Network Infrastructure Engineer

ePATHUSA

  • Clinton, Maryland
  • 4 days ago

    Highlights

    Additionally; Design, deploy, and operate new LDC (Liquor Distribution Center) fabrics, networks, idnetify-driven access systems, and observability platforms. Design, implement, and maintain Cisco Nexus platforms running ACI mode, including VRFs, Bridge Domains, EPGs/ESGs, L3Out, contracts, and fabric policies.

    Numbers & Facts

    LocationClinton, Maryland
    Websitehttps://www.epathusa.net/careers/

    Description

    Seeking a Network Infrastructure Engineer to support and advance the State's enterprise networking environment. Additionally;
    • Design, deploy, and operate new LDC (Liquor Distribution Center) fabrics, networks, idnetify-driven access systems, and observability platforms.
    • Work closely with infrastructure team to ensure the State's network services remain reliable, scalable, secure, and aligned with enterprise goals.
    • Design, implement, and maintain Cisco Nexus platforms running ACI mode, including VRFs, Bridge Domains, EPGs/ESGs, L3Out, contracts, and fabric policies.
    • Integrate ACI with virtualization and container platforms including Red Hat OpenShift VMM and Isovalent/Cilium.
    • Configure and optimize RoCEv2 within the ACI fabric for high-performance, low-latency workloads.
    • Conduct advanced troubleshooting of ACI fabric health, faults, endpoint learning, contracts, and multi-tenant segmentation.
    • Develop and maintain fabric documentation, standards, and operational procedures.
    • Deploy and support Cisco Catalyst platforms within campus environments.
    • Design and maintain Software-Defined Access (SDA) architectures, including SDA Wired Fabric and Fabric-Enabled Wireless.
    • Manage fabric underlay and overlay, policy mapping, authentication integrations, and assurance operations.
    • Collaborate with wireless engineers to optimize coverage, performance, and policy enforcement across SDA. 
    • Configure and administer Cisco Identity Services Engine (ISE) for TACACS+ device administration, authentication and authorization policy sets, and endpoint profiling.
    • Integrate Cyber Vision intelligence into profiling, segmentation, and access control workflows.
    • Support Zero Trust efforts through identity-centric segmentation and policy integration across ACI and SDA fabrics.
    • Deploy and manage ThousandEyes for end-to-end visibility, routing path analysis, and performance monitoring.
    • Implement and support Cisco Cyber Vision for OT/IoT asset visibility, device classification, and behavior analysis.
    • Manage DNA Spaces for location analytics, telemetry ingestion, device behavior, and wireless intelligence.
    • Provide meaningful insights to leadership using data from these observability platforms.
    • Troubleshoot complex L2/L3 network issues across multiple environments including VLANs, OSPF, BGP, STP, and multicast.
    • Designing, and implementing Palo Alto Networks security solutions across enterprise environments.
    • Create and maintain documentation including architecture diagrams, standards, runbooks, and asset inventories.
    • Assist in modernization planning, platform upgrades, procurement processes, and statewide technology initiatives.


    Requirements

    Skills
    Required/Preferred
    Years
    Candidate Experience
    Working with Cisco Networking
    Required
    15

    Hands-on experience with Cisco ACI in production environments.
    Required
    15

    Deep knowledge of ACI constructs (VRF, BD, EPG, ESG, L3Out, contracts).
    Required
    15

    Experience integrating ACI with OpenShift VMM and Cilium/Isovalent.
    Required
    15

    Proficiency with Cisco Catalyst platforms and SDA fabric technologies.
    Required
    15

    Experience administering Cisco ISE including TACACS+ and policy-set based NAC.
    Required
    15

    Strong understanding of ThousandEyes, Cyber Vision, and DNA Spaces or comparable tools.
    Required
    15

    Solid command of core TCP/IP, routing, switching, QoS, and network security fundamentals.
    Required
    15

    Ability to develop clear diagrams, documentation, and architectural artifacts.
    Required
    15

    Strong analytical and communication skills with the ability to work in fast-paced, mission-critical environments.
    Required
    15

    Cisco certifications such as CCNP Data Center, CCNP Enterprise, CCIE, or equivalent experience.
    Preferred


    Hands-on experience with container networking and virtualization integrations.
    Preferred


    Familiarity with NIST frameworks and state-level cybersecurity requirements.
    Preferred


    Experience with network automation tools (Python, Ansible, REST APIs).
    Preferred


    Prior work in state government or large enterprise network environments.
    Preferred


    PCCSA – Palo Alto Networks Certified Cybersecurity Associate Foundational security, NGFW basics, threats, App-ID, and policy.
    Preferred


    PCNSA – Palo Alto Networks Certified Network Security Administrator
    Preferred


    Focuses on NGFW configuration, security profiles, NAT, App-ID, U
    Preferred




    Benefits

    Benefit Package includes: 
    Paid Sick Time
    Insurance for Medical, Dental, Vision and Life Available
    401(k) including Employer Match 
    HSA, Short-term & Long-term Disability Available 
    We are an EEO/Veterans/Disabled employer


    Similar Jobs

    See more jobs