Responsibilities
- Design, deploy, and maintain high-performance and resilient network infrastructures to meet business needs.
- Implement SASE solutions to enhance network security and ensure secure access across various environments.
- Configure and manage BGP routing for optimal network performance and reliability.
- Design, deploy, and operate Layer 3 leaf-spine (Clos) data center fabric architectures for predictable, low-latency, non-blocking connectivity between compute and storage resources.
- Implement and maintain underlay routing (BGP-based) and overlay technologies (VXLAN/EVPN) to support scalable, multi-tenant data center fabrics.
- Support data center migrations, cutovers, hardware refresh, and fabric expansion projects with minimal service disruption.
- Configure, manage, and monitor firewalls, including rule sets, VPNs, and threat prevention features.
- Conduct regular firewall audits and assessments to ensure compliance with security policies and industry standards.
- Design and implement SD-WAN solutions to optimize connectivity and performance across multiple locations.
- Monitor and manage SD-WAN environments, addressing issues or performance bottlenecks.
- Integrate and manage network services within CSP environments (e.g., AWS, Azure, GCP) for secure and efficient cloud connectivity.
- Implement and manage VPNs, VPCs, and other cloud networking components.
- Configure and manage reverse proxy technologies to optimize and secure web traffic, ensuring proper load balancing and protection for backend servers.
- Monitor reverse proxy performance and troubleshoot issues to ensure reliable application delivery.
- Apply IT security best practices across network infrastructure, including system/device hardening, vulnerability management, and secure configuration baselines.
- Work closely with the security team on Zero Trust network access principles, network segmentation, and threat detection.
- Implement and maintain intrusion detection and prevention systems (IDS/IPS).
- Support security audits, vulnerability/penetration test remediation, and compliance reporting against industry standards.
- Provide advanced troubleshooting for network issues, identifying root causes and implementing effective solutions.
- Collaborate with other IT teams to resolve complex technical problems and support network-related incidents.
- Maintain detailed documentation of network configurations, changes, and procedures.
- Generate regular reports on network performance, security incidents, and project progress for management review.
- Stay updated on the latest industry trends and technologies to improve network efficiency, security, and performance.
- Propose and implement network upgrades and enhancements to meet evolving business needs.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- 5–8 years of experience in network engineering with a strong focus on SASE, BGP, Firewalling, SD-WAN, CSP operations, and Reverse Proxy technologies, including hands-on experience operating data center network fabrics (spine-leaf / Clos architectures).
- Proficient in configuring and managing SASE solutions and technologies.
- In-depth knowledge of BGP and other routing protocols.
- Hands-on experience with firewall technologies (e.g., Palo Alto, Fortinet).
- Strong understanding of SD-WAN technologies and best practices.
- Experience with network operations in cloud environments such as AWS, Azure, or GCP.
- Expertise in configuring and managing reverse proxy technologies (e.g., NGINX, HAProxy).
- Strong hands-on expertise in data center network architecture: Layer 3 leaf-spine (Clos) fabric design, and underlay/overlay (BGP EVPN-VXLAN) technologies.
- Solid IT Security background: vulnerability management, security hardening, Zero Trust principles, IDS/IPS, and familiarity with security compliance frameworks.
- General working knowledge of Aruba fabric switching (AFC-managed) and Cisco Meraki (SD-WAN, switching, wireless) — comfortable with day-to-day administration and troubleshooting; deep vendor-specialist expertise not required.
- English: mandatory. Professional proficiency, both written and spoken, to effectively collaborate with global teams and communicate with stakeholders.
- Strong self-learning capabilities.
- Excellent problem-solving and analytical skills.
- Strong communication skills, with the ability to explain complex technical concepts to non-technical stakeholders.
- Ability to work independently and as part of a collaborative team.
Nice to Have
- Relevant certifications (e.g., CCNA, CCNP, CISSP) are a plus.
- Cisco Certified Network Professional (CCNP)
- Certified Information Systems Security Professional (CISSP)
- AWS Certified Advanced Networking – Specialty
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- Relevant reverse proxy certifications or experience
- Cisco CCNP Data Center (350-601 DCCOR) or CCIE Data Center – data center fabric design and operations
- Juniper Networks Certified Internet Professional – Data Center (JNCIP-DC) or JNCIE-DC
- Arista Certified Engineer (ACE) – data center switching/fabric
- CompTIA Security+ – baseline IT security certification
Other
- English: mandatory. Professional proficiency, both written and spoken, to effectively collaborate with global teams and communicate with stakeholders. Candidates without a professional working level of English will not be considered.
- This role requires daily collaboration with a globally distributed team and stakeholders across Europe, the US, and India.