Job Summary
We are seeking a highly skilled and experienced Network Infrastructure Engineer to support and advance an enterprise networking environment. This position will play a critical role in designing, deploying, and operating data center networks, identity-driven access systems, and observability platforms. The engineer will work closely with infrastructure teams to ensure network services remain reliable, scalable, secure, and aligned with enterprise modernization goals. This is a hands-on engineering position requiring strong technical expertise, effective communication, and the ability to support mission-critical systems across data centers and statewide operations.
Key Responsibilities
• Design, implement, and maintain Cisco Nexus platforms running ACI mode, including VRFs, Bridge Domains, EPGs/ESGs, L3Out, contracts, and fabric policies.
• Integrate Cisco ACI with virtualization and container platforms, including Red Hat OpenShift VMM and Isovalent/Cilium.
• Configure and optimize RoCEv2 within the ACI fabric for high-performance, low-latency workloads.
• Troubleshoot ACI fabric health, faults, endpoint learning, contracts, and multi-tenant segmentation.
• Develop and maintain fabric documentation, standards, and operational procedures.
• Deploy and support Cisco Catalyst platforms within campus environments.
• Design and maintain Software-Defined Access (SDA) architectures, including SDA Wired Fabric and Fabric-Enabled Wireless.
• Manage fabric underlay and overlay, policy mapping, authentication integrations, and assurance operations.
• Collaborate with wireless engineers to optimize coverage, performance, and policy enforcement across SDA.
• Configure and administer Cisco Identity Services Engine (ISE) for TACACS+ device administration, authentication and authorization policy sets, and endpoint profiling.
• Integrate Cyber Vision intelligence into profiling, segmentation, and access control workflows.
• Support Zero Trust efforts through identity-centric segmentation and policy integration across ACI and SDA fabrics.
• Deploy and manage ThousandEyes for end-to-end visibility, routing path analysis, and performance monitoring.
• Implement and support Cisco Cyber Vision for OT/IoT asset visibility, device classification, and behavior analysis.
• Manage DNA Spaces for location analytics, telemetry ingestion, device behavior, and wireless intelligence.
• Provide meaningful insights to leadership using data from observability platforms.
• Troubleshoot complex Layer 2 and Layer 3 network issues across VLANs, OSPF, BGP, STP, and multicast environments.
• Design and implement Palo Alto Networks security solutions across enterprise environments.
• Create and maintain architecture diagrams, standards, runbooks, and asset inventories.
• Assist with modernization planning, platform upgrades, procurement processes, and enterprise technology initiatives.
Required Qualifications
• Minimum of 15 years of experience working with Cisco networking.
• Hands-on experience with Cisco ACI in production environments.
• Deep knowledge of ACI constructs, including VRF, BD, EPG, ESG, L3Out, and contracts.
• Experience integrating ACI with OpenShift VMM and Cilium/Isovalent.
• Proficiency with Cisco Catalyst platforms and SDA fabric technologies.
• Experience administering Cisco ISE, including TACACS+ and policy-set based NAC.
• Strong understanding of ThousandEyes, Cyber Vision, and DNA Spaces or comparable tools.
• Solid understanding of TCP/IP, routing, switching, QoS, and network security fundamentals.
• Ability to develop clear diagrams, documentation, and architectural artifacts.
• Strong analytical and communication skills with the ability to work in fast-paced, mission-critical environments.
Preferred Qualifications
• Cisco certifications such as CCNP Data Center, CCNP Enterprise, CCIE, or equivalent experience.
• Hands-on experience with container networking and virtualization integrations.
• Familiarity with NIST frameworks and cybersecurity requirements.
• Experience with network automation tools such as Python, Ansible, and REST APIs.
• Prior experience in state government or large enterprise network environments.
• PCCSA certification or equivalent knowledge of Palo Alto Networks security fundamentals, including NGFW concepts, threats, App-ID, and policy.
• PCNSA certification or equivalent experience with NGFW configuration, security profiles, NAT, App-ID, URL filtering, and WildFire.