We are looking for a Network Engineer (L2) to manage, troubleshoot, and support enterprise network infrastructure across client and internal environments. The ideal candidate has hands-on experience with firewalls, site-to-site VPNs, routing and switching, wireless infrastructure, and centralized authentication systems, and is comfortable working in a fast-paced, multi-client MSP or enterprise support environment.
Key Responsibilities
- Configure, monitor, and troubleshoot firewalls (e.g., FortiGate, Check Point, Palo Alto, or similar) including policy management, NAT, and security profiles.
- Design, deploy, and troubleshoot IPSec VPN tunnels (site-to-site and remote access), including Phase 1/Phase 2 negotiation issues, route-based and policy-based VPNs.
- Manage routing protocols (OSPF, BGP, static/default routing) across L3 environments.
- Configure and maintain switching infrastructure — VLANs, trunking, STP/RSTP/MSTP, EtherChannel/LACP, and Layer 2 loop prevention.
- Deploy and support WLAN infrastructure, including both physical and virtual wireless LAN controllers, and cloud-managed Wi-Fi (Cisco Meraki).
- Administer AAA services and RADIUS servers for network device and user authentication (e.g., Cisco ISE, FreeRADIUS, or equivalent).
- Perform day-to-day monitoring, incident troubleshooting, and root cause analysis for network outages or degraded performance.
- Maintain network documentation, topology diagrams, and change records.
- Support audits and compliance requirements related to network security and access controls.
- Escalate and coordinate with L3/architecture teams on complex design or capacity issues.
- Participate in on-call rotation / shift-based support as required (typical in MSP environments).
Required Skills & Experience
AreaExpected ProficiencyFirewallsPolicy configuration, NAT, VPN, troubleshooting (FortiGate/Check Point/similar)IPSec VPNSite-to-site & remote access tunnel setup and troubleshootingRoutingOSPF, BGP, static routing, route redistribution basicsSwitchingVLANs, trunking, STP/RSTP, port securityWLANPhysical & virtual wireless controllers, SSID/AP profile managementMerakiCloud-managed switching, WLAN, and/or firewall administrationAAA / RADIUSUser and device authentication, policy enforcement
Preferred Qualifications
- Bachelor's degree in IT, Computer Science, Electronics, or related field.
- Certifications such as CCNA / CCNP, Fortinet NSE, Check Point CCSA/CCSE, or Meraki certifications (a plus, not mandatory).
- Prior experience in an MSP or multi-client support environment.
- Familiarity with ticketing/monitoring tools (e.g., ServiceNow, SolarWinds, PRTG).
- Basic scripting/automation exposure (Python, Ansible) is a plus.
Soft Skills
- Strong troubleshooting and root-cause analysis mindset.
- Ability to work independently and manage multiple client environments/priorities.
- Clear communication for client-facing and internal escalation scenarios.
- Willingness to work in shifts/on-call as per business needs.