Design, deploy, maintain enterprise WAN/LAN/campus infrastructures (VLANs, STP, EtherChannel, vPC, HSRP/GLBP) across 100+ global sites.
Lead SD-WAN transformations (Cisco Viptela, Fortinet, VeloCloud) for performance, visibility, security.
Configure routing/switching (BGP, OSPF, EIGRP, VRFs); manage large-scale Wi-Fi, Cisco CUCM/MS Teams.
Implement NGFWs (Cisco Firepower/ASA, Fortinet, Palo Alto), VPNs (IPSec, DMVPN, GRE).
Deploy Zero Trust (Zscaler ZIA/ZPA/ZDX), NAC/ISE with AD/PKI compliance.
Ensure PCI DSS, ITIL, ISO/SOX alignment; support audits.
Hybrid cloud connectivity (Azure vWAN/ExpressRoute, AWS Direct Connect).
Cloud security (NSGs, Azure Firewall, VNET/VPC peering); IPv6 support.
Tools: SolarWinds, PRTG, ManageEngine, Cisco Prime.
Capacity planning, Python/Ansible automation for 1000s of devices.
Lead global teams/projects; mentor engineers; vendor collaboration.
CCIE (Enterprise Infrastructure/Security - Written + Lab) REQUIRED.
1+ years enterprise network/security engineering (global/multi-site preferred).
Hands-on: Cisco, Palo Alto, Fortinet; SD-WAN rollouts, NAC, Zero Trust, DDoS.
Cloud: AWS/Azure; routing mastery (BGP/OSPF); campus networking (VLAN/STP/vPC).
Compliance: PCI DSS/SOX/ITIL; Python/Ansible; troubleshooting/leadership.
Master's IT/CS; global team leadership; retail/banking/gov't experience.