The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
Job Summary:We are seeking a highly experienced
Senior Network Engineer to lead the design, implementation, modernization, and operational support of enterprise network infrastructure, with primary focus on
Cisco ACI fabric, data center networking, WAN architecture, routing, switching, and network resiliency.
This role will support secure, scalable, and highly available connectivity across data centers, branch locations, campus networks, and hybrid-cloud environments. The ideal candidate has deep hands-on experience with Cisco ACI, Cisco Nexus platforms, enterprise routing and switching, data center segmentation, and operational troubleshooting.
Cloud networking experience is important, but it should represent approximately
20% of the role, with the core focus remaining on enterprise network engineering and Cisco data center technologies.
Key Responsibilities- Design, deploy, and support enterprise Cisco network infrastructure across data center, campus, branch, and WAN environments.
- Lead Cisco ACI fabric design, implementation, policy modeling, operations, troubleshooting, upgrades, and lifecycle management.
- Build and manage ACI constructs including tenants, VRFs, bridge domains, subnets, endpoint groups, contracts, filters, application profiles, L3Outs, external EPGs, and route controls.
- Support Cisco ACI fabric operations including spine and leaf switches, APIC controllers, fabric discovery, fabric access policies, interface policies, domains, AAEPs, VLAN pools, and VMM integration.
- Design and support ACI external connectivity using L3Outs, BGP, OSPF, static routing, route maps, prefix filters, contracts, and route leaking.
- Support ACI data center segmentation, application connectivity, firewall integration, load balancer integration, and secure east-west traffic flows.
- Troubleshoot complex ACI issues related to endpoint learning, contract enforcement, policy deployment, routing adjacency, Layer 2 extension, Layer 3 connectivity, and fabric health.
- Architect and support WAN connectivity, including routing design, carrier circuits, MPLS, internet connectivity, VPN, and resilient site-to-site connectivity.
- Design and operate routing and switching environments using BGP, OSPF, EIGRP, VRF, VLAN, VPC, trunking, port channels, and network segmentation.
- Partner with operations, infrastructure, security, application, and vendor teams to deliver stable, secure, and scalable network services.
- Lead troubleshooting and root-cause analysis for complex network incidents, performance issues, packet loss, latency, routing problems, and application connectivity failures.
- Develop and maintain network standards, diagrams, implementation plans, migration plans, rollback plans, operational runbooks, and support documentation.
- Support network modernization initiatives focused on automation, observability, performance, scalability, resiliency, and security.
- Use tools such as SolarWinds, Splunk, NetBrain, Wireshark, APIC tools, packet captures, and network telemetry to improve visibility and operational response.
- Support hybrid-cloud connectivity and cloud network integration, including AWS Direct Connect, Transit Gateway, VPC design, routing, and DNS integration, as approximately 20% of the role.
- Participate in change management, implementation planning, production support, and on-call rotation as needed.
Required QualificationsExperience- 8+ years of enterprise network engineering experience in large, complex production environments.
- Strong hands-on experience designing, implementing, and supporting Cisco data center, WAN, routing, and switching environments.
- Deep experience with Cisco ACI fabric operations, policy design, data center segmentation, and troubleshooting.
- Proven experience supporting business-critical network infrastructure in highly available and highly regulated environments.
- Experience leading network projects, major changes, incident response, technical design discussions, and vendor coordination.
Cisco ACI and Data Center Networking- Strong hands-on experience with Cisco ACI fabric design and operations, including:
- APIC controller management
- Spine and leaf architecture
- Fabric discovery and node registration
- Firmware upgrades and lifecycle management
- Fabric health monitoring and fault analysis
- Deep understanding of ACI policy model, including:
- Tenants
- VRFs
- Bridge domains
- Subnets
- Endpoint groups
- Contracts
- Filters
- Application profiles
- External EPGs
- Strong experience with ACI access policy configuration, including:
- VLAN pools
- Physical domains
- AAEPs
- Interface policy groups
- Leaf interface profiles
- Switch profiles
- Port channels and virtual port channels
- Experience designing and supporting ACI L3Out connectivity, including:
- BGP
- OSPF
- Static routing
- Route maps
- Prefix filtering
- Route redistribution
- External network policies
- Experience with ACI segmentation and security design, including:
- Contract-based access control
- Inter-VRF communication
- Shared services
- Route leaking
- Firewall insertion or firewall integration
- Load balancer integration
- Strong troubleshooting skills for:
- Endpoint learning issues
- Contract or policy enforcement issues
- Misconfigured bridge domains or EPGs
- L3Out routing problems
- Asymmetric routing
- Fabric faults
- Link failures
- APIC policy deployment issues
- Experience with Cisco Nexus switching, VPC, port channels, VLANs, overlays, underlays, high availability, and data center network segmentation.
- Experience with data center migration, capacity planning, resiliency design, and network lifecycle management.
WAN, Routing, and Switching- Deep understanding of BGP, OSPF, EIGRP, MPLS, route redistribution, route filtering, path selection, VRFs, and network segmentation.
- Strong knowledge of enterprise switching, spanning tree, VLAN design, trunking, access-layer design, port security, and high availability patterns.
- Experience supporting WAN circuits, carrier coordination, VPN technologies, site connectivity, branch networking, and routing failover design.
- Strong understanding of TCP/IP, DNS, DHCP, IP addressing, subnetting, NAT, packet flow, and network troubleshooting methods.
- Experience troubleshooting packet loss, latency, routing loops, route instability, asymmetric flows, and application connectivity issues.
Security, Observability, and Operations- Strong understanding of network security controls, access control lists, segmentation, firewall integration, and secure management access.
- Experience with monitoring, logging, telemetry, and troubleshooting platforms such as Splunk, SolarWinds, NetBrain, Wireshark, APIC tools, and packet capture tools.
- Experience with Infoblox DNS, DHCP, and IP address management is strongly preferred.
- Ability to create clear technical documentation, network diagrams, implementation plans, validation plans, rollback plans, and operational runbooks.
- Experience working within change management, incident management, problem management, and production support processes.
Automation and Cloud Networking- Practical experience with network automation using Python, Ansible, Terraform, APIs, or scripting is preferred.
- Experience using automation to support configuration validation, compliance checks, reporting, configuration backup, or repeatable network deployment.
- Working knowledge of AWS networking, including Transit Gateway, Direct Connect, VPC design, Route 53, security groups, network access controls, and hybrid-cloud connectivity.
- Cloud networking experience should support the enterprise network function and is expected to represent approximately 20% of the role.
Preferred Qualifications- CCNP, CCIE, or equivalent enterprise networking certification.
- Cisco ACI hands-on implementation, migration, or operations experience.
- Experience with Cisco Nexus 9K, data center switching, and large-scale enterprise network environments.
- Experience in financial services or other highly regulated industries.
- Experience with SD-WAN, SASE, Zero Trust Network Access, or large-scale network modernization programs.
- AWS Advanced Networking Specialty or AWS Solutions Architect certification is a plus, but not the primary requirement.
Education:• Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience
"Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position."The typical base pay range for this role is as follows:
- New York / New Jersey: $150k - $194k
- Non-New York / New Jersey: $140k - $174k
depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
Our hybrid work schedule is four days on-site and work remotely one day per week.