· 1) Architecture & Design
· Lead the design of secure network architectures (campus, branch, data center, OT/ICS, and cloud edge).
· Define Zero Trust segmentation, SASE/SSE patterns, ZTNA, and micro‑segmentation (host- and network-based).
· Produce HLD/LLD, security design patterns, policy matrices, and traffic flow diagrams.
· Integrate security with cloud networking (Azure vWAN/VNet, AWS VPC, GCP VPC), private connectivity (ExpressRoute/Direct Connect), and edge.
· 2) Implementation & Migration
· Deploy and tune NGFW, IDS/IPS, WAF, SWG/CASB, SSE, DLP, email security, VPN/SD‑WAN, and NAC.
· Implement SIEM/SOAR integrations, syslog/NetFlow, EDR/XDR signal sharing, and playbooks for automated response.
· Execute phased migrations and cutovers with rollback plans and customer communication.
· 3) Security Operations & Hardening
· Build/optimize security monitoring use cases (MITRE ATT&CK mapping, UEBA, threat intel).
· Harden network/security platforms (CIS benchmarks, secure baselines, PKI/TLS, SSH, least privilege, password vaulting).
· Lead/assist incident response: triage, containment, forensics coordination, lessons learned.
· 4) Governance, Risk & Compliance
· Align designs with NIST CSF, ISO/IEC 27001, CIS Controls, and applicable regulations.
· Define security policies/standards, data classification enforcement at network boundaries, and change control.
· Produce compliance artifacts: risk registers, control matrices, test evidence, and audit responses.
· 5) Advisory & Stakeholder Management
· Act as trusted advisor to CISO, Network, Cloud, Infrastructure, and App teams.
· Run assessments (maturity, gap, architecture), TCO/ROI, and cost optimization for security tooling.
· Deliver workshops, knowledge transfer, and clear documentation.
· 6) Mentoring & Practice Development
· Mentor consultants/engineers, review designs, and contribute reference architectures, runbooks, and reusable templates.
· Support pre‑sales: discovery, scoping, level of effort, and solution proposals.