Job Description:We are seeking a Senior Network Engineer to support, design, and maintain our enterprise network infrastructure. This role owns day-to-day network operations while also driving architecture and configuration work for new deployments and upgrades. The ideal candidate has deep hands-on expertise with Layer 2/Layer 3 switching, enterprise firewalls, and VPN technologies, and can troubleshoot complex issues across multi-vendor environments with minimal supervision. Security experience is a strong plus.
Responsibilities include: Network Operations & Support- Serve as an escalation point for complex network incidents, performing root cause analysis and driving issues to resolution within SLA
- Monitor network health, capacity, and performance; proactively identify and remediate bottlenecks before they impact users
- Troubleshoot connectivity issues across VLANs, routing, switching, DNS, DHCP, TCP/IP, and WAN/ISP links
- Use packet capture and network monitoring tools to diagnose latency, packet loss, and application performance problems
- Manage firmware upgrades, patching, and configuration backups following established change management procedures
- Participate in an on-call rotation and support scheduled maintenance windows
Network Design & Architecture- Design scalable, resilient LAN, WAN, and remote-access solutions that support business growth
- Develop network diagrams, IP addressing schemes, VLAN plans, and routing designs
- Evaluate and recommend hardware, software, and circuits; participate in vendor selection and technical evaluations
- Lead network components of infrastructure projects - site build-outs, migrations, refreshes, and cloud connectivity
- Define and maintain network standards, baseline configurations, and technical documentation
Configuration & Implementation- Configure and maintain Layer 2/Layer 3 switches, including VLANs, trunking, spanning tree, port security, link aggregation, and inter-VLAN routing
- Configure and maintain routing protocols (OSPF, BGP, EIGRP, static routing) across the enterprise WAN
- Administer enterprise firewalls: security policies, NAT, application control, and access control rules
- Build and maintain site-to-site IPsec VPN tunnels between offices, data centers, and third-party partners, including troubleshooting Phase 1/Phase 2 negotiation, rekeying, and tunnel stability issues
- Deploy and support remote-access VPN (SSL/IPsec) for end users, including authentication integration and client troubleshooting
- Implement network segmentation and access control between environments
Collaboration & Documentation- Maintain accurate network documentation, runbooks, and as-built diagrams
- Provide technical mentorship to junior engineers and help-desk staff
- Work with systems, application, and security teams on cross-functional initiatives
- Communicate clearly with non-technical stakeholders during outages and project planning
Requirements:• 7+ years of hands-on enterprise network engineering experience (or 5+ with a relevant degree)
• Expert-level knowledge of Layer 2/Layer 3 switching and routing in production environments
• Strong hands-on experience administering enterprise firewalls (e.g., Palo Alto, Fortinet, Cisco ASA/Firepower, Check Point)
• Proven experience designing, deploying, and troubleshooting site-to-site and remote-access VPNs
• Solid grasp of TCP/IP, subnetting, DNS, DHCP, NAT, QoS, and network security fundamentals
• Demonstrated ability to troubleshoot complex, cross-domain issues under pressure
• Experience working within formal change management and documentation practices
• Strong written and verbal communication skills
Additional Skills Preferred (but not required):• Security experience: firewall log analysis, incident response support, IDS/IPS, network segmentation, or vulnerability remediation
• Industry certifications: CCNP, CCIE, PCNSE, NSE 4+, JNCIP, CompTIA Security+, or equivalent
• Experience with NAC, 802.1X, RADIUS/TACACS+, or Zero Trust access models
• Cloud networking experience (AWS, Azure, or GCP - VPCs, transit gateways, VPN/Direct Connect)
• Wireless infrastructure experience (Cisco, Aruba, Meraki)
• SD-WAN deployment and management
• Hands-on experience with network automation frameworks and infrastructure-as-code practices (Python, Ansible, Terraform, Git)
• Experience with AIOps or AI-assisted network monitoring, observability, and analytics platforms
• Familiarity with compliance frameworks (NIST, PCI-DSS, HIPAA, SOC 2)
Education & Experience:• Bachelor's degree in Computer Science, Information Technology, Computer Engineering, Telecommunications, or a related technical field -
or equivalent combination of education, certifications, and hands-on experience
• Demonstrated experience supporting multi-site environments with 2000+ users and/or multiple data centers or branch locations
• Experience operating in a 24/7 production environment with defined SLAs, change control, and on-call responsibilities
• Prior experience mentoring junior engineers or serving as a technical escalation point
• Active or recent industry certification (CCNA/CCNP or vendor-equivalent) required; advanced certifications (CCIE, PCNSE, NSE 4+) strongly preferred