Job SummaryWe are looking for a Systems Engineer II to join our dynamic engineering team. In this role, you will be responsible for integrating systems for broadband devices while designing, implementing, and maintaining a robust infrastructure. The ideal candidate will have expertise in system administration, network architecture, automation, and troubleshooting complex technical issues. You will work closely with cross-functional teams to optimize and enhance system performance, ensuring seamless integration and reliability for cutting-edge broadband technologies.
ResponsibilitiesScope of Work: - Design, deploy, and maintain systems, including SASE/SD-WAN controllers and gateways, branch CPE, and networking components.
- Automate deployment and management of system operations using scripting languages and APIs (e.g., Python, PowerShell, Bash, Ansible).
- Integrate and validate broadband CPE (gateways, modems, Wi-Fi) into the production architecture.
- Integrate and validate B2B SASE/SD-WAN CPE (e.g., Versa) into the production architecture, including ZTP/staging, overlay, and policy.
- Work with Google Cloud to host, network, and operate lab and production-support infrastructure for SASE/SD-WAN (compute, VPC, IAM, storage, and connectivity).
- Deploy and maintain services on Kubernetes (GKE), including configuration, upgrades, monitoring, and troubleshooting of cluster and workload issues.
- Automate lab and operational workflows; monitor SD-WAN/SASE, GCP, and GKE health and close issues through to root cause.
- Partner with development, operations, and security on releases, incidents, and Zero Trust / security-policy hardening.
- Keep topologies, MOPs, change logs, and troubleshooting guides current.
- Monitor and improve network and SASE performance, ensuring high availability and security.
- Troubleshoot CPE, overlay/underlay, software, and network issues, implementing effective solutions.
- Collaborate with development and security teams to support DevOps, Zero Trust, and cybersecurity initiatives.
- Collaborate in the planning and execution of disaster recovery and high-availability strategies for SASE infrastructure.
Collaboration and Documentation: - Maintain up-to-date documentation of network topologies, including traffic flow and interconnectivity.
- Create detailed troubleshooting guides for device and network failures.
- Create change management & deployment logs to track system updates and upgrades to ensure stability.
- Write clear and concise workflow documents, emails, presentations, and thought leadership materials.
Continuous Improvement: - Staying current with new technologies, certifications, and knowledge sharing.
- Proactively share knowledge, mentor junior engineers, and maintain accountability for team performance and production availability.
QualificationsEducation :- Bachelor's in Computer Science, Information Technology, Electrical Engineering, or equivalent experience (Master's a plus).
- 3-5 years in systems, network, or CPE engineering with SD-WAN, SASE, or enterprise WAN/security.
- Hands-on routing/switching/VPN, Zero Trust / secure access, and a SASE platform (Versa strongly preferred).
- Scripting or IaC (Python, Ansible, Terraform, or APIs) and cloud familiarity (AWS, Azure, or GCP).
- Strong troubleshooting, written communication, and cross-team collaboration.
- Docker/Kubernetes, deeper cybersecurity/certs (e.g. NSE, Versa, CCNA/CCNP, ZTNA), additional NMS/SIEM, B2B underlay (fiber/DOCSIS) awareness.
- Excellent communication and collaboration abilities.
Required Technical Skills: - Networking and SD-WAN: Strong foundation in routing, switching, VPN, and SD-WAN deployments (underlay/overlay, WAN/LAN, VLANs, BGP where used). Apply this to branch CPE, path selection, and connectivity into the SASE fabric.
- SASE platform: Hands-on experience with SASE / Versa, including controllers, gateways, CPE, policy, ZTP/staging, and service-provider SASE operations.
- Cloud security and Zero Trust: Implement and maintain secure access, including SWG, CASB, ZTNA, and cloud-based firewall policies. Enforce Zero Trust on user, device, and site access.
- Google Cloud Platform: Hands-on GCP for compute, VPC, IAM, storage, and connectivity used to host, network, and operate SASE/SD-WAN lab and production-support systems. Familiarity with AWS or Azure is a plus.
- Kubernetes (GKE): Deploy, operate, and troubleshoot Kubernetes clusters and workloads on GKE, including configuration, upgrades, monitoring, and cluster/workload networking.
- Broadband CPE and Wi-Fi: Integrate and validate broadband CPE (gateways, modems, Wi-Fi) into the production architecture. Expertise in Wi-Fi (802.11 a/b/g/n/ac/ax) troubleshooting and architecture, and in
- DOCSIS cable modems (provisioning, firmware validation, service bring-up) where SASE rides the broadband underlay.
- Linux / Unix systems: Administer and harden Linux (Ubuntu, CentOS, RHEL) with a focus on availability, scalability, fault diagnosis, and system resources (CPU, memory, storage).
- Scripting and automation: Python, Bash, Ansible, Terraform, or APIs to automate configuration, policy deployment, validation, and monitoring, including GCP (gcloud) and Kubernetes (kubectl, Helm). Follow MOPs for change, rollback, and consistency.
- Monitoring and troubleshooting: Prometheus, Grafana, Splunk (or similar), and SIEMs/NMS as needed, for health, logging, alerting, and isolating network, SASE, CPE, GCP, and GKE faults.
- Documentation: Maintain topologies, troubleshooting guides, change/deployment logs, and clear written/verbal updates.
Pay is competitive and based on a number of job-related factors, including skills and experience. The starting pay rate/range at time of hire for this position in the posted location is $92,534.00 - $152,021.00 / year. The rate/range provided herein is the anticipated pay at the time of hire and does not reflect future job opportunity.