Reference code: JR132830
Richemont vereint einige der weltweit führenden Maisons für Luxusartikel mit besonderer Expertise in der Fertigung von Schmuck, exklusiven Uhren und Premium-Accessoires. Jedes Maison steht für eine eigene stolze Tradition des Stils, der Qualität und des Handwerks, und Richemont hat sich zur Aufgabe gemacht, das einzigartige Erbe und die Identität jedes einzelnen Maison zu bewahren. Gleichzeitig verpflichten wir uns in einem kontinuierlichen kreativen Schöpfungsprozess der Innovation sowie der Entwicklung neuer Produkte auf Grundlage der besonderen Werte unserer Maisons.
We are seeking a forward-thinking Connectivity SASE Architect to lead the design, strategy, and global evolution of Richemont’s Secure Access Service Edge (SASE) and cloud-security architecture. In this role, you will be the primary architect and subject matter expert for our secure connectivity platforms, driving the global transition to a robust, identity-centric Zero Trust Network Access (ZTNA) framework. You will play a pivotal role in ensuring secure, high-performance connectivity for our global workforce, leveraging advanced digital experience monitoring to optimize and secure user workflows. The ideal candidate combines deep technical expertise with a passion for cloud networking, automation, and modern security frameworks. Occasional international travel may be required.
KEY RESPONSIBILITIES
- Architect, design, and govern Richemont's global SASE roadmap, with a primary focus on enterprise cloud security platforms and cloud-native security services.
- Lead the design, configuration, and optimization of Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA) solutions to secure web traffic and private application access globally.
- Leverage Digital Experience Monitoring (DEM) capabilities to proactively monitor, analyze, and optimize end-user digital performance, isolating and troubleshooting connectivity and application latency issues.
- Design and align SASE strategies with hybrid and multi-cloud connectivity architectures leveraging AWS, GCP, and SD-WAN services.
- Define and implement granular, identity-aware security policies, cloud-firewall rules, and access controls across cloud and remote-work environments.
- Provide high-level architectural standards for office and branch connectivity, collaborating with local infrastructure teams who manage physical local area networks (LAN/WLAN).
- Automate secure network provisioning, policy updates, and deployments using Python, REST APIs, Ansible, or Terraform.
- Maintain comprehensive SASE architectural documentation, service definitions, reference designs, and security standards.
- Collaborate closely with Cybersecurity, Cloud, Identity (IAM), and Workplace engineering teams to ensure end-to-end integration.
REQUIRED SKILLS AND EXPERIENCE
- Extensive experience in network security architecture with a heavy focus on SASE, Zero Trust, and Cloud Security.
- Subject matter expertise in leading SASE platforms, preferably Zscaler (including ZIA, ZPA, and ZDX or equivalent industry-leading technologies):
- Secure Web Gateway / CASB: URL filtering, SSL inspection, DLP, Cloud Firewall, and Sandboxing.
- ZTNA: App connectors, private access policies, segment groups, and bypass configurations.
- Digital Experience Monitoring: Experience building dashboards, analyzing telemetry, and troubleshooting performance from user-to-app.
- Solid foundational knowledge of enterprise LAN/WLAN environments to ensure seamless integration and alignment between local office infrastructure and the global SASE platform.
- Strong understanding of cloud networking architectures within AWS and/or GCP.
- Familiarity with modern SD-WAN and secure-edge technologies (e.g., Cato Networks, Silver Peak, or similar).
- Solid understanding of foundational network and security protocols (TCP/IP, DNS, BGP, HTTP/S, SAML/OIDC for identity federation).
- Automation and scripting skills (Python, Terraform, or Ansible) for managing API-driven security policies.
QUALIFICATIONS
- Bachelor’s degree or equivalent professional experience.
- SASE/Cloud Security Certifications are highly preferred (e.g., Zscaler ZCCA/ZCCP, Cato SASE Expert, or equivalent vendor-neutral cloud security certifications).
- Cloud certifications (AWS Certified Advanced Networking, GCP Cloud Network Engineer) are a plus.
- Fluency in English.


