Principal Network EngineerAbout YouAs a Principal Network Engineer, you will serve as TASB's most senior individual-contributor authority on enterprise networking, owning both the architecture and the hands-on engineering of a multi-entity, hybrid Azure/on-premises environment with compliance-sensitive segmentation requirements. You will build the multi-year network modernization roadmap and personally implement it, leading TASB's platform migration from Cisco to Juniper while keeping the existing Cisco environment fully stable throughout the transition.
A Typical Day - Own and evolve enterprise network architecture and the multi-year technology roadmap, including platform standards, topology design, and lifecycle planning for switching, routing, and security infrastructure
- Lead the design, planning, and execution of the Cisco-to-Juniper platform migration, including risk assessment, cutover planning, and post-migration validation
- Collaborate with the Information Security team on network security policy, firewall rule management, and traffic flow analysis, and mentor supporting network staff
- If you're still reading, we'd love to meet you!
How You'll Make an Impact- Own and continuously evolve enterprise network architecture and the multi-year technology roadmap, including platform standards, topology design, and lifecycle planning for switching, routing, and security infrastructure
- Lead the design, planning, and execution of network platform migrations and major technology transitions, including risk assessment, cutover planning, and post-migration validation
- Design and implement network segmentation strategies - including trust zones, VLANs, NAC, and 802.1X to enforce security boundaries and meet entity-specific and regulatory isolation requirements
- Perform hands-on configuration, deployment, and troubleshooting of switching, routing, and firewall infrastructure across campus, datacenter, and edge environments
- Architect and maintain hybrid connectivity between on-premises infrastructure and Microsoft Azure, including VPN Gateway, ExpressRoute, VNets, NSGs, and multi-subscription routing
- Serve as the escalation point for complex network incidents, performing root cause analysis and driving remediation for issues affecting production systems
- Provide technical mentorship and day-to-day guidance to network administration staff, building team capability on current and emerging platforms
- Develop and maintain network documentation, standards, and diagrams, ensuring architecture decisions are captured and repeatable
- Evaluate emerging network technologies and vendor products, and recommend investments aligned to organizational strategy and budget
- Manage network-related change control activities, including change proposals, testing, and coordination with the Change Advisory Board
- Collaborating with the Information Security team on network security policy, firewall rule management, and traffic flow analysis
- Present architecture strategy, project status, and technology investment recommendations to IT leadership and other non-technical stakeholders
- Participate in an on-call rotation and provide after-hours support for critical network incidents as needed
Skills For SuccessEducation and Experience:
- Bachelor's degree in Information Technology, Computer Science, Engineering, or a related field, or equivalent professional experience
- Required certifications: JNCIP-ENT (JNCIE-ENT preferred) and CCNP Enterprise or CCIE Enterprise Infrastructure; Microsoft Certified: Azure Network Engineer Associate strongly preferred; or ability to obtain required certifications within the first 12 months of employment as a condition of employment
- 10+ years of progressive enterprise networking experience
- 5+ years of network architecture and design ownership; not participation, but accountable decision-making
- Hands-on experience deploying and administering Juniper EX Series switching and SRX Series security platforms, and administering Cisco Catalyst and Nexus platforms, in a production enterprise environment
- Experience designing and implementing network segmentation, trust zones, VLANs, NAC, and 802.1X in a multi-entity or multi-tenant environment, ideally with compliance-aware requirements such as FINRA or SOC2
- Experience with Microsoft Azure hybrid networking in multi-subscription environments, including VPN Gateway, ExpressRoute, NSGs, and hub-spoke topologies
Knowledge, Skills, and Abilities
- Demonstrated ability leading or executing a network platform migration in a production enterprise environment.
- Ability to operate as a senior individual contributor in a lean team
- Skilled in Juniper EX Series (access/distribution/core switching), SRX Series (stateful firewall, routing, security policy).
- Knowledge with Network security policy design, firewall rule management, traffic flow analysis
- Ability to present architecture and investment recommendations to non-technical leadership
- Knowledgeable in nonprofit, public sector, or multi-affiliate organizational environments
The TASB Difference- Enjoy competitive pay and rich benefit offerings
- Be part of a collaborative environment where every contribution impacts Texas public schoolchildren
- Thrive in a culture that promotes bringing your whole self to work every day and emphasizes healthy boundaries and work-life balance
- Learn and grow individually and together through frequent professional development, wellness seminars, and more
- Work alongside transparent leaders with an open and consistent feedback approach
- Celebrate as a team with meaningful (and fun) events and tokens of appreciation throughout the year
Posting Notices- Salary commensurate with experience
- The health and safety of our employees and members is our top priority
- This position does not qualify for visa sponsorship
- Any job offer is contingent upon receipt of results of a satisfactory background check
#LI-Hybrid