Job Summary
Network & security SME
Key Responsibilities
Enterprise Network Architecture: Design, implement, and maintain highly scalable core networks using advanced routing protocols (BGP, OSPF, EIGRP). Architect robust campus, data centre, and global WAN infrastructure leveraging SD-WAN technologies.Perimeter & Edge Security Engineering: Design and manage enterprise Next-Generation Firewalls (NGFW) from top-tier vendors (e.g., Palo Alto Networks, Fortinet, Check Point). Define global security policies, configure Intrusion Prevention Systems (IPS/IDS), and oversee SSL/TLS decryption strategies.Zero Trust & Secure Access (SASE/ZTNA): Architect and maintain modern Secure Access Service Edge (SASE) platforms, cloud-delivered firewalls, and Zero Trust Network Access (ZTNA) frameworks to support a highly secure, distributed workforce.Cloud & Hybrid Networking: Design secure public cloud networking structures (AWS VPCs, Azure VNets), leveraging transit gateways, express routes, direct connects, and web application firewall (WAF) distributions.Performance Analysis & Network Troubleshooting: Act as the final escalation tier for deep packet analysis and network traffic anomalies. Utilize tools like Wireshark, NetFlow, and specialized network monitoring tools to rapidly diagnose latency, jitter, and link saturation.Network Automation & Infrastructure as Code: Drive operational efficiency by writing scripts and playbooks via Ansible, Python, or Terraform to automate configuration deployments, device backups, and compliance audits across network hardware
Skill Requirements
Experience: 8+ years of dedicated experience engineering and architecting enterprise network infrastructure and advanced security perimeters.Routing & Switching Mastery: Deep, internal-level understanding of hardware switches, fabrics (e.g., Cisco Nexus, Arista), load balancers (e.g., F5 BIG-IP), and modern network encapsulation protocols (VXLAN, IPsec, GRE).Security Tooling Expertise: Advanced hands-on proficiency with enterprise firewalls, secure web gateways (SWG), network access control platforms (NAC, such as Cisco ISE), and DDoS mitigation frameworks.Protocol-Level Knowledge: In-depth working knowledge of the TCP/IP stack, DNS architecture, DHCP systems, public/private PKI environments, and precise firewall rules tracking.Automation Proficiency: Solid capabilities in leveraging automation tooling (Python, Ansible, Netmiko) to interact with network APIs and device command-line interfaces.
Other Requirements
NA