Senior Network Engineer - Global Infrastructure
Job Description Location - Vadodara , Gujrat
Reporting to - Group Head of IT Infrastructure & Cybersecurity
Experience - 7 to 10 Years
Full-time, highly hands-on individual contributor Timings
UK Shift hours with 5 days working ( Saturday as per business requirement )
Role Purpose
The Senior Network Engineer Global Infrastructure will be the Groups senior hands-on network subject-matter expert, responsible for the design, implementation, security, operation, monitoring, troubleshooting and continuous improvement of B&S Groups global network infrastructure.
The role covers enterprise LAN, WAN, wireless, Internet connectivity, firewalls, VPNs, SD-WAN, routing, switching, network security and cloud connectivity across offices, warehouses, manufacturing facilities and server environments.
Key Responsibilities
1. Network Architecture, Design & Advisory
- Act as the senior technical authority and SME for enterprise networking across the Group.
- Advise on network architecture, technology standards, design options, risk and the longer-term network roadmap.
- Design resilient LAN, WAN, wireless, Internet, hybrid-cloud and inter-site connectivity solutions.
- Produce and maintain High-Level Designs (HLD), Low-Level Designs (LLD), topology diagrams, IP plans, VLAN plans, firewall matrices and implementation documentation.
- Design routing, segmentation, security zones, resilience and failover patterns for critical services.
- Review proposed infrastructure and application solutions to ensure the network design is secure, supportable, resilient and appropriate for business requirements.
- Evaluate new technologies, run Proofs of Concept and provide evidence-based recommendations.
2. Global WAN & Connectivity
- Own and support point-to-point circuits, MPLS, Dedicated Internet Access (DIA), Internet breakout, SD-WAN, site-to-site VPNs and remote-access connectivity.
- Design and maintain primary, secondary and tertiary connectivity paths with tested failover.
- Monitor bandwidth, latency, jitter, packet loss, utilisation and application impact across WAN services.
- Troubleshoot complex inter-site issues and work directly with ISPs, carriers and support partners during incidents and implementations.
- Review capacity and service performance and recommend optimisation or upgrades before business impact occurs.
- Maintain baseline network performance metrics and use before/after evidence to validate network changes.
3. Firewalls & Network Security
- Own day-to-day engineering and operational administration of FortiGate firewalls and associated network security controls.
Senior Network Engineer Global Infrastructure
- Design, configure, review and maintain firewall policies, NAT, IPsec VPNs, remote access, routing, HA and security profiles.
- Review firewall rules, hit counts and utilisation regularly; remove obsolete, duplicate or overly permissive rules.
- Maintain secure configuration, firmware currency, backups and recovery procedures for network security devices.
- Design and maintain network segmentation across users, servers, applications, warehouses, manufacturing/OT, guest, management and other security zones.
- Implement least-privilege network access and secure administrative access using appropriate controls such as MFA, RADIUS/TACACS+, 802.1X, certificate-based authentication or NAC where applicable.
- Support IDS/IPS, DNS/web filtering, application control, WAF/load-balancer connectivity and secure remote access.
- Harden routers, switches, firewalls, wireless platforms and management interfaces and remediate network vulnerabilities.
- Work closely with the Cyber Security Engineer on secure-by-design reviews, incidents, penetration-test findings, vulnerability remediation and security improvements.
- Provide technical network-security recommendations and personally implement approved controls.
4. LAN, Routing & Switching
- Design, configure and troubleshoot Layer 2 and Layer 3 switching, VLANs, trunks, STP/RSTP, LACP, ACLs, QoS and inter-VLAN routing.
- Understand and support VXLAN-based network overlays and segmentation, including the use of VXLAN to extend Layer 2 connectivity and support scalable network designs across enterprise or data-centre environments.
- Knowledge of EVPN/VXLAN architectures would be advantageous.
- Configure and troubleshoot static and dynamic routing, including OSPF and BGP where required.
- Own DNS, DHCP relay and core network services as they relate to connectivity and network design.
- Diagnose complex switching, routing and connectivity issues independently without relying solely on suppliers.
5. Wireless, Warehouse & Manufacturing Networking
- Design and support enterprise wireless networks across offices, warehouses and manufacturing locations.
- Support Juniper Mist or equivalent platforms, including RF planning, AP placement, roaming, channel use, coverage, capacity and interference analysis.
- Design secure wireless onboarding for corporate, guest, warehouse, operational and IoT devices using appropriate identity and access controls.
- Optimise warehouse connectivity for handheld scanners and operational devices, with particular attention to roaming, latency, jitter, availability and resilience.
- Review segmentation and security of warehouse/manufacturing connectivity and ensure operational changes are properly tested and risk assessed.
6. Monitoring, Analytics & Proactive Operations
- Own proactive monitoring and performance visibility for the network estate using Zabbix, Wazuh and other appropriate tools.
- Monitor availability, interfaces, circuits, latency, packet loss, VPN status, firewall health, wireless health, authentication patterns and capacity trends.
- Use SNMP, syslog, NetFlow/IPFIX/sFlow or equivalent traffic visibility where appropriate to identify top talkers, abnormal traffic and emerging bottlenecks.
- Tune thresholds, reduce alert noise and develop useful technical and management dashboards.
- Investigate abnormal behavior and degradation before it becomes a service-affecting incident.
- Develop one-page operational views and meaningful metrics for management and executive reporting where required.
7. Troubleshooting & Incident Resolution
- Act as the senior escalation point for complex network and connectivity incidents.
- Troubleshoot end to end across clients, wireless, VLANs, switches, routing, firewalls, VPNs, WAN, DNS, DHCP, servers, reverse proxies, load balancers and applications.
- Use Wireshark, packet capture, SPAN/port mirroring, traceroute, routing tables, firewall logs, interface counters and performance telemetry to isolate root cause.
- Work with Infrastructure, Applications, Cybersecurity and suppliers to resolve cross-platform issues.
- Drive permanent corrective action for recurring problems rather than relying on temporary workarounds.
Senior Network Engineer Global Infrastructure
8. Projects, Change & Technical Delivery
- Deliver network projects from initial requirement through assessment, design, HLD/LLD, risk review, implementation, testing, rollback, hypercare and BAU handover.
- Personally implement technical changes while delegating defined tasks to other engineers where appropriate.
- Technically validate network and firewall change requests and ensure higher-risk changes follow the appropriate change and approval process.
- Support strategic projects including WAN redesign, SD-WAN, FortiGate HA, segmentation, NAC, wireless improvements, centralised management and site connectivity.
- Ensure business-critical changes have clear success criteria, rollback plans and post-change validation.
9. Configuration Management, Resilience & Lifecycle
- Maintain automated and secure network configuration backups with clear version history and recovery procedures.
- Develop configuration standards, templates and baseline controls to improve consistency across sites.
- Maintain lifecycle visibility for network hardware, firmware, licensing, support status, end-of-life/end-of-support dates and replacement requirements.
- Design appropriate management networks, console access and out-of-band recovery for critical network infrastructure where required.
- Plan and conduct resilience testing, including circuit, firewall, switch, VPN and failover scenarios, and record recovery results and lessons learned.
10. Cloud & Hybrid Networking
- Support and advise on networking across Microsoft Azure, Google Cloud Platform and DigitalOcean environments as required.
- Understand VNet/VPC design, routing, gateways, VPN connectivity, public/private addressing, load balancers, WAFs, security groups and hybrid connectivity.
- Ensure cloud network designs integrate securely and efficiently with on-premises infrastructure.
11. Automation & Continuous Improvement
- Identify opportunities to automate repetitive network administration, configuration, compliance and monitoring tasks.
- Use technologies such as Ansible, Python, PowerShell, APIs, templates and Infrastructure-as-Code principles where appropriate.
- Continuously review network architecture and operational processes for opportunities to simplify, standardise, secure and improve them.
12. Documentation, Knowledge Transfer & Team Development
- Maintain accurate and current network diagrams, HLD/LLD, IP/VLAN registers, firewall matrices, circuit inventories, device inventories, SOPs and troubleshooting guides.
- Document dependencies, recovery procedures and configuration standards so that critical network knowledge is not held by one individual.
- Mentor and train Infrastructure and Operations engineers so they can safely perform defined network tasks under agreed standards.
- Support technical knowledge transfer and reduce single-person dependency within the team.
13. Suppliers & Stakeholder Engagement
- Work directly with ISPs, carriers, network vendors, firewall/wireless vendors and support partners.
- Review technical proposals and Statements of Work, challenge weak designs, validate specifications and provide an independent technical view.
- Communicate network issues, risks and recommendations clearly to technical teams, managers and senior stakeholders.
- Provide practical advice and consultancy to Infrastructure, Applications, Cybersecurity and business teams.
Technical Skills Essential
- Strong enterprise LAN/WAN knowledge: TCP/IP, Layer 2/3 switching, VLANs, routing, ACLs, QoS, DNS and DHCP.
- Hands-on FortiGate/FortiOS or equivalent enterprise firewall experience.
- Strong knowledge of NAT, IPsec VPN, remote access, firewall HA, segmentation and secure network design.
- Experience with MPLS, DIA, point-to-point connectivity, SD-WAN and resilient WAN design.
- Enterprise wireless design and troubleshooting, ideally in warehouse or operational environments.
- Deep troubleshooting capability using packet capture, Wireshark, firewall logs, routing tables and performance telemetry.
- Experience producing HLD/LLD, diagrams, implementation plans and operational documentation.
- Good understanding of network security controls including IDS/IPS, NAC, 802.1X, RADIUS/TACACS+, secure management and network hardening.
- Ability to monitor and optimise network performance using tools such as Zabbix, SNMP, syslog and traffic-flow analytics.