

Kforce Inc
Principle Technical Architect
β - Featured Role | Apply direct with Data Freelance Hub
This role is for a Principal Technical Architect in Plano, TX, with a contract length of "unknown" and a pay rate of "unknown." Key skills include CCIE certification, 10+ years in enterprise networking, and expertise in Cisco SD WAN and ISE.
π - Country
United States
π± - Currency
$ USD
-
π° - Day rate
880
-
ποΈ - Date
November 14, 2025
π - Duration
Unknown
-
ποΈ - Location
On-site
-
π - Contract
Unknown
-
π - Security
Unknown
-
π - Location detailed
Plano, TX
-
π§ - Skills detailed
#Strategy #Security #Azure #Firewalls #Redis #Alation #Leadership #Cloud #Ansible #Deployment #Terraform #Migration #Automation #AI (Artificial Intelligence) #Python #API (Application Programming Interface) #GIT #VPN (Virtual Private Network) #AWS (Amazon Web Services) #Scala
Role description
Responsibilities
Kforce has a client that is seeking a Principle Technical Architect in Plano, TX. In this role, you will set architecture direction, drive complex deployments across distributed campuses, and mentor engineers while partnering closely with security and operations. Duties/Day to Day Overview:
β’ Own end to end SD Access architecture for large, multi-site enterprises: fabric design (control/edge/border), transit options, segmentation (SGTs/TrustSec), identity policy, and integration with WAN and data center
β’ Lead Catalyst Center-driven automation: design templates, SDA workflows, network assurance, SWIM, and closed loop operations aligned to reliability/SLOs
β’ Design identity centric security with ISE: policy sets, authorization profiles, posture, PxGrid integrations, wired/wireless 802.1X/MAB, guest/BYOD, and scalable group policies
β’ Engineer secure edge and campus perimeters: Cisco FTD/Firepower policy design, NAT, VPN, IDS/IPS, SSL decryption strategy, and high availability
β’ Architect SD WAN underlay/overlay: transport independence, application aware routing, DIA/Cloud on ramp, security integration, and multi region scale
β’ Expert routing at scale: BGP (policy, route reflectors, communities), OSPF, EIGRP, ECMP, redistribution strategies, route filtering, summarization, and IPv6 planning
β’ Drive modernization roadmaps: brownfield to SDA migration, hierarchical campus design, QoS, multicast, wireless controller (Catalyst 9800) alignment, and resiliency patterns
β’ Deliver hands on build and escalation leadership: lab validation, pilot, phased rollout, cutover plans, MOPs, change windows, and root cause analysis for P1/P2 incidents
β’ Mentor and uplift engineering teams: design reviews, standards, runbooks, and enablement sessions for operations and field engineers
Requirements
β’ Active CCIE (any track; Enterprise Infrastructure and/or Security strongly preferred)
β’ 10+ years enterprise networking experience, including 3-5+ years leading SD Access architecture and deployment across multiple sites
β’ Strong experience with Cisco SD WAN (design, policy/templating, security integration, operationalization)
β’ Proven, exceptional hands-on skills with Cisco routing/switching and Catalyst Center (formerly Cisco DNA Center) for SDA automation and assurance
β’ Deep expertise with Cisco ISE (policy, 802.1X, SGT/TrustSec) and Cisco FTD (Firepower) firewalls (threat, access control, NAT/VPN, high availability)
β’ Expert level knowledge of BGP, EIGRP, OSPF, redistribution, and route policy design for large enterprises
β’ Demonstrated success leading complex, multi-phase migrations and mentoring senior engineers
Preferred Qualifications
β’ CCDE or dual CCIE; Cisco Certified Specialist certifications in SDA, ISE, or SD WAN
β’ Automation fluency (Ansible, Python, Terraform), Git based workflows, and API integration with Catalyst Center/ISE/FTD/SD WAN
β’ Wireless (Catalyst 9800/Prime/Catalyst Center Assurance), QoS strategy, multicast, NAC posture, and Zero Trust segmentation
β’ Cloud networking (Azure/AWS), hybrid connectivity, and DNS/DHCP/IPAM integration
β’ Familiarity with data center and campus interconnect (e.g., ACI concepts beneficial but not required)
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking βApply Todayβ you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.
Responsibilities
Kforce has a client that is seeking a Principle Technical Architect in Plano, TX. In this role, you will set architecture direction, drive complex deployments across distributed campuses, and mentor engineers while partnering closely with security and operations. Duties/Day to Day Overview:
β’ Own end to end SD Access architecture for large, multi-site enterprises: fabric design (control/edge/border), transit options, segmentation (SGTs/TrustSec), identity policy, and integration with WAN and data center
β’ Lead Catalyst Center-driven automation: design templates, SDA workflows, network assurance, SWIM, and closed loop operations aligned to reliability/SLOs
β’ Design identity centric security with ISE: policy sets, authorization profiles, posture, PxGrid integrations, wired/wireless 802.1X/MAB, guest/BYOD, and scalable group policies
β’ Engineer secure edge and campus perimeters: Cisco FTD/Firepower policy design, NAT, VPN, IDS/IPS, SSL decryption strategy, and high availability
β’ Architect SD WAN underlay/overlay: transport independence, application aware routing, DIA/Cloud on ramp, security integration, and multi region scale
β’ Expert routing at scale: BGP (policy, route reflectors, communities), OSPF, EIGRP, ECMP, redistribution strategies, route filtering, summarization, and IPv6 planning
β’ Drive modernization roadmaps: brownfield to SDA migration, hierarchical campus design, QoS, multicast, wireless controller (Catalyst 9800) alignment, and resiliency patterns
β’ Deliver hands on build and escalation leadership: lab validation, pilot, phased rollout, cutover plans, MOPs, change windows, and root cause analysis for P1/P2 incidents
β’ Mentor and uplift engineering teams: design reviews, standards, runbooks, and enablement sessions for operations and field engineers
Requirements
β’ Active CCIE (any track; Enterprise Infrastructure and/or Security strongly preferred)
β’ 10+ years enterprise networking experience, including 3-5+ years leading SD Access architecture and deployment across multiple sites
β’ Strong experience with Cisco SD WAN (design, policy/templating, security integration, operationalization)
β’ Proven, exceptional hands-on skills with Cisco routing/switching and Catalyst Center (formerly Cisco DNA Center) for SDA automation and assurance
β’ Deep expertise with Cisco ISE (policy, 802.1X, SGT/TrustSec) and Cisco FTD (Firepower) firewalls (threat, access control, NAT/VPN, high availability)
β’ Expert level knowledge of BGP, EIGRP, OSPF, redistribution, and route policy design for large enterprises
β’ Demonstrated success leading complex, multi-phase migrations and mentoring senior engineers
Preferred Qualifications
β’ CCDE or dual CCIE; Cisco Certified Specialist certifications in SDA, ISE, or SD WAN
β’ Automation fluency (Ansible, Python, Terraform), Git based workflows, and API integration with Catalyst Center/ISE/FTD/SD WAN
β’ Wireless (Catalyst 9800/Prime/Catalyst Center Assurance), QoS strategy, multicast, NAC posture, and Zero Trust segmentation
β’ Cloud networking (Azure/AWS), hybrid connectivity, and DNS/DHCP/IPAM integration
β’ Familiarity with data center and campus interconnect (e.g., ACI concepts beneficial but not required)
The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.
We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.
Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce's sole discretion unless and until paid and may be modified in its discretion consistent with the law.
This job is not eligible for bonuses, incentives or commissions.
Kforce is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
By clicking βApply Todayβ you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.






