Principal Cybersecurity Architect - Lab & Customer Infrastructure
EXOSJob Description
Role Summary
Our client's Information Security group is looking for a Security Architect to design and govern security across our customer-facing lab environments - the infrastructure we provision for customers to connect into, test configurations, stage equipment, and prepare for datacenter deployments. This is a hands-on architecture role at the intersection of network security, infrastructure engineering, and customer-facing operations.
Context
Our lab environments serve multiple simultaneous customers, each connecting into dedicated segments to test infrastructure configurations, evaluate solutions, or stage physical and virtual equipment before it ships to their datacenters. This creates a unique security challenge: strict multi-tenant isolation, controlled external access, supply chain integrity for outbound hardware, and a constantly shifting topology as customer environments are provisioned and decommissioned.
Responsibilities
Multi-Tenant Environment Security & Isolation
- Design and enforce security segmentation between customer lab environments - ensuring no customer can reach another's segment through any path, intentional or accidental
- Define the network security architecture for the lab: VLANs, micro-segmentation, firewall zoning, and inter-VLAN routing controls - with a zero-trust posture between tenant segments
- Develop and maintain a customer environment provisioning security standard - covering how new lab environments are stood up, validated for isolation, and decommissioned cleanly without data or configuration remnants
- Lead regular isolation validation exercises: penetration testing of tenant boundaries, traffic analysis, and configuration audits
- Customer Connectivity & External Access
- Architect secure connectivity options for customers accessing lab environments remotely: ZTNA, IPSec/SSL VPN, MPLS/dedicated circuit - selecting appropriate models based on customer security requirements and sensitivity of the work
- Define onboarding standards for external parties: identity verification, access scoping, MFA requirements, and time-limited access windows
- Design and operate a secure remote access gateway that logs all customer sessions, enforces least-privilege network access, and integrates with the broader security monitoring stack