Sr. Network Engineer
We are looking for a hands-on SD‑WAN / WAN & Firewall Engineer to support and operate large-scale enterprise network environments spanning campuses, clinics, and hospital locations. This role focuses on day-to-day SD‑WAN and firewall stability, BGP-based routing, internet edge security, incident response, lifecycle management, and automation, with exposure to platforms such as VMware VeloCloud, Cisco SD‑WAN (Viptela), Fortinet Secure SD‑WAN/Firewalls, Aruba EdgeConnect, Palo Alto, or similar technologies.
Key Responsibilities
- Provide L2 operational support for WAN, SD‑WAN, and firewall services across geographically distributed sites using platforms such as VMware VeloCloud (preferred), Cisco SD‑WAN, Fortinet Secure SD‑WAN/Firewalls, Aruba EdgeConnect, Palo Alto, or equivalent.
- Participate in On‑Call rotations (including weekends/after hours as required) to restore WAN, internet edge, and firewall-related outages within SLA.
- Monitor WAN, SD‑WAN, and firewall health using tools such as SolarWinds, VeloCloud Orchestrator, Cisco vManage, FortiManager/FortiAnalyzer, Panorama, and act on performance, stability, and compliance issues.
- Own internet edge connectivity and security, including site‑to‑site VPNs, NAT, ACLs, firewall policies, and redundancy using dual ISPs and HA designs.
- Troubleshoot Layer‑3 routing and security issues, including BGP peering, routing convergence, firewall policy behavior, failover, packet loss, latency, jitter, and path selection.
- Support SD‑WAN overlay/underlay and firewall integration, including tunnel stability, traffic steering, and application‑aware routing and security policies.
- Drive DPMO and service reliability improvements by identifying recurring WAN/firewall defects and implementing preventive fixes.
- Execute WAN and firewall Get Well initiatives, including EOL/EOS router and firewall refresh programs.
- Perform IOS, SD‑WAN edge, and firewall software upgrades, and assist with hardware lifecycle management.
- Plan and execute maintenance window activities, including WAN cutovers, SD‑WAN turn‑ups, firewall migrations, ISP transitions, and post‑change validation.
- Create and follow Method of Procedure (MOP) documents and coordinate with ISPs, carriers, firewall vendors, and field engineers.
- Ensure configuration standardization and compliance across WAN routers, SD‑WAN edges, and firewall platforms.
- Support incident, problem, and RCA processes, with clear documentation and stakeholder communication.
- Work closely with LAN, Wireless, Security, Voice, and Service Desk teams to ensure end‑to‑end connectivity and secure application reachability.
- Identify opportunities to automate WAN, SD‑WAN, and firewall operations using Python, Ansible, or similar tools.
What Would Your Day Look Like?
- Review WAN/SD‑WAN/firewall dashboards, ISP status, BGP adjacencies, VPN tunnels, and alerts.
- Handle incidents involving ISP failures, BGP instability, SD‑WAN tunnel drops, firewall policy or NAT issues, and application performance problems.
- Proactively monitor routing stability, security posture, and failover/path optimization behavior.
- Work with ISPs, telcos, and site teams to resolve circuit, firewall, and last‑mile issues.
- Analyze recurring defects and contribute to continuous reliability and security improvements.
- Execute planned maintenance such as IOS upgrades, SD‑WAN and firewall upgrades, new site turn‑ups, and hardware refreshes.
- Prepare and execute MOP‑based changes, perform validations, and share post‑change reports.
- Participate in On‑Call support, providing timely restoration, updates, and RCAs.
- Develop or enhance automation scripts to reduce manual WAN/SD‑WAN/firewall operational effort.
Who Are We Looking For?
- Bachelor’s Degree (or equivalent) in Engineering / Technology.
- 3–6 years of enterprise networking experience, including:
- 3+ years of hands‑on WAN / SD‑WAN operations
- Experience with router and firewall lifecycle / EOL‑EOS activities
- 2+ years of BGP‑based WAN routing
- Hands‑on exposure to SD‑WAN and firewall platforms such as VMware VeloCloud (preferred), Cisco SD‑WAN, Fortinet, Aruba/Silver Peak, Palo Alto, or similar
- Strong understanding of WAN and firewall fundamentals: BGP, QoS, NAT, ACLs, IP SLA, VPNs, ISP redundancy, and HA designs.
- Experience supporting large, distributed enterprise WAN and internet edge environments.
- Comfortable troubleshooting routing, SD‑WAN overlay/underlay, firewall policy, VPN, ISP, and application path issues.
- Proactive mindset with ability to identify recurring issues and improve reliability and security.
- Experience executing planned maintenance, upgrades, and refresh programs.
- Disciplined approach to configuration standards and documentation.
- Willingness to participate in On‑Call rotations.
- Exposure to automation using Python, Ansible, or similar tools is strongly preferred.