OculusIT is a fast-growing global technology services company focused exclusively on supporting Higher Education institutions across the United States. Headquartered in Chicago with a Global Delivery Centre in Gurgaon, the company partners with universities and colleges to deliver Managed IT Infrastructure, Cybersecurity, ERP solutions, and Cloud & Digital Transformation services.
What makes OculusIT unique is its purpose-driven mission of enabling institutions to provide secure, reliable, and modern technology environments for students, faculty, and academic operations.
The organization has demonstrated strong growth, achieving 40% growth last year with a projected 34% growth in 2026, creating excellent career advancement opportunities. Employees benefit from Learning & Development programs, mentorship, Internal Job Postings, and cross-functional growth paths.
Backed by Avathon Capital since April 2025, OculusIT continues to expand its service capabilities and strengthen its position in Higher Education IT services. The company also offers long-term project stability through multi-year partnerships with universities.
Its people-first culture emphasizes approachable leadership, transparent communication, collaboration, and work-life balance. With improved employee engagement, strong retention, and a clear long-term vision, OculusIT offers professionals a stable and meaningful platform to grow while contributing to the future of education through technology.
Job Description
Principal Network Engineer
Position Description:
OculusIT is seeking a hands‑on Principal Network Engineer operating at L3/L4 level to provide end‑to‑end technical ownership for complex enterprise network, network‑security and communications environments. The role is responsible for architecture, engineering, implementation, advanced troubleshooting, modernization, automation and operational excellence across LAN, WAN, data center, SD‑WAN, Internet edge, SASE/Zero Trust, cloud connectivity, firewalls and enterprise telephony.
This is a senior technical engineering role, not a people‑management‑only position. The successful candidate must be comfortable troubleshooting at protocol, packet, platform and policy level, leading major incidents, reviewing architecture and engineering work, and personally executing complex changes. The candidate must also have previously led a team of network/technology engineers as a Technical Lead, Lead Network Engineer, Principal Engineer or equivalent.
The role has particular depth in Cisco enterprise networking and Palo Alto Networks security platforms, with strong hands‑on Zscaler/SASE experience and practical automation using Python, Ansible and APIs.
Responsibilities and Duties:
- Act as the highest technical escalation point for complex L3/L4 network, security, SD‑WAN, data‑center, cloud‑connectivity and telephony incidents.
- Own enterprise network architecture across campus, branch, WAN, data center, Internet edge, cloud and remote‑access environments.
- Design and implement secure, resilient, highly available network solutions and lead complex migrations, upgrades and technology refreshes.
- Lead P1/P2 technical response, packet‑level troubleshooting, RCA, problem management and permanent corrective actions.
- Provide technical direction to L2/L3 engineers, review designs and configurations, and lead engineering work during major incidents and maintenance windows.
- Develop HLD/LLD, implementation plans, rollback plans, standards, SOPs, runbooks, diagrams and operational documentation.
- Drive network automation, configuration compliance, provisioning, validation and remediation through Python, Ansible, APIs and infrastructure‑as‑code practices.
- Partner with Security, Cloud, Infrastructure, Service Desk, Architecture and Application teams for end‑to‑end service delivery.
- Lead technical engagements with Cisco, Palo Alto Networks, Zscaler, Fortinet, carriers/ISPs, telecom providers and other strategic vendors.
- Evaluate emerging enterprise networking, SASE, Zero Trust, observability, automation and AI‑assisted operations technologies and recommend adoption where justified.
Network Infrastructure Management
- Design, deploy, administer, and maintain enterprise network infrastructure across campus, data center, and multi‑site environments.
- Manage and support LAN, WAN, WLAN, VPN, MPLS, Internet Edge, and SD‑WAN solutions.
- Configure and maintain Cisco routers, switches, wireless controllers, and access points.
- Monitor network performance, capacity, utilization, and availability while recommending improvements and optimizations.
- Perform network lifecycle management including upgrades, hardware refreshes, EOS/EOL remediation, and technology modernization.
- Implement high‑availability network architectures and redundancy solutions.
- Support network segmentation, QoS policies, routing protocols, and performance optimization initiatives.
Cisco Enterprise Networking – Deep Technical Requirement
- Expert‑level hands‑on Cisco routing and switching, with CCNP Enterprise/CCNP Security‑level knowledge required.
- Cisco Catalyst 9000 family, IOS‑XE, Catalyst Center, campus LAN architecture, high availability and network assurance.
- Cisco Nexus platforms and data‑center switching, including vPC, port‑channels, VLAN/VRF architecture and operational troubleshooting.
- Advanced routing: BGP, OSPF, route redistribution, route filtering, policy‑based routing, ECMP, summarization, VRF/VRF‑Lite and IPv6.
- Layer 2: VLANs, 802.1Q, STP/RSTP/MST, BPDU protection, root guard, loop prevention, LACP, EtherChannel and storm control.
- Gateway and HA technologies including HSRP/VRRP and resilient default‑gateway design.
- QoS design and troubleshooting for voice, video, business‑critical applications and WAN traffic.
- Cisco Catalyst SD‑WAN: architecture, controllers, transport, overlays, segmentation, centralized policies, application‑aware routing, QoS, security and troubleshooting.
- Data‑center fabric experience with VXLAN/EVPN, BGP underlay/overlay, leaf‑spine design and EVPN multihoming is highly desirable.
- Cisco Catalyst Center for device onboarding, configuration, assurance, inventory, compliance, topology and automation.
- Cisco ISE/NAC, 802.1X, RADIUS/TACACS+, profiling, guest access, posture concepts and identity‑based segmentation.
- Deep troubleshooting using CLI, packet captures, logs, routing tables, counters, telemetry, SPAN/ERSPAN and protocol analysis.
- Experience with Cisco TAC cases, bug analysis, software lifecycle, IOS‑XE/NX‑OS upgrades and production change planning.
Palo Alto Networks – Deep Technical Requirement
- Strong production experience administering and troubleshooting Palo Alto Networks Next‑Generation Firewalls, preferably across enterprise HA deployments.
- PAN‑OS fundamentals and advanced administration including zones, interfaces, virtual routers, security policies, NAT, PBF, routing, objects, services, tags and policy lifecycle.
- Panorama administration including device groups, templates, shared policies/objects, centralized policy governance, configuration management and commit workflows.
- Application‑ID, User‑ID, Content‑ID, URL Filtering, Anti‑Spyware, Vulnerability Protection, WildFire and Security Profiles.
- GlobalProtect architecture and troubleshooting, including gateway/portal concepts, authentication, HIP‑based policy and remote‑access connectivity.
- IPsec/SSL VPN, site‑to‑site VPN, tunnel monitoring, routing interaction and failover troubleshooting.
- High Availability including active/passive design, HA state synchronization, failover, link/path monitoring and maintenance procedures.
- Advanced troubleshooting using session tables, traffic/threat/system logs, packet capture, flow troubleshooting, routing information and dataplane/control‑plane indicators.
- Policy optimization, rulebase hygiene, least‑privilege design, segmentation, shadow‑rule identification, object cleanup and security‑policy lifecycle management.
- PAN‑OS upgrades, content updates, vulnerability remediation, configuration backup, rollback and production change control.
- Strong understanding of Panorama‑led enterprise firewall management and controlled deployment across multiple firewalls/sites.
- Hands‑on API automation is expected: PAN‑OS REST/XML APIs, Python/Ansible or equivalent automation for objects, policies, validation, reporting and controlled configuration workflows.
Network Security & Fortinet Administration
- Design, deploy, and manage Fortinet security solutions including FortiGate Firewalls, FortiManager, and FortiAnalyzer.
- Configure and manage security policies, NAT rules, IPS, IDS, Application Control, Web Filtering, and UTM capabilities.
- Implement and maintain IPSec VPN and SSL VPN solutions for secure connectivity.
- Conduct firewall rule reviews, policy audits, compliance assessments, and security optimization activities.
Enterprise Telephony & Communications
- Hands‑on responsibility for enterprise IP telephony and unified communications infrastructure in a production environment.
- Cisco Unified Communications Manager (CUCM), Cisco IP phones, SIP, RTP, SRTP, dial plans, route patterns, translation patterns, partitions, calling search spaces and voice gateways.
- Cisco Unity Connection, voicemail, conferencing and enterprise calling integrations where applicable.
- SIP trunking, E1/PRI or SIP carrier connectivity, SBC concepts, PSTN integration, number management and carrier troubleshooting.
- Voice VLAN, QoS, DSCP marking, LLQ, jitter, latency, packet loss and end‑to‑end voice‑quality troubleshooting.
- Experience with Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA).
- Zscaler Client Connector, traffic forwarding, GRE/IPsec tunnels, PAC files, policy troubleshooting and user/application connectivity.
- Zero Trust and SASE architecture, least‑privilege access, identity‑aware policy, segmentation and secure Internet/private application access.
- Experience integrating Zscaler with enterprise identity, endpoint, firewall, SD‑WAN and branch architectures.
- Hands‑on AWS and/or Azure networking including VPC/VNet, routing, peering, transit architectures, VPN and Direct Connect/ExpressRoute.
- Hybrid connectivity between enterprise data centers, branches, cloud workloads and security platforms.
- Cloud network security, route control, segmentation, DNS, load‑balancing concepts and identity integration.
Automation, Network‑as‑Code & AIOps
- Understanding of Python for network automation, API integration, validation, configuration generation, telemetry processing and operational tooling.
- Understanding of Ansible for provisioning, configuration management, compliance, backup, validation and remediation across multi‑vendor infrastructure.
- REST APIs and SDKs for Cisco Catalyst Center, Cisco SD‑WAN, Palo Alto/Panorama, Zscaler and other platforms.
- Ansible, Terraform and Git‑based infrastructure‑as‑code experience preferred.
- CI/CD concepts for controlled network automation, including source control, peer review, testing, approval gates and rollback.
- Automate repetitive operations such as device onboarding, configuration backup, compliance validation, policy checks, health checks, certificate checks and evidence collection.
Technical Leadership
- Prior experience leading a team of network/technology engineers in an enterprise, MSP or systems‑integrator environment is required.
- Lead a technical team through prioritization, incident response, engineering delivery, knowledge management and continuous improvement.
- Remain hands‑on while providing technical direction and escalation support to engineers.
- Conduct architecture/configuration reviews and establish engineering standards and troubleshooting methods.
- Coach L2/L3 engineers toward advanced routing, security, automation and architecture capability.
- Coordinate internal teams and vendors during P1/P2 incidents, major migrations and maintenance windows.
- Communicate complex technical issues clearly to senior management and customer/CIO stakeholders.
Major Incident, Problem & Change Management
- Lead P1/P2 incidents involving network, security, WAN, data center, cloud, telephony or Internet services.
- Use structured incident command, technical triage, evidence collection, restoration and stakeholder communication.
- Perform packet‑level and protocol‑level analysis and produce technically rigorous RCA documents.
- Lead high‑risk changes using peer review, pre‑change validation, implementation checklists, maintenance‑window controls and tested rollback procedures.
- Drive problem management to eliminate repeat incidents rather than relying on repeated operational workarounds.
Preferred Certifications
- CCNP Enterprise / CCNP Security; CCIE Enterprise Infrastructure or Security preferred.
- Palo Alto PCNSE or current equivalent Palo Alto certification.
- Zscaler certification(s) or demonstrable production ZIA/ZPA expertise.
- Fortinet FCP/FortiGate certification where applicable.
- AWS Advanced Networking Specialty and/or Azure Network Engineer Associate.
- ITIL Foundation or higher.
Principal‑Level Success Measures
- Consistent technical ownership and resolution of complex P1/P2 incidents with strong RCA and measurable recurrence reduction.
- Safe delivery of network, firewall, SASE, SD‑WAN, cloud and telephony migrations with documented rollback and minimal customer impact.
- Measurable reduction in repetitive manual operations through governed automation and API‑driven workflows.
- Improved network resilience, security posture, observability and operational consistency.
- Improved L2/L3 engineering capability through technical leadership, reviews, mentoring and knowledge transfer.
- High‑quality architecture, documentation, standards and runbooks suitable for a managed‑services enterprise environment.
Required Experience & Qualifications
- 16+ years of progressive enterprise networking experience with significant L4 responsibility.
- Demonstrated experience as Principal Network Engineer, L4 Engineer, Network Architect, Network Solution Engineer or equivalent.
- CCNP Enterprise / CCNP Security or equivalent advanced Cisco expertise required; CCIE strongly preferred.
- Proven technical‑team leadership experience.
- Excellent customer‑facing communication, documentation and incident‑management capability.
Required Skills
AWS Advanced Networking Specialty NetworkSecurity SD‑WAN ZERO Trust NetworkOperations Cisco Unified Communications Manager CCIE CCNP Cisco Enterprise Networking Palo Alto PCNSE