Loading jobs…
Loading jobs…
Baron Capital — Bloomington, Minnesota
We are seeking a VP - IT Infrastructure & Security to architect, secure, and operate a modern hybrid enterprise infrastructure. This role operates at the intersection of network engineering, cloud architecture, endpoint security, and cybersecurity governance. You will be responsible for designing and enforcing a defense-in-depth security model, implementing Zero Trust Architecture, and ensuring end-to-end protection of identity, devices, networks, applications, and data across the organization.
This is a hands-on technical leadership role with ownership of architecture, security strategy, and operational excellence. This position requires 24/7 on-call availability, with regular working hours of Monday through Friday, 8:00 AM to 5:00 PM. Enterprise Architecture & Zero Trust Design Design and implement end-to-end enterprise architecture across on-prem and cloud environments (Azure-first strategy).
Lead adoption of Zero Trust Architecture (ZTA): Identity-driven access (Azure AD / Entra ID) Device trust enforcement (Intune / MDM compliance) Network segmentation & micro-segmentation Continuous verification and least-privilege access Establish defense-in-depth strategy across: Perimeter (firewalls, NAC) Internal network (segmentation, NAC) Endpoint (EDR/XDR) Identity (MFA, Conditional Access) Data (DLP, encryption) Advanced Network Engineering & Security Architect and manage enterprise-grade networking across Netgear, Cisco Meraki, and hybrid WAN environments. Design and enforce multi-tier VLAN architecture, segmentation, and secure routing strategies. 1X authentication for secure network access.
Perform deep network analysis including packet capture, traffic inspection, and anomaly detection. Integrate network telemetry into centralized logging / SIEM pipelines. Cloud Infrastructure & Hybrid Identity (Azure) Architect and manage Microsoft Azure environments: VMs, VNets, NSGs, load balancers, private endpoints Hybrid connectivity (VPN, ExpressRoute) Design secure identity architecture using Azure AD (Entra ID): Conditional Access policies MFA enforcement (Duo/YubiKey integration) Identity Protection & risk-based access Integrate on-prem Active Directory with Azure AD for hybrid identity governance.
Implement role-based access control (RBAC) and privileged identity management (PIM). Drive infrastructure-as-code (IaC) and automation strategies. Endpoint Security, MDM & Device Governance Architect enterprise endpoint strategy using: Microsoft Intune (MDM/MAM) Device compliance policies, configuration profiles, and security baselines Enforce Zero Trust device posture validation before granting access.
Implement full device lifecycle management (provisioning → compliance → decommissioning). Secure both corporate and BYOD environments with strict policy enforcement. Advanced Threat Protection & Data Security Lead deployment and optimization of CrowdStrike Falcon (EDR/XDR platform): Policy creation and tuning Behavioral threat detection and threat hunting Automated containment and response Design and enforce data protection strategies: Data classification and labeling Encryption (at rest, in transit) Implement multi-layered security controls across all attack surfaces.
Conduct vulnerability management and coordinate remediation using enterprise tools. Email Security & Domain Protection Architect and enforce email authentication and anti-spoofing controls: DMARC, DKIM, SPF Monitor and respond to phishing campaigns and domain abuse. Manage DNS security, domain configurations, and SSL/TLS certificates via GoDaddy or enterprise DNS providers.