Fidelity Investments Header

Principal Network Engineer

Westlake, TX
Full-Time

Job Description

Job Description:

Note: Fidelity is not providing immigration sponsorship for this position.

Job Title: Principal Network Engineer - Network Segmentation

Role Summary

We are seeking an experienced Network Engineer to support a data center network segmentation initiative focused on implementing micro segmentation and Zero Trust architecture. The role involves designing, deploying, and optimizing segmentation policies using Segmentation platforms. You will be part of the team that leads the strategic shift from traditional flat networks to highly secure, micro-segmented environments across on-premises data centers, global offices, and multi-cloud infrastructure.

You will work closely with security, infrastructure, and application teams to improve east-west traffic visibility, reduce attack surface, and enforce least-privilege communication.

Location

Westlake, Texas (Onsite)

Key Responsibilities

Design and Architecture

  • Design and implement network segmentation and micro segmentation strategies across data center environments
  • Develop Zero Trust network architectures aligned with enterprise security policies
  • Define segmentation models (application-centric, environment-based, etc.)

Implementation

  • Deploy and configure:
  • Segmentation Platforms across On-Prem and Cloud Data Centers
  • Create and enforce security policies for east-west traffic
  • Integrate segmentation tooling with:
  • Firewalls
  • SIEM/SOAR platforms
  • CMDB / asset inventory systems

Traffic Analysis and Policy Creation

  • Analyze application dependencies and traffic flows
  • Build and validate allow/deny rules and segmentation policies
  • Support policy simulation, testing, and enforcement phases

Operations and Optimization

  • Monitor segmentation effectiveness and tune policies
  • Troubleshoot connectivity issues related to segmentation enforcement
  • Ensure high availability and scalability of segmentation deployments

Collaboration

  • Partner with:
  • Application owners
  • Security teams
  • Infrastructure/Cloud teams
  • Drive workshops and onboarding sessions for segmentation adoption

Qualifications and Skills

  • 7 - 10 plus years of experience in:
  • Network engineering
  • Data center networking
  • Prior experience in large-scale segmentation or migration projects
  • Hands-on experience with Segmentation platforms (Illumio, Guardicore (Akamai), Cisco Secure Workload/Tetration)
  • Strong understanding of:
  • Networking: Cisco, HP, Arista, Palo Alto, Check Point, Juniper
  • TCP/IP, routing, switching
  • Firewalls and ACLs
  • Network security principles
  • Experience with:
  • Application dependency mapping
  • East-west traffic inspection
  • Experience with Enterprise Security:
  • Strong understanding of Zero-Trust Network Access (ZTNA), Secure Access Service Edge (SASE) architectures, and stateful firewalling.
  • Experience with:
  • Cloud platforms (AWS, Azure, GCP)
  • Kubernetes / container networking
  • Scripting/automation skills:
  • Python, PowerShell, or APIs
  • Experience CMDB Tools and Technologies (ServiceNow)
  • Familiarity with Linux and Windows server environments
  • Experience working in financial services or highly regulated environments

Certifications:

Category:

Information Technology

Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.

PDN-a216b243-3757-4431-bf24-37d5e81d071d

Job Description:

Note: Fidelity is not providing immigration sponsorship for this position.

Job Title: Principal Network Engineer - Network Segmentation

Role Summary

We are seeking an experienced Network Engineer to support a data center network segmentation initiative focused on implementing micro segmentation and Zero Trust architecture. The role involves designing, deploying, and optimizing segmentation policies using Segmentation platforms. You will be part of the team that leads the strategic shift from traditional flat networks to highly secure, micro-segmented environments across on-premises data centers, global offices, and multi-cloud infrastructure.

You will work closely with security, infrastructure, and application teams to improve east-west traffic visibility, reduce attack surface, and enforce least-privilege communication.

Location

Westlake, Texas (Onsite)

Key Responsibilities

Design and Architecture

  • Design and implement network segmentation and micro segmentation strategies across data center environments
  • Develop Zero Trust network architectures aligned with enterprise security policies
  • Define segmentation models (application-centric, environment-based, etc.)

Implementation

  • Deploy and configure:
  • Segmentation Platforms across On-Prem and Cloud Data Centers
  • Create and enforce security policies for east-west traffic
  • Integrate segmentation tooling with:
  • Firewalls
  • SIEM/SOAR platforms
  • CMDB / asset inventory systems

Traffic Analysis and Policy Creation

  • Analyze application dependencies and traffic flows
  • Build and validate allow/deny rules and segmentation policies
  • Support policy simulation, testing, and enforcement phases

Operations and Optimization

  • Monitor segmentation effectiveness and tune policies
  • Troubleshoot connectivity issues related to segmentation enforcement
  • Ensure high availability and scalability of segmentation deployments

Collaboration

  • Partner with:
  • Application owners
  • Security teams
  • Infrastructure/Cloud teams
  • Drive workshops and onboarding sessions for segmentation adoption

Qualifications and Skills

  • 7 - 10 plus years of experience in:
  • Network engineering
  • Data center networking
  • Prior experience in large-scale segmentation or migration projects
  • Hands-on experience with Segmentation platforms (Illumio, Guardicore (Akamai), Cisco Secure Workload/Tetration)
  • Strong understanding of:
  • Networking: Cisco, HP, Arista, Palo Alto, Check Point, Juniper
  • TCP/IP, routing, switching
  • Firewalls and ACLs
  • Network security principles
  • Experience with:
  • Application dependency mapping
  • East-west traffic inspection
  • Experience with Enterprise Security:
  • Strong understanding of Zero-Trust Network Access (ZTNA), Secure Access Service Edge (SASE) architectures, and stateful firewalling.
  • Experience with:
  • Cloud platforms (AWS, Azure, GCP)
  • Kubernetes / container networking
  • Scripting/automation skills:
  • Python, PowerShell, or APIs
  • Experience CMDB Tools and Technologies (ServiceNow)
  • Familiarity with Linux and Windows server environments
  • Experience working in financial services or highly regulated environments

Certifications:

Category:

Information Technology

Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.

PDN-a216b243-3757-4431-bf24-37d5e81d071d

About Fidelity Investments

At Fidelity, since our founding in 1946, we have been dedicated to strengthening and security our clients’ financial well-being through exceptional service and innovative solutions. We empower over ~50 million people to achieve their most important financial goals, manage employee benefit programs for nearly 24,000 businesses, and support more than 16,000 wealth management firms and institutions with cutting-edge investments and technology. Our diverse business portfolio and independence provide us with a comprehensive view of the market and the stability to deliver long-term value for our customers. As the financial industry evolves and customer needs grow more complex, Fidelity continues to reinvent, innovate, and transform to meet the challenges of tomorrow’s financial landscape.
 

*Specifically serviced by our Clearing & Custody team within Fidelity Institutional

 

Fidelity TalentSource, is the in-house temporary staffing provider for Fidelity Investments. Unlike traditional staffing agencies, we are an internal business unit within Fidelity’s Talent Acquisition team, dedicated to recruiting talent from various backgrounds for roles in Fidelity’s regional and investor center locations. Our mission is to help you experience Fidelity’s diverse and inclusive workplace while expanding your skill set and professional network, with the ultimate goal of conversion to full-time employment as part of Fidelity’s long-term strategy. To learn more about temporary positions at Fidelity Investments, visit FidelityTalentSource.com.

Related Jobs

Continue to Apply

Fidelity Investments would like you to finish the application on their website.

Apply For This Job
Fidelity Investments
Principal Network Engineer
Fidelity Investments
Westlake, TX
Jun 23, 2026
Full-time
Your Information
First Name *
Last Name *
Email Address *
This email belongs to another account. Please use a diferent email address or Sign In.
Zip Code *
Password *
Confirm Password *
Create your Profile from your Resume
By clicking the Apply button, you agree to the terms of use and privacy policy and consent to receive emails from us about job opportunities, career resources, and other relevant updates. You can unsubscribe at any time.
Continue to Apply

Fidelity Investments would like you to finish the application on their website.

©2026 IT Diversity Careers.
Powered by TalentAlly.