Position Overview
The client is seeking an experienced Network Infrastructure Engineer to support and modernize the State's enterprise networking environment.
This is a hands-on engineering role responsible for designing, deploying, maintaining, and troubleshooting enterprise network infrastructure across data centers and statewide operations. The engineer will work closely with infrastructure, security, virtualization, wireless, and other technology teams to ensure network services remain reliable, scalable, secure, and aligned with enterprise modernization initiatives.
Key Responsibilities Cisco ACI & Data Center Networking
- Design, implement, and maintain Cisco Nexus platforms operating in ACI mode.
- Configure and manage ACI components, including VRFs, Bridge Domains (BDs), EPGs, ESGs, L3Outs, contracts, and fabric policies.
- Integrate Cisco ACI with Red Hat OpenShift VMM and Isovalent/Cilium container networking.
- Configure and optimize RoCEv2 within ACI environments for high-performance and low-latency workloads.
- Troubleshoot ACI fabric health, faults, endpoint learning, contracts, and multi-tenant segmentation.
- Develop and maintain network architecture documentation, standards, and operational procedures.
Cisco Catalyst & Software-Defined Access- Deploy, configure, and support Cisco Catalyst platforms in enterprise campus environments.
- Design and maintain Cisco Software-Defined Access (SDA) architectures, including wired and wireless fabric environments.
- Manage SDA underlay and overlay networks, policy mapping, authentication integrations, and assurance operations.
- Collaborate with wireless engineering teams to optimize network coverage, performance, and policy enforcement.
Identity-Driven Networking & Security- Configure and administer Cisco Identity Services Engine (ISE).
- Support TACACS+, authentication and authorization policy sets, and endpoint profiling.
- Integrate Cisco Cyber Vision with endpoint profiling, segmentation, and access-control workflows.
- Support Zero Trust initiatives through identity-based segmentation and policy integration across ACI and SDA environments.
Network Visibility & Observability- Deploy and manage ThousandEyes for end-to-end network visibility, routing-path analysis, and performance monitoring.
- Implement and support Cisco Cyber Vision for OT/IoT asset visibility, device classification, and behavioral analysis.
- Manage DNA Spaces for location analytics, telemetry, device behavior, and wireless intelligence.
- Analyze observability data and provide actionable insights to technical leadership.
Core Network Engineering- Troubleshoot complex Layer 2/Layer 3 network issues across enterprise environments.
- Work with VLANs, OSPF, BGP, STP, multicast, TCP/IP, routing, switching, and QoS.
- Design and implement Palo Alto Networks security solutions across enterprise environments.
- Create and maintain architecture diagrams, technical standards, runbooks, and network asset inventories.
- Support modernization initiatives, platform upgrades, procurement activities, and statewide technology programs.
- Perform other related duties as assigned.
Required QualificationsMinimum Experience
- 15+ years of professional experience working with Cisco networking technologies.
Required Technical Skills
- Hands-on production experience with Cisco ACI.
- Strong knowledge of ACI constructs, including:
- VRF
- Bridge Domain (BD)
- EPG
- ESG
- L3Out
- Contracts
- Experience integrating Cisco ACI with OpenShift VMM and Cilium/Isovalent.
- Strong experience with Cisco Catalyst platforms and SDA fabric technologies.
- Experience administering Cisco ISE, including TACACS+ and policy-set-based NAC.
- Working knowledge of ThousandEyes, Cyber Vision, and DNA Spaces, or comparable network visibility/observability technologies.
- Strong understanding of TCP/IP, routing, switching, QoS, and network security.
- Ability to create clear network diagrams, technical documentation, and architectural artifacts.
- Strong analytical, troubleshooting, communication, and collaboration skills.
- Ability to work effectively in fast-paced, mission-critical environments.
Preferred QualificationsThe following qualifications are desirable but not required:
- Cisco certifications such as CCNP Data Center, CCNP Enterprise, CCIE, or equivalent hands-on experience.
- Experience with container networking and virtualization integrations.
- Familiarity with NIST frameworks and state-level cybersecurity requirements.
- Experience with network automation using Python, Ansible, and REST APIs.
- Previous experience supporting state government or large enterprise network environments.
- PCCSA (Palo Alto Networks Certified Cybersecurity Associate).
- PCNSA (Palo Alto Networks Certified Network Security Administrator).