Network Infrastructure Cloud Architect
Ropes & Gray is a preeminent global law firm with approximately 2,500 lawyers and professionals serving clients in major centers of business, finance, technology, and government. The firm has consistently been recognized for its leading practices in asset management, private equity, M&A, finance, real estate, tax, antitrust, life sciences, health care, intellectual property, litigation & enforcement, privacy & cybersecurity, and business restructuring.
About the role
The Network Infrastructure Cloud Architect is a senior-level role in the IT Department responsible for supporting the design and architecture of the firm's data, wireless, video, and VOIP networks, as well as cloud and IaaS-based network connectivity, with a primary focus on Microsoft Azure and familiarity with other major cloud platforms (AWS, GCP). This role encompasses three key areas of focus: physical and cloud-based designs, logical/secure designs, and monitoring/measuring to validate digital experience and business value across hybrid and multi-cloud deployments. The architect will recommend emerging cloud and networking technologies, collaborate across IT teams, and provide technical guidance from cloud migration strategy to project planning.
Responsibilities
- Contribute to the strategic design and architecture of the firm's data network environment, including hybrid cloud connectivity and Azure virtual networking (VNets, ExpressRoute, Azure Virtual WAN).
- Design, deploy, and maintain network systems and components such as routers, switches, internet services, WAN services, wireless networks, VPNs, firewalls, video and VoIP infrastructure, security, cloud network gateways, and performance management systems.
- Design and manage cloud network architectures in Azure, including hub-and-spoke topologies, network security groups, Azure Firewall, Private Link, and DNS integration, with awareness of equivalent services in AWS and GCP.
- Participate in physical build planning and design for new spaces, as well as cloud landing zone design and implementation.
- Scope, recommend, design, plan, oversee, and test inter-rack and station cabling for office, MDF, IDF, and datacenter builds and refreshes, alongside cloud infrastructure provisioning using infrastructure as code tools such as Terraform or Azure Resource Manager templates.
- Configure on-premises and cloud-based networks to ensure smooth and reliable operation for business objectives.
- Evaluate emerging cloud and networking technologies (e.g., Azure-native services, SD-WAN, SASE, zero trust architectures) and recommend hardware/software enhancements.
- Recommend performance standards, processes, policies, and procedures for on-premises and cloud network environments.
- Provide senior-level technical support for network elements, systems, and cloud networking services.
- Design and monitor network performance across on-premises and cloud environments using tools such as Azure Monitor, Azure Network Watcher, and third-party observability platforms; troubleshoot problem areas.
- Collaborate with executive management and department leaders to assess near and long-term network capacity needs, including cloud resource planning and cost optimization.
- Create and maintain documentation for network architecture, configuration, cloud network topology diagrams, runbooks, and infrastructure as code repositories.
- Ensure knowledge transfer for new systems, including cloud-based services and hybrid connectivity solutions.
- Coordinate business continuity and disaster recovery programs, including cloud-based disaster recovery, geo-redundancy planning, and Azure Site Recovery configurations.
- Perform other work-related duties as assigned.
Requirements
- Bachelor's Degree or equivalent experience.
- 7+ years of experience in the network field.
- Proven experience with planning, installing, and managing networks including LAN, MAN, WAN, Optical Networking, Silverpeak SDWAN Optimizers, F5 Load Balancers, iRules, F5 Global Traffic Manager, Infoblox/BloxOne, Illumio, Checkpoint firewalls, Checkpoint Identity Collector, VPN, DMZ, IDS/IPS, Zscaler Web Proxy, content filter, NAC, Cisco ISE, Ciena DWDM, 100 Gig optics, DNS Traffic Control, Cisco ACI & NXOS, SDN, network segmentation, Cisco Catalyst center, Cisco CLI, ACL management, SNMP MIBs, Aruba wireless controllers and APs, SSL certificate management, DNS domain registration, Citrix Netscaler, VMware NSX, network taps, and Extrahop.
- Experience with Azure networking solutions including Virtual Network Peering, VPN Gateway, and ExpressRoute to support SaaS and cloud-based initiatives.
- Familiarity with Infrastructure as Code (IaC) tools such as Ansible, Terraform, Azure Resource Manager, or Chef.
- Familiarity with EntraID, Active Directory, LDAP, PKI, SAML, OAUTH, and SSO.
- Experience with network monitoring and tools (e.g., OpenView, Spectrum, NetScout, Gigamon, APCON, NetMRI, MRTG, CACTI, Solarwinds, SmokePing, NetFlow, Tufin, Splunk, syslog).
- Proven experience with network capacity planning, security principles, and general network management best practices.
- Strong hands-on knowledge of LAN/WAN/MAN protocols and technologies including Carrier Ethernet, T1, DS3, optical, DWDM, NTP, Spanning Tree, VLANs, 802.1q, VFR, LFA, SNMP v1-v3, OSPF, BGP, MPLS, VPLS, SIP, H.323, QoS, Multicast, Anycast, 802.1x, Radius, TACACS+, SSH, NAC, DHCP, DNS, F5 Wide-IP, VRRP, HSRP, GLBP, PBR, VPC, LACP, SGT, SGACL, SXP, VxLAN, OTP, LISP, SPAN, WCCP, PfR, IPSLA, iWAN, VPN, IPSec, WiFi 6, 6E, 7.
- Strong working knowledge of Cisco routers and switches (Nexus 9K, 7K, 5K, 2K, 1K; Catalyst 9410, 9300; ISR-4451, 8300).
- Experience with fiberoptic cabling, patching, cleaning, and troubleshooting.
- Strong hands-on knowledge of DNS record creation (A, CNAME, TXT, SRV, NS, PTR) and DNS SPF, DMARC, DKIM records.
- Experience with racking and patching appliances and servers, rack power management, and monitoring managed PDUs.
- Experience with console servers for out-of-band serial access.
- Experience with DevOps, automating, and scripting.
- Experience with data center, server room, and IDF design; station cabling layout design and implementation; UPS management and monitoring; and environmental monitoring systems.
Skills
- Ability to maintain strict confidentiality of the firm's internal and personnel affairs.
- Ability to influence at all levels of the organization.
- Self-starter who understands details within a larger context.
- Teamwork and collaborative skills.
- Creativity and flexibility to respond to shifting demands and opportunities; ability to work under tight deadlines and handle multiple tasks.
- Team-oriented with the ability to share information, goals, opportunities, successes, and failures.
- Strong organizational, planning, and project management skills.
- Attention to detail and follow-through.
- Ability to work effectively in a multi-office environment.
- Strong verbal, interpersonal, analytical, problem-solving, customer service, team, leadership, and project management skills.
Preferred Qualifications
- Certifications: CCNA, CCNP, CCDE, CCDA, CCSP.
Pay
The anticipated pay range for this role is listed below and represents the firm's good faith and reasonable estimate of the starting salary range at the time of posting. The actual offered rate will be determined based on qualifications, experience, geographic location, education, external market data, and internal equity. In addition, this role is eligible for a discretionary bonus based on performance.
- Boston: $134,700 - $205,450
- New York: $145,800 - $222,350
Schedule
This position requires hybrid on-site presence as an essential function of the role. Consistent and predictable on-site presence is required for ongoing business continuity, professional development, and effective collaboration with colleagues and management. Travel to firm sites and vendor conferences may be required.