跳到主要内容
不同姿势的人物拼贴画
Richemont

CONNECTIVITY SASE ARCHITECT

  • Richemont
  • Technology
  • Moscavide, PT
立即申请

Reference code: JR132830

Richemont owns some of the world’s leading luxury goods Maisons, with particular strengths in jewellery, fine watches and premium accessories. Each Maison represents a proud tradition of style, quality and craftsmanship and Richemont seeks to preserve the heritage and identity of each of its Maisons. At the same time, we are committed to innovation and designing new products which are in keeping with our Maisons’ values, through a process of continuous creativity.

We are seeking a forward-thinking Connectivity SASE Architect to lead the design, strategy, and global evolution of Richemont’s Secure Access Service Edge (SASE) and cloud-security architecture. In this role, you will be the primary architect and subject matter expert for our secure connectivity platforms, driving the global transition to a robust, identity-centric Zero Trust Network Access (ZTNA) framework. You will play a pivotal role in ensuring secure, high-performance connectivity for our global workforce, leveraging advanced digital experience monitoring to optimize and secure user workflows. The ideal candidate combines deep technical expertise with a passion for cloud networking, automation, and modern security frameworks. Occasional international travel may be required.

KEY RESPONSIBILITIES

  • Architect, design, and govern Richemont's global SASE roadmap, with a primary focus on enterprise cloud security platforms and cloud-native security services.
  • Lead the design, configuration, and optimization of Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA) solutions to secure web traffic and private application access globally.
  • Leverage Digital Experience Monitoring (DEM) capabilities to proactively monitor, analyze, and optimize end-user digital performance, isolating and troubleshooting connectivity and application latency issues.
  • Design and align SASE strategies with hybrid and multi-cloud connectivity architectures leveraging AWS, GCP, and SD-WAN services.
  • Define and implement granular, identity-aware security policies, cloud-firewall rules, and access controls across cloud and remote-work environments.
  • Provide high-level architectural standards for office and branch connectivity, collaborating with local infrastructure teams who manage physical local area networks (LAN/WLAN).
  • Automate secure network provisioning, policy updates, and deployments using Python, REST APIs, Ansible, or Terraform.
  • Maintain comprehensive SASE architectural documentation, service definitions, reference designs, and security standards.
  • Collaborate closely with Cybersecurity, Cloud, Identity (IAM), and Workplace engineering teams to ensure end-to-end integration.

REQUIRED SKILLS AND EXPERIENCE

  • Extensive experience in network security architecture with a heavy focus on SASE, Zero Trust, and Cloud Security.
  • Subject matter expertise in leading SASE platforms, preferably Zscaler (including ZIA, ZPA, and ZDX or equivalent industry-leading technologies):
  • Secure Web Gateway / CASB: URL filtering, SSL inspection, DLP, Cloud Firewall, and Sandboxing.
  • ZTNA: App connectors, private access policies, segment groups, and bypass configurations.
  • Digital Experience Monitoring: Experience building dashboards, analyzing telemetry, and troubleshooting performance from user-to-app.
  • Solid foundational knowledge of enterprise LAN/WLAN environments to ensure seamless integration and alignment between local office infrastructure and the global SASE platform.
  • Strong understanding of cloud networking architectures within AWS and/or GCP.
  • Familiarity with modern SD-WAN and secure-edge technologies (e.g., Cato Networks, Silver Peak, or similar).
  • Solid understanding of foundational network and security protocols (TCP/IP, DNS, BGP, HTTP/S, SAML/OIDC for identity federation).
  • Automation and scripting skills (Python, Terraform, or Ansible) for managing API-driven security policies.

QUALIFICATIONS

  • Bachelor’s degree or equivalent professional experience.
  • SASE/Cloud Security Certifications are highly preferred (e.g., Zscaler ZCCA/ZCCP, Cato SASE Expert, or equivalent vendor-neutral cloud security certifications).
  • Cloud certifications (AWS Certified Advanced Networking, GCP Cloud Network Engineer) are a plus.
  • Fluency in English.

#Richemont #WeCraftTheFuture

一群人围坐在一张桌子旁

抱负与价值观

作为一家秉持家族精神的集团,我们的使命是通过培育员工独特的技艺、创新精神和创造力,共创未来。我们致力于为所有利益相关者——客户、同事、投资者、合作伙伴以及更广泛的社会——创造长期价值。

了解更多

All Maisons Logos Blue

Richemont is the owner of prestigious Maisons, recognised for their excellence in jewellery, watches, fashion and accessories. They are renowned for their distinctive heritage, craftsmanship and creativity.

Learn more about our prestigious Maisons