
Closed
Posted
I are seeking an experienced Senior Solution & Network Architect to design and support the implementation of an enterprise Cyber Vault and isolated recovery environment for a major organisation in Abu Dhabi, UAE. This is not a general cloud, DevOps, system administration, or backup-operations role. We require a senior architect who has personally designed secure, isolated, and resilient recovery platforms that protect critical enterprise data against ransomware and major cyber incidents. The successful consultant will own or contribute significantly to the end-to-end architecture across backup, storage, virtualization, cloud, network isolation, privileged access, secrets management, security controls, and disaster recovery. Key Responsibilities Design the end-to-end Cyber Vault and isolated recovery architecture. Produce HLDs, LLDs, reference architectures, technical standards, and implementation roadmaps. Design immutable, air-gapped, or logically isolated backup repositories. Define network segmentation between production, backup, Cyber Vault, and clean-recovery environments. Design secure administrative access, privileged-access controls, break-glass procedures, and four-eyes approval processes. Define recovery sequencing, RPO, RTO, restoration testing, and ransomware-recovery procedures. Review existing cloud, data-centre, storage, VMware, backup, and network environments. Evaluate technologies and vendors through RFI, RFP, POC, or technical-assessment processes. Present proposed designs to senior stakeholders, Architecture Review Boards, or Design Authorities. Support technical teams throughout implementation, testing, handover, and operational readiness. Essential Experience Applicants should have at least 10 years of enterprise IT experience, with strong architecture experience in several of the following areas: Cyber Vault or Cyber Recovery architecture Isolated Recovery Environments Immutable or air-gapped backup Ransomware recovery and clean-room restoration Rubrik, Veeam, Commvault, Cohesity, NetBackup, Dell PowerProtect, Data Domain, Avamar, NetWorker, HYCU, or IBM Spectrum Protect Enterprise SAN/NAS and object-storage architecture Fibre Channel, zoning, LUNs, multipathing, storage replication, and retention controls VMware ESXi, vCenter, vSphere, vSAN, NSX, SRM, or VMware Cloud Foundation AWS or Microsoft Azure infrastructure, storage, networking, security, and disaster recovery Cisco or Juniper networking BGP, OSPF, MPLS, SD-WAN, inter-site connectivity, firewalls, and network segmentation HashiCorp Vault, CyberArk, BeyondTrust, ARCON, or another enterprise secrets-management or PAM platform Zero Trust, IAM, RBAC, MFA, encryption, PKI, and HSM integration ISO 27001, NIST, PCI-DSS, DORA, or other regulated-industry security frameworks HLD, LLD, target-state architecture, reference architecture, and technical-roadmap preparation Important Clarification HashiCorp Vault and Cyber Vault are different technologies.
Project ID: 40617164
16 proposals
Remote project
Active 3 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
16 freelancers are bidding on average $61 USD/hour for this job

With a comprehensive background in backend development, DevOps engineering, and Kubernetes orchestration, I bring an all-encompassing perspective to the table that is perfect for your project. Combining my skills in securing and scaling cloud infrastructures with my emphasis on compliance with frameworks such as PCI-DSS and GDPR, I have hands-on experience implementing infrastructure-as-code solutions like Terraform and CloudFormation. Specifically, my ability to automate deployment workflows for high-traffic applications will prove invaluable in ensuring the successful implementation of the enterprise Cyber Vault and isolated recovery environment you seek. Lastly, my AWS certifications – Solutions Architect Associate and Practitioner – align perfectly with your cloud-centric project needs. My exposure to AWS AI/ML services is yet another advantage that comes along with me; it will aid me in integrating intelligent automation solutions that can optimize your operations post-deployment. In conclusion, I am not just a 'tech-guy', but a tech-evangelist who aims for practical applicability and sustainable results – exactly what you need from a senior architect. Choose me to lead this extremely vital assignment and let's together bolster your security walls!
$50 USD in 40 days
5.0
5.0

Bid Rate: $75 USD/hour Estimated Duration: 8–12 weeks (depending on discovery, architecture reviews, and implementation support) This is the kind of enterprise architecture work I've been involved in for large, security-critical environments. I've designed cyber-resilient recovery platforms covering immutable backups, isolated recovery environments, VMware, Azure/AWS, enterprise storage, network segmentation, PAM, and Zero Trust controls—not just backup infrastructure. I also appreciate your clarification that HashiCorp Vault and Cyber Vault are entirely different technologies. A successful Cyber Vault architecture requires coordinating backup, storage, networking, IAM/PAM, and recovery orchestration into a validated ransomware recovery strategy. I can produce complete HLDs, LLDs, implementation roadmaps, and work directly with Architecture Review Boards while supporting implementation through operational readiness. Given the scope, $75/hour reflects senior enterprise architecture expertise and is aligned with market rates. I'd be happy to discuss your preferred Cyber Vault platform and current backup ecosystem.
$75 USD in 40 days
3.8
3.8

Designing a cyber vault that’s actually resilient to ransomware means more than just air-gapping or layering backup vendors. You need strict isolation, immutable storage, network segmentation, PAM and break-glass controls, plus documented recovery paths you’ve tested under real-world constraints. I’ve architected cyber vault and isolated recovery platforms for two large FSI clients—NetBackup, Data Domain, dual-site air gap, role-based access controls, and integration with Azure and AWS for tiered recovery. HLDs, LLDs, board presentations, and technical handover are routine. I document and own the stack: backup solution, network design, VMware/physical infra, firewalls, segmentation, and compliance against ISO 27001/NIST. Is Rubrik, Veeam, or another platform already shortlisted? I can start with a gap review or straight to architecture if you prefer. Pradeep
$50 USD in 40 days
2.5
2.5

With over a decade of experience in designing and implementing secure, resilient, and isolated environments, I am confident that I will be an excellent fit for your Senior Solution & Network Architect role. I have successfully architected several cyber vaults, recovery platforms, and backup repositories for major organizations, displaying my intricate understanding of the threats posed by ransomware and my ability to counter them. One area where my expertise could prove invaluable is in my familiarity with a wide array of technologies such as Rubrik, Veeam, Commvault, Cohesity, NetBackup, Dell PowerProtect etc. Couple that with my comprehensive knowledge of enterprise SAN/NAS architecture, LUNs zoning, storage replication and more ensures that I understand the practicalities and challenges of implementing solutions at scale.
$50 USD in 40 days
2.6
2.6

Hey! This is deeply specialized — Cyber Vault/isolated recovery architecture is a rare, senior niche. $50+/hr is a fair floor, but for this calibre (10+ yrs, HLD/LLD ownership, Rubrik/Veeam/CyberArk-level expertise, UAE enterprise stakeholder work) market typically lands $85–130/hr. SolutionzHere has senior architects with backup/storage/network segmentation and Zero Trust design experience — happy to align the right specialist to this scope. Quick Q: is this remote-only, or does it require periodic on-site presence in Abu Dhabi?
$130 USD in 40 days
2.7
2.7

The Cyber Vault and isolated recovery environment requires more than a standard backup deployment: it needs a complete architecture spanning immutable or air-gapped repositories, production/backup/vault/clean-room segmentation, privileged access, secrets protection, recovery sequencing, and ransomware restoration testing. I can support this work through structured architecture documentation and implementation guidance, drawing on 10+ years across cloud, infrastructure, networking, security integration, and technical delivery. My approach would begin with reviewing the current Azure/AWS, data-centre, VMware, storage, backup, firewall, and identity environments. I would then define the target-state architecture, trust boundaries, data flows, RPO/RTO tiers, retention and immutability controls, isolated administration, MFA/RBAC, break-glass and four-eyes procedures, and clean recovery-zone connectivity. I would produce HLDs, LLDs, UML/network diagrams, standards, technology assessment criteria, and a phased implementation and testing roadmap. Vendor options such as Rubrik, Veeam, Commvault, Cohesity, PowerProtect, SAN/NAS, and object storage can be assessed against resilience and operational requirements. HashiCorp Vault and Cyber Vault would be treated as separate architectural components, with PAM, PKI, encryption, and framework controls mapped appropriately. Muhammad Saad
$50 USD in 40 days
0.0
0.0

Hi there, This is Shree from Kyyba. Is the position remote, or does the Architect need to work at your client's location in Abu Dhabi, UAE? Quick Questions Is there a preferred backup platform: Rubrik, Veeam, Dell, Cohesity? On-premises, Azure, AWS, or hybrid? Existing VMware Cloud Foundation or standard vSphere? Are NIST or UAE regulatory frameworks mandatory? Technical Approach • Assess the current infrastructure across backup, VMware, storage, networking, IAM, and cloud platforms. • Design an end-to-end Cyber Vault with immutable, air-gapped/logically isolated repositories and clean-room recovery architecture. • Prepare HLD, LLD, reference architecture, implementation roadmap, RPO/RTO strategy, and operational runbooks. • Define secure network segmentation between production, backup, Cyber Vault, and recovery zones using Zero Trust principles. • Implement PAM, MFA, RBAC, break-glass access, secrets management CyberArk/HashiCorp Vault, encryption, PKI, and audit controls. • Architect ransomware recovery workflows, validation testing, recovery sequencing, and operational readiness. Core Expertise Cyber Vault & Isolated Recovery VMware vSphere, vSAN, NSX, SRM AWS & Azure DR SAN/NAS, Object Storage Cisco/Juniper Networking Zero Trust & NIST/ISO 27001 PAM, CyberArk, HashiCorp Vault Enterprise Backup & Disaster Recovery Thanks Shree Kyyba.
$80 USD in 40 days
0.0
0.0

Baguio, Philippines
Payment method verified
Member since Jun 4, 2015
$10 USD
$10-30 USD
$10-30 USD
$15-25 USD / hour
$250-750 USD
$30-250 USD
$30-250 USD
£20-250 GBP
£10-15 GBP / hour
₹750-1250 INR / hour
₹600-1500 INR
£20-250 GBP
₹750-1250 INR / hour
₹75000-150000 INR
₹75000-150000 INR
₹400-750 INR / hour
min $50 USD / hour
$30-250 USD
₹750-1250 INR / hour
$10-30 USD
$30-250 USD
€250-750 EUR
₹12500-37500 INR
₹1500-12500 INR
₹12500-37500 INR