Job Summary
Job Description – L3 Network Engineer (Hybrid Networking) Role Summary The L3 Network Engineer is responsible for designing, implementing, operating, and optimizing enterprise-grade on‑premises and cloud network infrastructures. The role requires deep expertise in routing, switching, SD‑WAN, wireless, NAC/802.1X, and hybrid cloud networking across Azure and GCP environments. The engineer will act as a technical escalation point (L3), lead architecture reviews, support complex incidents, and drive continuous improvement through standardization and automation. Key Responsibilities 1. Architecture Ownership & Design Authority Own and validate LAN / WAN / SD‑WAN / Wireless architectures across enterprise environments Act as design authority for routing protocols (BGP, OSPF, DMVPN) Define network segmentation, routing policies, and resiliency models Review and approve HLDs / LLDs created by projects or L2 engineers Ensure designs align with scalability, resiliency, and security standards 2. L3 Operations & Escalation Ownership Serve as final escalation point (L3) for complex incidents and chronic issues Perform deep‑dive root cause analysis (RCA) for Sev‑1 / Sev‑2 incidents Define permanent corrective and preventive actions (PCA) Own problem records and ensure recurrence prevention Drive resolution across network, cloud, and security teams 3. On‑Prem Network Engineering (Primary Skill Ownership) Enterprise Routing & Switching (LAN/WAN) SD‑WAN architecture, failover, and traffic engineering Wireless (Wi‑Fi) design, optimization, and troubleshooting 802.1X authentication for wired and wireless access Network Access Control (NAC) design and enforcement MPLS and enterprise WAN connectivity models 4. Cloud & Hybrid Networking (Secondary but Mandatory for E3.x) Azure Networking Design and support: ExpressRoute vWAN VNETs, NSGs, UDRs BGP‑based hybrid routing Troubleshoot complex on‑prem ↔ Azure connectivity issues GCP Networking Design and support: VPCs, subnets Cloud routing & firewall rules VPN / Interconnect Support multi‑cloud and hybrid connectivity patterns 6. Documentation & Knowledge Management Own and maintain: Network standards HLD / LLD SOPs, runbooks, and troubleshooting guides Ensure documentation is audit‑ready and operationally usable Drive standardization across environments 7. Team Enablement & Technical Mentorship Provide technical mentorship to L1 and L2 engineers Review L2 solutions and guide corrective improvements Enable cross‑skilling and capability uplift Act as technical reviewer for training content and SOPs Skill Matrix Primary Skills (Must Have) LAN / WAN enterprise networking BGP, OSPF, DMVPN SD‑WAN Wireless (Wi‑Fi) 802.1X & NAC MPLS Secondary Skills (Expected for L3) Azure Networking (ExpressRoute, vWAN, VNETs, NSGs) GCP Networking (VPC, routing, VPN/Interconnect) Hybrid cloud connectivity Network monitoring & diagnostics tools Experience & Qualification 8–12+ years in enterprise networking roles Minimum 2–3 years in L3 / design / escalation role Proven experience in hybrid (Onprem + cloud) networks Certifications (preferred, not mandatory): CCNP / CCIE Azure Network Engineer Associate GCP Professional Cloud Network Engineer Fortinet NSE 5 – FortiNAC‑F Administrator Behavioral & Professional Expectations High ownership and accountability Structured problem‑solving mindset Strong documentation discipline Ability to operate under ambiguity and pressure Clear communication with stakeholders and leadership
Key Responsibilities
Key Responsibilities 1. Architecture Ownership & Design Authority Own and validate LAN / WAN / SD‑WAN / Wireless architectures across enterprise environments Act as design authority for routing protocols (BGP, OSPF, DMVPN) Define network segmentation, routing policies, and resiliency models Review and approve HLDs / LLDs created by projects or L2 engineers Ensure designs align with scalability, resiliency, and security standards 2. L3 Operations & Escalation Ownership Serve as final escalation point (L3) for complex incidents and chronic issues Perform deep‑dive root cause analysis (RCA) for Sev‑1 / Sev‑2 incidents Define permanent corrective and preventive actions (PCA) Own problem records and ensure recurrence prevention Drive resolution across network, cloud, and security teams 3. On‑Prem Network Engineering (Primary Skill Ownership) Enterprise Routing & Switching (LAN/WAN) SD‑WAN architecture, failover, and traffic engineering Wireless (Wi‑Fi) design, optimization, and troubleshooting 802.1X authentication for wired and wireless access Network Access Control (NAC) design and enforcement MPLS and enterprise WAN connectivity models 4. Cloud & Hybrid Networking (Secondary but Mandatory for E3.x) Azure Networking Design and support: ExpressRoute vWAN VNETs, NSGs, UDRs BGP‑based hybrid routing Troubleshoot complex on‑prem ↔ Azure connectivity issues GCP Networking Design and support: VPCs, subnets Cloud routing & firewall rules VPN / Interconnect Support multi‑cloud and hybrid connectivity patterns 6. Documentation & Knowledge Management Own and maintain: Network standards HLD / LLD SOPs, runbooks, and troubleshooting guides Ensure documentation is audit‑ready and operationally usable Drive standardization across environments 7. Team Enablement & Technical Mentorship Provide technical mentorship to L1 and L2 engineers Review L2 solutions and guide corrective improvements Enable cross‑skilling and capability uplift Act as technical reviewer for training content and SOPs
Skill Requirements
Skill Matrix Primary Skills (Must Have) LAN / WAN enterprise networking BGP, OSPF, DMVPN SD‑WAN Wireless (Wi‑Fi) 802.1X & NAC MPLS Secondary Skills (Expected for L3) Azure Networking (ExpressRoute, vWAN, VNETs, NSGs) GCP Networking (VPC, routing, VPN/Interconnect) Hybrid cloud connectivity Network monitoring & diagnostics tools Experience & Qualification 8–12+ years in enterprise networking roles Minimum 2–3 years in L3 / design / escalation role Proven experience in hybrid (Onprem + cloud) networks Certifications (preferred, not mandatory): CCNP / CCIE Azure Network Engineer Associate GCP Professional Cloud Network Engineer Fortinet NSE 5 – FortiNAC‑F Administrator
Other Requirements
NA