Inception42
IT Manager- Network and Security Architect Department: Information Technology Reporting To: IT Senior Manager Location: Abu Dhabi - UAE Job Summary The IT Manager - Network and Security Architect is the senior technical authority for enterprise networking, secure access, and hybrid-cloud connectivity. The role owns architecture, standards, resilience, and lifecycle management across Aruba and Cisco enterprise networking, Palo Alto, Zscaler SASE, Azure networking, Internet connectivity, and structured cabling. It unifies campus, perimeter, cloud, and remote-access services into one secure architecture while providing hands-on escalation, network-security operations governance, technical leadership, project delivery, and vendor and contract management. Key Responsibilities Network Architecture & Reliability • Define secure, scalable target architecture and standards for LAN, WLAN, WAN, the Internet edge, hybrid cloud, routing, VPN, segmentation, high availability, and traffic flows. • Own roadmaps, capacity, resilience, design assurance, change governance, architecture diagrams, and technical standards. Aruba Network & Cabling • Design, configure, optimize, and lifecycle-manage Aruba switches, controllers or gateways, access points, and related platforms. • Set standards for copper and fiber cabling, racks, patching, labeling, testing, certification, and as-built documentation. Cisco Enterprise Networking • Architect and lifecycle-manage Cisco enterprise routing, switching, campus, WAN, and data-centre platforms, including Catalyst and Nexus, IOS XE/NX-OS, VLANs/VRFs, OSPF/BGP, QoS, high availability, secure management, telemetry, and software lifecycle. • Govern Catalyst Center, Cisco ISE/802.1X network access control, Catalyst SD-WAN, automation, and assurance where deployed; own configuration standards, Smart Licensing, TAC escalation, and interoperability with Aruba, Palo Alto, Zscaler, Azure, and carrier services. Perimeter Security, SASE & Zscaler • Architect and govern Palo Alto firewalls and Zscaler ZIA/ZPA as an integrated perimeter and SASE control plane, covering zones, policies, NAT, VPN, secure Internet and private-application access, logging, high availability, and rule lifecycle. • Define control boundaries and traffic flows across the enterprise border and edge, identity, endpoints, DNS, ISP services, and Azure; govern proxy forwarding, PAC file configuration, bypasses, inspection, resilience, segmentation, and secure change. Azure & Hybrid Networking • Design and govern Azure networking, including VNets, subnets, peering, Azure VPN Gateway, site-to-site and point-to-site VPNs, routing, UDRs, BGP, DNS, and proxy paths. • Define hybrid connectivity and network segregation across on-premises and Azure environments using security zones, NSGs, route controls, inspected egress, and resilient, auditable standards. Network Security Operations & Resilience • Define and govern the operating model for Cisco, Palo Alto, Aruba, Zscaler, Azure networking, VPN, Internet, proxy, and network segmentation. • Establish proactive monitoring for availability, security events, anomalous traffic, configuration drift, capacity, ISP resilience, and service performance. • Lead major network-security incidents with Cybersecurity and the SOC, covering investigation, containment, recovery, root-cause analysis, and permanent remediation. • Integrate Cisco, Aruba, firewall, Zscaler, Azure, VPN, DNS, proxy, and network telemetry with SIEM and monitoring platforms, including effective alerting and escalation. • Govern policies, access rules, secure configurations, vulnerabilities, updates, controlled changes, runbooks, and provider performance against SLAs. Vendors, Contracts & Delivery • Manage network, cloud, SASE, ISP, cabling, and support providers, including contracts, SLAs, renewals, licensing, warranties, performance, and escalations. • Lead network and security programmes, present architecture decisions and risks, and mentor engineers through standards and design reviews. Qualifications & Experience • Bachelor's degree in IT, Computer Science, Network Engineering, Cybersecurity, or a related field. • 10+ years of enterprise networking or network-security experience, including architecture and technical leadership responsibility. • Hands-on expertise in Aruba switching and wireless, Cisco Catalyst/Nexus routing and switching, and Palo Alto firewalls, including IOS XE/NX-OS, OSPF/BGP, VLAN/VRF, QoS, policy, NAT, VPN, high availability, logging, and secure management. • Expertise in Zscaler ZIA/ZPA, SASE and Zero Trust design, proxy forwarding, PAC files, exceptions, and policy governance. • Expertise in Azure VNets, peering, VPN Gateway, routing, UDRs/BGP, hybrid connectivity, proxy paths, and network segregation. • Deep knowledge of TCP/IP, routing, switching, VLAN/WLAN, DNS/DHCP, network access control, carrier services, SIEM integration, security operations, troubleshooting, vendors, contracts, and SLAs; experience with Cisco ISE/802.1X, Catalyst Center, or Catalyst SD-WAN is highly desirable. Professional Certifications Preferred certifications include: • Cisco CCNP Enterprise; CCDE or CCIE Enterprise Infrastructure is highly desirable • CCNP Security, CCIE Security, CCNP Wireless, CCIE Wireless, or a relevant Cisco Certified Specialist credential • Aruba, Palo Alto Networks, Zscaler, Azure Network Engineer Associate, CISSP/CISM, ITIL 4, or equivalent Skills & Competencies • Strong architecture judgement, hands-on engineering, incident leadership, and root-cause analysis capability. • Strategic leadership that translates business, risk, and regulatory requirements into pragmatic architectures and roadmaps. • Executive communication that clearly presents technical risks, options, and investment priorities. • Stakeholder influence and collaboration across cybersecurity, cloud, infrastructure, applications, procurement, finance, and external partners. • Coaching, mentoring, design review, and knowledge transfer across technical teams. • Negotiation, commercial awareness, prioritization, accountability, sound judgement, and delivery discipline. Key Performance Indicators (KPIs) • Availability, resilience, and performance of enterprise network and network-security services. • Critical-incident restoration time, recurrence reduction, and timely closure of root-cause actions. • Configuration compliance across Cisco, Palo Alto, Aruba, Zscaler, Azure, routing, VPN, proxy/PAC, network access control, and segmentation. • Timely remediation of vulnerabilities, configuration risks, audit findings, and overdue security changes. • Delivery of network and security initiatives to scope, schedule, budget, risk, quality, and documentation standards. • Vendor and carrier SLA performance, contract and licence renewals, service improvement, and cost optimization.
What does a IT Manager- Network and Security Architect earn in the UAE?
See the full Michael Page salary benchmark — ranges, skills, and career progression.
Security Architect
iConnect IT Business Solutions DMCCDubai, UAE
AED 42,000 – 70,000/mo
Senior Architect - DC Network Engineering
Core42Abu Dhabi, UAE
AED 28,000 – 42,000/mo
Sr. Staff Network Engineer
ZscalerRemote
AED 15,000 – 25,000/mo
Pre-Sales Solution Architect – Network & Security
Finstorm Placement Services
AED 15,000 – 15,000/mo