Work Location:US.LA.Carencro.2900 Highway 93
Working Environment: On-Site
Division: Site Access
Information Technology - Infrastructure
The Senior Network Engineer (OT/ICS) designs, deploys, secures, and supports network infrastructure across NPK's enterprise IT and industrial/OT environments in Carencro, Louisiana. This role bridges the IT/OT divide - configuring enterprise Cisco routing and switching, hardening plant-floor control networks, and building segmentation and security policy on Fortinet firewalls. The engineer partners closely with the Senior Manager of IT Services & Support, site operations, and controls/automation teams to maintain availability, enforce segmentation per IEC 62443 and NIST frameworks, and deliver projects aligned with the IT strategic roadmap.
Responsibilities:
- Design, implement, and maintain LAN, WAN, and wireless infrastructure across corporate, plant, and cloud-connected environments.
- Architect and enforce secure IT/OT network segmentation using the Purdue model, VLANs, VRFs, firewalls, and industrial DMZs.
- Configure and support routing and switching technologies, including OSPF, BGP, static routing, STP/RSTP, LACP, VLANs, trunking, switch stacking, QoS, and 802.1X.
- Build and maintain highly available network architectures, including redundant uplinks, HA firewall pairs, and resilient topologies for 24/7 operations.
- Plan, deploy, and support secure site-to-site and remote-access connectivity using IPsec and SSL VPN technologies.
- Configure, manage, and optimize Fortinet solutions, including FortiGate NGFWs, security policies, NAT, VIPs, IPS, application control, web filtering, SSL inspection, FortiManager, FortiAnalyzer, FortiSwitch, and FortiAP.
- Administer and support Cisco Catalyst, Nexus, IOS/IOS-XE, wireless, and industrial Ethernet platforms; troubleshoot Layer 1-3 connectivity issues using CLI tools, packet captures, and SPAN.
- Support and secure OT/ICS environments, including PLCs, HMIs, RTUs, SCADA systems, and historians, while accounting for legacy protocols, deterministic traffic, and operational constraints.
- Enforce least-privilege access controls and secure remote access solutions for internal users, vendors, and support personnel across IT and OT networks.
- Participate in on-call support and maintenance activities; maintain network documentation, including topology diagrams, IP addressing schemes, firewall rule sets, and operational runbooks, and perform additional duties as assigned.
Experience Requirements:
- Bachelor's degree in Information Technology, Computer Science, Network Engineering, or a related technical field preferred; equivalent combinations of education and relevant hands-on experience will be considered.
- Experience with Cisco and Fortinet networking technologies, including routing, switching, wireless, WAN/SD-WAN connectivity, firewalls, VPNs, network segmentation, centralized management, and network troubleshooting.
- Strong knowledge of core networking and security concepts, including TCP/IP, DNS, DHCP, NAT, QoS, routing and switching protocols, network monitoring/analysis, and security policy administration.
- Familiarity with IT/OT and industrial networking environments, including OT/ICS security principles, industrial protocols, and network automation/scripting tools.
- Experience supporting multi-site network environments, including cloud networking, centralized firewall management, and occasional travel between facilities.
- Knowledge of industry security frameworks (NIST CSF, CIS Controls, IEC 62443); relevant certifications such as Fortinet, Cisco, CompTIA, or IEC 62443 are preferred.