Role Description
The
Network Architect
is the technical design authority for Littelfuse's global enterprise network. This role defines secure, resilient and scalable architectures across manufacturing, R&D, distribution, corporate and cloud environments, then works with engineering, security, cloud and local IT teams to turn those designs into repeatable standards and successful implementations.
This is a hands-on architecture position rather than a purely advisory role. The successful candidate will combine strategic thinking with deep technical execution:
-
Creating high-level and low-level designs
-
Leading proofs of concept and design reviews
-
Validating configurations
-
Guiding migrations
-
Mentoring engineers
-
Serving as an escalation point for the most complex network and connectivity issues
About Your Job:
-
Create a globally consistent network architecture that improves security, resilience, cloud readiness, operational simplicity and business continuity while supporting the realities of manufacturing sites.
Key Responsibilities
-
Architecture, Strategy and Standards
-
Own and evolve global reference architectures for WAN, LAN, WLAN, internet edge, firewalls, remote access, cloud connectivity and network services.
-
Translate business, security and operational requirements into practical roadmaps, design principles, approved patterns and lifecycle standards.
-
Define the target architecture for SASE, SD-WAN, Zero Trust network access and secure branch connectivity, including coexistence and migration from legacy services.
-
Establish a standard site blueprint for manufacturing, R&D, distribution and corporate locations, including resilient connectivity tiers, segmentation patterns and technology selection criteria.
-
Act as design authority for major network changes, ensuring solutions are supportable, cost-effective, secure and aligned with the global strategy.
-
Cloud and Hybrid Connectivity
-
Design resilient Azure network architectures, including hub-and-spoke connectivity, routing domains, BGP policy, VPN/ExpressRoute integration, cloud firewalls, load-balancing dependencies and high availability across regions.
-
Identify and resolve routing asymmetry, overlapping path, failover and convergence risks across cloud hubs, branch connectivity and security enforcement points.
-
Define secure connectivity patterns between Azure, AWS, SaaS platforms, business partners, internet-facing services and the global enterprise network.
-
Partner with Cloud, Cybersecurity and Application teams to ensure network architecture supports availability, performance, observability and recovery requirements.
-
Network Security and Segmentation
-
Architect firewall, VPN and remote-access solutions using Palo Alto Networks technologies and related cloud-delivered security services.
-
Develop scalable IT/OT segmentation and zone-based security patterns for manufacturing environments in partnership with Cybersecurity and OT stakeholders.
-
Advance network access control and identity-based access using technologies such as Cisco ISE, 802.1X and complementary edge-security controls.
-
Ensure designs follow least-privilege, defense-in-depth and secure-by-design principles while remaining practical for local operations.
-
Campus, Branch and Wireless Architecture
-
Define and maintain standards for switching, routing and wireless solutions across a mixed Cisco and Meraki estate.
-
Design resilient branch connectivity using appropriate combinations of DIA, broadband, private connectivity, cellular/5G and satellite services based on site criticality and regional availability.
-
Guide wireless architecture and optimization, including RF design fundamentals, capacity, coverage, client steering, authentication and troubleshooting of complex user-experience issues.
-
Create repeatable deployment patterns for new sites, acquisitions, site expansions, technology refreshes and data-center exit activities.
-
Reliability, Performance and Operational Excellence
-
Set architecture requirements for availability, failover, monitoring, capacity and performance; validate that implemented solutions meet the intended design.
-
Improve observability using platforms such as SolarWinds, cloud-native telemetry, vendor portals, logs, flow data and APIs.
-
Lead technical root-cause analysis for major or recurring incidents and convert findings into durable architecture, configuration and process improvements.
-
Optimize application experience for collaboration, voice, video and other business-critical traffic through sound routing, QoS, path selection and security-service design.
-
Provide senior technical escalation support during high-impact incidents and planned migrations when architecture-level decisions are required.
-
Design Governance, Delivery and Technical Leadership
-
Produce clear high-level designs, low-level designs, diagrams, bills of material, decision records, standards, migration approaches, test plans and operational handover documentation.
-
Lead architecture reviews, technical workshops, proofs of concept and vendor evaluations; present recommendations, trade-offs, risks and investment needs to technical and business stakeholders.
-
Partner with Network Engineering, Cybersecurity, Cloud, Infrastructure, Enterprise Architecture, local IT and external service providers throughout the solution lifecycle.
-
Mentor engineers, improve troubleshooting discipline and raise the quality and consistency of network design and documentation across the team.
-
Support commercial and lifecycle decisions through technical due diligence, total-cost considerations, licensing analysis and vendor performance evaluation.
-
Remain hands-on enough to review configurations, validate routing and security behavior, test failover and assist with difficult implementation issues.
Qualifications
-
Bachelor's degree in Computer Science, Information Technology, Engineering or a related field, or equivalent relevant experience.
-
Typically 8+ years of progressive enterprise network engineering experience, including at least 3 years performing architecture, lead design or principal-level responsibilities.
-
Demonstrated experience designing networks for a global, multi-site enterprise; manufacturing or other business-critical operational environments are strongly valued.
-
Expert-level understanding of TCP/IP, IPv4/IPv6, BGP, OSPF, route redistribution and policy, QoS, NAT, VPN technologies, high availability, failure domains and asymmetric routing.
-
Strong hands-on experience with enterprise firewalls and secure remote access, preferably Palo Alto Networks and Prisma Access technologies.
-
Strong cloud-networking experience in Microsoft Azure, including hybrid connectivity, routing, security controls, load-balancing dependencies and multi-region resiliency.
-
Solid experience with enterprise routing, switching and wireless technologies; Cisco and/or Meraki experience is preferred.
-
Practical understanding of SASE, SD-WAN, Zero Trust, network segmentation, NAC and identity-aware access.
-
Ability to create high-quality architecture documentation and communicate complex technical decisions clearly to engineers, leaders and non-technical stakeholders.
-
Professional fluency in English and Spanish, both written and spoken, to support global collaboration and effective partnership with the Matamoros site.
-
Ability to participate in planned off-hours changes or critical-incident support when business needs require it.
Preferred Qualifications
-
Advanced certification such as CCNP Enterprise or CCIE; Palo Alto Networks PCNSE; or relevant Microsoft Azure networking/security certification.
-
Experience evaluating or implementing Cato Networks, Prisma SD-WAN, or a comparable enterprise SASE/SD-WAN platform.
-
Experience with Cisco ISE, 802.1X, IT/OT segmentation and security architecture in manufacturing environments.
-
Experience connecting Azure and AWS environments and designing secure inter-cloud or partner connectivity.
-
Network automation or infrastructure-as-code experience using Python, Ansible, Terraform, Git, APIs or similar tools.
-
Experience with Microsoft Teams network readiness, voice/video traffic engineering or unified communications.
-
Experience leading global migrations, data-center exits, acquisitions, site integrations or large-scale network refresh programs.
-
Experience running structured vendor selections, proofs of concept and technical/commercial comparisons.
Critical Competencies
-
Architecture with execution: Turns strategy into designs that can be built, tested, operated and supported.
-
Systems thinking: Understands end-to-end dependencies across cloud, security, applications, identity, carriers and physical sites.
-
Technical judgment: Makes clear decisions based on risk, reliability, complexity, cost and business impact.
-
Ownership: Drives ambiguous, cross-functional technical problems through to a documented and sustainable outcome.
-
Influence without authority: Builds alignment across engineering teams, security, cloud, site IT, vendors and leadership.
-
Communication: Explains complex network concepts in concise, decision-ready language for different audiences.
-
Continuous improvement: Simplifies the environment, removes technical debt and makes standards easier to adopt and operate.
What Success Looks Like
-
A clear and adopted target architecture exists for global WAN, cloud connectivity, security enforcement, campus networking and branch resilience.
-
Major network initiatives use consistent design standards, documented decisions, validated failover behavior and defined operational ownership.
-
Cloud and site connectivity become more resilient, observable and predictable, with fewer routing asymmetry and escalation-driven surprises.
-
Security segmentation and access controls improve without creating unnecessary operational complexity for manufacturing locations.
Benefits
-
Competitive compensation and benefits
-
Performance-based incentives
-
Flexible work arrangements
-
Development opportunities