizing micro‑segmentation solutions that enhance security, improve visibility into network traffic, and reduce cybersecurity risk. Responsibilities include analyzing application traffic patterns, developing and enforcing segmentation policies, and supporting secure communication across data center and cloud environments. By modernizing network security controls, this role plays a critical part in protecting Fidelity’s technology ecosystem and business operations.
The Expertise and Skills You Bring
7+ years of experience in network engineering and data center networking
Hands‑on experience with network segmentation platforms such as Illumio, Akamai Guardicore, or Cisco Secure Workload
Experience leading or supporting large‑scale network segmentation, security transformation, or migration initiatives
Strong knowledge of TCP/IP networking, routing, switching, firewalls, access control policies, and network security principles
Experience analyzing application dependencies, network traffic flows, and east‑west communication patterns to develop segmentation policies
Knowledge of Zero Trust architecture, Zero Trust Network Access (ZTNA), Secure Access Service Edge (SASE), and enterprise security frameworks
Experience implementing network security solutions across on‑premises and cloud environments, including AWS, Azure, or Google Cloud Platform
Ability to troubleshoot network connectivity and security policy issues in complex enterprise environments
Experience integrating network security technologies with security monitoring, asset inventory, or configuration management platforms such as ServiceNow
Scripting or automation experience using Python, PowerShell, or APIs preferred
Experience with Kubernetes, container networking, Linux, and Windows server environments preferred
Experience working within financial services or other highly regulated industries preferred
The Team
The Network Segmentation team is part of Fidelity’s Enterprise Infrastructure and Cybersecurity organization, focused on strengthening the security of the firm’s global technology environment. We partner closely with application development teams, cybersecurity professionals, cloud engineers, and infrastructure teams to design and implement secure communication frameworks across data centers, offices, and cloud platforms. Our work enables the adoption of Zero Trust security principles while helping the business innovate safely and efficiently. Fidelity is committed to protecting client information, advancing technology innovation, and investing in our greatest asset: our people.
Fidelity’s Onsite Working Model
Fidelity is transitioning to a full‑time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.
Certifications:
Category:
Information Technology
Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement‑related financial activities and the rules and regulations of numerous self‑regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.
#J-18808-Ljbffr
Worksite address
durham, NC, 27703, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.