Back to search
Subway Linkedin · Posted 8d ago

Director of Network

Shelton, Connecticut, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Why Join Subway?

At Subway, we are not standing still. We are building.


This is a business focused on what matters most: growing franchisee profitability, strengthening our brand and creating long-term value. The people who thrive here are the ones who want to make a real impact.


You will not just do the work. You will shape it.


We move fast. We think like owners. We make decisions that matter. We hold ourselves to a high standard because what we do directly impacts thousands of franchisees around the world.


If you bring energy, accountability and a bias for action, you will fit right in.

We take the work seriously, but we also know the best results come from teams that support each other, celebrate wins and show up ready to build something better every day.

This is your chance to be part of what’s next.


Role Overview

The Director of Network is a senior technology leader responsible for the strategy, architecture, and operational excellence of Subway's enterprise network infrastructure. Reporting to the Sr. Director of Platform Engineering, this role owns WAN/LAN, SD-WAN, ZTNA, DNS, and load balancing across corporate, cloud (Azure/AWS), and franchise restaurant environments.

Key Responsibilities

Network Strategy & Architecture

  • Define enterprise network strategy: WAN/LAN, SD-WAN (Silver Peak/Aruba EdgeConnect), restaurant connectivity, NGFW (Palo Alto), and cloud networking (Azure vNET/ExpressRoute/Firewall/NSGs; AWS Transit Gateway/VPC/Direct Connect).
  • Own the ZTNA roadmap, replacing legacy VPN with zero trust access.
  • Design DNS, DHCP, IPAM, and load balancing for high availability across corporate and franchise environments.
  • Partner with Cyber Security on segmentation and firewall policy compliance.
  • Drive cloud-native architecture (hub-and-spoke, shared services, IaC provisioning) across Azure and AWS.

Infrastructure-as-Code & Automation

  • Lead Terraform adoption as the primary IaC tool; enforce module governance and state management.
  • Build CI/CD pipelines (GitHub Actions/Azure DevOps) for automated network config deployment.
  • Supplement Terraform with light scripting (Python/Ansible) only where needed.
  • Champion automation-first culture; implement drift detection and remediation.

Cloud Networking

  • Own multi-cloud architecture and operations across Azure and AWS with consistent security posture and routing design.
  • Manage VNets, peering, private endpoints, NSGs, route tables, and cloud-native firewalls.
  • Lead observability (flow logs, performance monitoring, alerting) and cost optimization (right-sizing, traffic engineering, egress governance).
  • Partner with Cloud Engineering and Application teams on scalable architectures.

Franchise & Restaurant Network Operations

  • Oversee connectivity/performance for 37,000+ restaurant locations globally.
  • Standardize restaurant network architecture (POS, guest Wi-Fi, digital menu boards, IoT).
  • Manage ISP/MSP/equipment vendor relationships for SLA adherence and cost control.

Team Leadership & Vendor Management

  • Lead a blended team (FTE + managed services) across network engineering and operations.
  • Hold vendors/system integrators accountable to SOWs, SLAs, and milestones.
  • Manage annual operating/capital budgets; champion AI tooling adoption.

Governance, Risk & Compliance

  • Ensure network controls meet SOX, PCI-DSS, GDPR, CCPA; serve as audit point of contact.
  • Maintain and test DR/BC plans.
  • Identify and mitigate availability and security risks.
  • Run change advisory board (CAB) reviews.

Required Qualifications

  • Bachelor's in Computer Science, Network Engineering, Cybersecurity, IT, or related field.
  • 12–15+ years in IT infrastructure/network engineering, including 5+ years in senior leadership over enterprise network functions. Multi-site franchise/retail/QSR experience preferred.
  • Deep expertise in ZTNA, routing/switching (BGP, OSPF, VXLAN), Palo Alto NGFW (PAN-OS, Panorama), and Silver Peak/Aruba EdgeConnect SD-WAN (overlay design, path conditioning, QoS).
  • Strong cloud networking across Azure (vNET, ExpressRoute, Firewall, NSGs, App Gateway) and AWS (Transit Gateway, VPC, Direct Connect, Security Groups, Network Firewall), including hub-and-spoke and shared services at scale.
  • Terraform required as primary automation mechanism — modular codebases, remote state, drift detection, CI/CD integration. Light scripting (Python/Ansible) a plus.
  • Certifications: CCNP or CCIE required; AZ-700 or AWS Advanced Networking Specialty preferred; Terraform Associate and ITIL v4 a plus.
  • Proven leadership of blended FTE/MSP teams, multi-million-dollar budget management, and vendor accountability.
  • Strong executive communication skills, able to translate technical topics for business audiences.

Hands-On Technical Requirements (direct build/design/operate experience, not just oversight)

  • Azure VNet: peering, hub-and-spoke, route tables, private/service endpoints
  • AWS VPC: subnetting, routing, peering, PrivateLink, security groups, NACLs across multi-account environments
  • AWS Transit Gateway: multi-VPC/account connectivity, route segmentation, inter-region peering, centralized inspection
  • NSGs: rule design and automated enforcement at scale
  • Guardicore (Akamai Segmentation): microsegmentation, ring-fencing, label-based policy
  • ZTNA: hands-on implementation and operations
  • Palo Alto Networks: NGFW administration, policy management, threat prevention
  • Silver Peak (Aruba EdgeConnect) SD-WAN: overlay design, path conditioning, QoS
  • Terraform: production-grade modules for Azure/AWS, remote state, workspaces, pipelines
  • Cloud observability: flow logs, network watcher, traffic analytics, alerting

Preferred

  • QSR/franchise/hospitality experience at 10,000+ location scale
  • Legacy VPN-to-ZTNA migration experience
  • Zero Trust framework familiarity (CISA, Forrester, NIST 800-207)
  • PCI-DSS network segmentation knowledge
  • AIOps/generative AI familiarity for network automation and troubleshooting

Why This Role

Own network strategy for one of the world's largest franchise brands — 37,000+ restaurants and a global workforce — while leading Subway's transition to Zero Trust and a scaled, IaC-driven multi-cloud network.


What do we offer?

  • Insurance Plans (Medical, Life)
  • Pension/401K/RSP (country specific)
  • Competitive Bonus
  • Mobility Allowance
  • Tuition Reimbursement
  • Company Holidays
  • Volunteering time
  • And More…..


Compensation: The base pay range for this role is $184,500-230.600 annually

Pay within this range will be determined in good faith based on job-related factors, which may include skills, experience, education/training, location, and internal equity.


Subway uses technology‑assisted tools to support our recruitment process. These tools strictly help organize and sort applications based on job‑related qualifications. All decisions are made by people - our recruiting team and hiring managers. If you have questions or would like to request an alternative review process, please let us know.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search