POSITION OVERVIEWBioworld Merch is seeking a hands-on Network Engineer to design, deploy, and maintain global network infrastructure across corporate offices, warehouses, distribution centers, and data center environments. The role has strong day-to-day ownership of Cisco networking, Palo Alto firewalls, wireless, WAN/SD-WAN, VPN, and network troubleshooting.
This position works closely with the internal Security Engineer/security team to implement firewall policy, network segmentation, access-control changes, security remediation, and incident-response actions based on established security standards. The role is hands-on and requires regular access to physical infrastructure, including network closets, warehouse/distribution equipment, and data center hardware.
Location: Dallas-Fort Worth (DFW) metro area | Schedule: 4 days on-site, 1 remote day | Department: IT / Infrastructure | Reports to: IT Manager / Director of Infrastructure | Employment: Full-Time | Target base salary: $105,000-$140,000
RESPONSIBILITIES- Design, deploy, configure, and maintain LAN/WAN, wireless, and data center network infrastructure across corporate offices, warehouses, and distribution centers.
- Manage Cisco routing and switching environments, including Catalyst, Nexus, ISR/ASR, VLANs, STP, EIGRP/OSPF/BGP, QoS, and link aggregation.
- Maintain SD-WAN and WAN circuit performance, including MPLS, broadband, and LTE/5G failover across multiple sites.
- Own network documentation, including topology diagrams, IP address management (IPAM), configuration standards, and runbooks.
- Provide Tier 2/3 troubleshooting and root-cause analysis for network outages, performance issues, and connectivity problems.
- Configure and maintain Palo Alto Networks firewalls, including Panorama, NGFW policies, App-ID, User-ID, URL filtering, and GlobalProtect VPN, based on security policies and standards.
- Support the Cisco security stack, including ASA/Firepower, ISE for NAC, and Umbrella, where applicable.
- Implement network segmentation and access-control changes in coordination with the internal Security Engineer/security team.
- Manage site-to-site and remote-access VPNs, including IPSec, SSL/GlobalProtect, and AnyConnect.
- Apply firmware and patch updates to network and firewall appliances and execute remediation items from audits and penetration tests in coordination with Security.
- Serve as the network-side point of contact during security incidents by providing logs, executing emergency firewall/network changes, and supporting investigation and containment efforts.
- Lead or contribute to network refreshes, data center migrations, cloud connectivity, office build-outs, and other infrastructure projects.
- Evaluate and recommend network tools and technologies that improve visibility, automation, reliability, and operational efficiency.
- Automate repetitive network tasks using Python, Ansible, Terraform, or similar tools where appropriate.
- Partner closely with Security Engineering and the broader IT team to translate security and business requirements into scalable network designs.
QUALIFICATIONS- 4+ years of hands-on experience in network engineering.
- Deep, hands-on experience with Cisco networking, including switching, routing, wireless, configuration, troubleshooting, and lifecycle management.
- Deep, hands-on experience with Palo Alto Networks firewalls, including policy creation, Panorama management, and day-to-day administration.
- Strong understanding of TCP/IP, DNS, DHCP, VLANs, routing protocols such as OSPF and BGP, NAT, and QoS.
- Practical experience with site-to-site and remote-access VPN technologies.
- Working knowledge of network segmentation, IDS/IPS, logging, and SIEM fundamentals, with the ability to execute security changes defined by a security team.
- Experience troubleshooting multi-site, multi-vendor network environments under production pressure.
- Comfortable with on-call rotation and occasional after-hours maintenance windows.
- Must reside in or be willing to relocate to the DFW metro area and work on-site 4 days per week, with occasional travel between Dallas-area facilities as needed.
- Preferred certifications include CCNA/CCNP, PCNSA/PCNSE, or CompTIA Security+.
- Preferred experience with Cisco ISE, Umbrella, NAC/SASE solutions, SD-WAN, and network automation using Python, Ansible, or Terraform.
- Preferred experience in retail, e-commerce, warehouse/distribution, or manufacturing environments, including PCI-DSS exposure and hybrid cloud networking.
EDUCATION- Bachelor's degree in Computer Science, Information Technology, Network Engineering, or a related field, or equivalent professional experience.
BUSINESS HOURS- Regular business hours are Monday through Friday, 8:30am - 5:30pm. The role requires flexibility for on-call support and occasional after-hours maintenance windows, as needed to meet business and infrastructure objectives.