Location: Penang, 07, MY
Functional Area: Information Technology (ITM)
Career Stream: IT Infrastructure (INFR)
Role: Technical Lead (TEL)
Job Title: Technical Lead, IT Infrastructure
Job Code: TEL-ITM-INFR
Job Level: Level 10
Direct/Indirect Indicator: Indirect
Core Responsibilities
- 1. SONiC & Open Network Operations
- SONiC Infrastructure Management: Monitor, configure, and maintain the health,performance, and uptime of Celestica’s proprietary open network switches running theSONiC operating system.
- Configuration & Segmentation: Implement localized VLAN adjustments, IP addressallocations, and switch port provisioning within the SONiC environment to isolate multi-tenant engineering projects.
- Routine Maintenance: Execute hardware diagnostics, physical cabling checks, andSONiC OS/firmware updates following strict maintenance window guidelines.
- Secondary Infrastructure Support: Perform operational support, troubleshooting, and maintenance of legacy secondary network components, including Check Point 3980firewalls, Silver Peak SD-WAN appliances, and Cisco Catalyst 9400/9200 switches asrequired.
- 2. Zscaler & Internal Security Policy Administration
- Zero-Trust Internal Firewalling: Administer and configure Zscaler ZTNA / AppConnectors to serve as internal firewalls, establishing secure boundaries and controlling data flow across isolated local VLANs.
- Access Control & Identity: Provision local user accounts, configure role-basedpermissions, and manage decentralized credentials on Linux-based jump hosts.
- Remote Session Security: Manage secure engineer connections using CyberArk vPAM(Virtual Privileged Access Management).
- Security Auditing: Conduct weekly audits of active user sessions, ACL configurations, and local accounts to maintain an uncompromising security posture.
- 3. Data Transfer & Repository Sync Operations
- Multi-Tier Sync Execution: Execute and monitor the secure transfer of "transferbundles" containing OS packages (Rocky Linux, Ubuntu, CentOS, etc.), drivers, andsoftware libraries across the physical air gap.
- Repository Services Administration: Ensure repository services remain operational, synchronized, and accessible to authorized systems within segmented and isolated RDLenvironments.
- Integrity Validation: Verify cryptographic hashes (SHA-256 checksums) of all datapackages moving from the Global Repository Server to the RDL Local RepositoryServer.
- 4. Support Ticket Resolution & SLA Adherence
- End-User Support: Act as the primary technical point of contact for HPS designengineers needing open network troubleshooting, VLAN routing resolution, or newpackage requests.
- Ticketing Operations: Process, update, and resolve secure lab support tickets inaccordance with established Service Level Agreements (SLAs).
- Escalation Point: Identify complex open-networking bugs, design deviations, or routinglimitations and elevate them directly to the Lead Network Architect.
- 5. Compliance & Environment Enforcement
- Software Auditing: Conduct regular logical audits of systems within the RDL to ensurestrictly banned corporate agents (e.g., CrowdStrike, Threat Locker, Big Fix, ServiceNowAgents, ClearPass NAC) are not installed.
- Asset Tracking: Maintain a flawless inventory of all HPS-owned assets inside the RDLphysical rooms, including servers, switches, wireless access points (Aruba 755), andconnected lab machines.
Required Technical Skills
- Network & Security Hardware: Practical experience configuring and troubleshootingLayer 2 and Layer 3 network environments including VLANs, routing, ACLs, packet captureanalysis, and protocol troubleshooting using tools such as Wireshark and tcpdump.
- Monitoring & Visibility: Experience with SNMP-based monitoring and alerting platformssuch as SolarWinds, including device health monitoring, performance analysis, faultidentification, and capacity trending.
- Linux System Administration: Mid-to-senior level Linux administration experienceincluding user management, shell scripting, package management, service administration,repository hosting, and network troubleshooting.
- Access Tools: Experience working with remote access tools such as Zscaler ZTNA / AppConnectors and Privilege Access Management solutions (specifically CyberArk).
- Virtualization Administration: Experience provisioning, maintaining, and troubleshootingvirtual machines, clustered hosts, storage resources, and virtual networking withinVMware vSphere, Nutanix AHV, and/or Microsoft Hyper-V environments.
- Air-Gap Protocols: Working knowledge of secure file transfer protocols (SFTP, SCP,rsync) and security scanning methodologies.
Preferred Certifications
- CCNA (Cisco Certified Network Associate)
- Check Point Certified Security Administrator (CCSA)
- CompTIA Security+ or Linux+
- CyberArk Certified Trustee or Defender
Soft Skills & Working Style
- High Operational Discipline: Ability to strictly adhere to Standard Operating Procedures(SOPs) without cutting corners, even during urgent troubleshooting.
- Excellent Communicator: Strong written and verbal communication skills, necessary fortranslating technical issues to designers and coordinating with corporate security teams.
- Multi-Tasker: Capable of balancing ticket requests from multiple global labs concurrentlywhile maintaining accurate records.
Physical Demands
- Duties of this position are performed in a normal office environment.
- Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.
Education & Experience
- Bachelor’s degree in Network Administration, Information Technology, Computer Science,or equivalent hands-on experience.
- 4+ years of experience in network administration or system administration, preferablymanaging secure, segmented, or laboratory networks.
- Overall 14+years of work experience is required.
Notes
This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.
Celestica is an equal opportunity employer. All qualified applicants will receive consideration for employment and will not be discriminated against on any protected status (including race, religion, national origin, gender, sexual orientation, age, marital status, veteran or disability status or other characteristics protected by law). At Celestica we are committed to fostering an inclusive, accessible environment, where all employees and customers feel valued, respected and supported. Special arrangements can be made for candidates who need it throughout the hiring process. Please indicate your needs and we will work with you to meet them.