Job Title: Network Architect (CR262)1
Location: VacavilleCA (Stakeholder prefers someone local to the Bay Area. Travel will be as needed depending on projects and/or issues.)
Duration: Long term
Project Background:
This position will act as a primary technical principal and is responsible for delivery of network solutions at an enterprise level. Expertise with network infrastructure technologies such as AWS Cloud Azure Cloud LAN WAN Wireless Security VoIP Video and Data Center. Ideal candidates will have Data Center experience. Candidates for this position must be able to from day one roll up their sleeves and hit the ground running and bring their experience to the team to make the project deployments much smoother.
MUST HAVES:
Technical Knowledge and Skills:
- Expert knowledge of Palo Alto Network Firewall CloudFlare and Prisma Cloud and Cisco ASA.
- Expert knowledge of F5 Load Balancers LTM. GTM WAF and AWS ELB.
- Advanced OSI layer 2 knowledge and practical experience including various flavors of STP ARP QOS etc.
- Comprehensive knowledge of OSI layer 3 networks and protocols including broadcast multicast anycast concepts routing etc.
- Expert knowledge of various routing protocols (BGP OSPF EIGRP) and multihoming Internet circuit configuration
- Proficient knowledge of network security methodologies as a whole including but not limited to: ACLs Stateful firewalls VPNs (tunneling IPsec SSL etc.)
- Fluency with common network admin and monitoring tools such as Rancid OpenNMS Nagios Opmanager Wireshark Nmap Nessus Netflow Sflow etc.
- Administrative scripting skills (Perl UNIX shell scripting)
- Advanced knowledge of Cisco IOS NXOS both Cisco Nexus 1K 2K 5K 7K 9K and nonNexus series switches Cisco routers and other Cisco networking gear.
- Working knowledge of data center related technology and collocation environment.
- Advanced knowledge of MPLS network.
- Working knowledge of Nexus 9K and VPC
- Advanced knowledge of Forcepoint configuration
- Advanced knowledge and experience with Routing Protocols (BGP RIP OSPF etc)
- Working knowledge of Palo Alto Global Protect VPN
- Advanced knowledge and handson experience on Cisco Network Devices automation
- Working knowledge of Ansible or Python scripting for Network automation
- Deep domain expertise in networking network security and public/private clouds
- Working knowledge deploying and maintaining wireless networks
- Expert knowledge of AWS services i.e. EC2 ELB RDS S3 Route53 VPC Cloud formation SSM and Transit gateway
- Working knowledge of deploying and maintaining Microsoft Team PBX VOIP deployments (network side not telecom) SIP Trunking and Five 9 Content Center
- Working knowledge of deploying and maintaining wireless networks
- Working knowledge of managing network service and similar support providers in a client/vendor relationship
Deliverables or Tasks:
- Oversee planning design implementation and operation of network infrastructure projects and participate in the specification of business requirements and implementation plans for technically advanced internetworking solutions.
- Manage implementation of network infrastructure projects from both technical and communication aspects.
- Review network design for network security and other risks during course of projects. Serve as a liaison to vendors and/or thirdparty providers as assigned.
- Provide onsite and remote technical assistance to other resources and to customers.
- Build and document new Infrastructure environments following industry best practices and internal security policies and standards.
- Provide infrastructure design implementation planning deployment support software strategy system troubleshooting performance engineering and optimization maintenance strategy.
- Provide technical guidance knowledge transfer and mentorship to State Fund internal engineering peers as required and lead technical staff responsibilities.
- Establish networking environment by designing system configuration; directing system installation; defining documenting and enforcing system standards.
- Maximize network performance by monitoring performance; troubleshoot network problems and outages; schedule upgrades; collaborate with other teams on network optimization.
- Secure network and server systems by establishing and enforcing policies; define and monitor access.
- Accomplish information systems and organization mission by completing related results as needed.
- Provide 24 by 7 support.
- Report network operational status by gathering prioritizing information.
- Participate in capacity planning and demand forecasting software performance analysis and network tuning.
- Collaborate with cross functional teams to ensure timely delivery of solutions which drive successful business outcomes.
PREFERRED SKILLS:
- Advance handson experience in Palo Alto firewall F5 LTM GTM and WAF.
- Advance handson experience in AWS cloud.
- Extensive handson experience in automation with Ansible CloudFormation or Terraform.
- AWS solution architect certification and CCNP certification required.
- Deep knowledge in Forcepoint.
Desired Qualifications and Certifications:
Bachelors degree in a technical field (e.g. Computer Science IT or similar disciplines).
Equivalent work experience implementing and operating enterprise level data center and/or office networks.
Experience operating in a modern cloud environment such as AWS GCP or Azure or largescale data centers is a plus.
CCNP is the very minimum requirement. CCIE R&S or CCIE data center certifications and AWS certified solutions architect is a big plus.