Role Summary
This is a client-facing hands-on technical leadership role As the L3 Team Lead you will be the highest technical authority for Network Architecture Routing amp Switching Network Security Cyber Security and Unified Communications deployments for Hilal Technology s client base Your primary mandate is to design implement migrate and troubleshoot network and security solutions leading a team of deployment engineers and working closely with the Project Manager and Technical Manager to ensure that what is sold is delivered to the highest standard Important Note This is a Project Delivery amp Engineering role The engineer must be available to resolve and support the team upon request amp urgency nbsp
Key Responsibilities
- Network Engineering Routing amp Switching Core Infrastructure Design configure and troubleshoot complex enterprise LAN WAN environments across Cisco Catalyst Nexus Aruba CX Switches Dell PowerSwitch DS Series and Huawei Cloud Engine S-series switches Advanced Routing Implement and optimize dynamic routing protocols OSPF BGP EIGRP IS-IS across multi-vendor routers and firewalls Wireless Oversee deployment of enterprise wireless networks specifically Cisco Meraki Aruba Wireless Controllers Access Points Central ArubaOS and Huawei WLAN solutions Network Automation amp Management Deploy and manage Cisco DNA Centre Catalyst Centre and Huawei iMaster NCE to automate provisioning monitor network health and enforce policy-based networking
- Network amp Cyber Security Engineering Hands-On L3 Multi-Vendor Firewall Expertise Act as the L3 Subject Matter Expert technical authority for deployment migration and tuning of Next-Gen Firewalls across Palo Alto Check Point Cisco FTD ASA Fortinet FortiGate Juniper SRX and Huawei USG Firepower Execute complex firewall security migrations e g Check Point to Palo Alto Cisco to Fortinet Legacy Cisco to Palo Alto Juniper to Fortinet with minimal downtime using automation tools Configure advanced features including BGP OSPF routing SSL Decryption App-ID User-ID Threat Prevention and Site-to-Site Remote Access VPNs Route-based Hub-and-Spoke and SD-WAN integrations Network Access Control NAC Design and implement 802 1X and MAB solutions e g Cisco ISE FortiNAC Aruba ClearPass to secure wired wireless and VPN access integrated with enterprise wireless and switching infrastructure Identity amp Access Management MFA Design and integrate Multi-Factor Authentication solutions specifically Cisco Duo and FortiAuthenticator for remote VPN and admin access Privileged Access Management PAM Deploy PAM solutions e g CyberArk Wallix BeyondTrust including vaulting session isolation and integration with client Active Directories Endpoint Security EDR XDR Lead large-scale agent deployment projects CrowdStrike SentinelOne Cortex XDR Defender across client environments ensuring policy tuning and false-positive resolution before handover Web Application Firewall WAF Deploy and tune WAF policies e g F5 Imperva FortiWeb Cloudflare in front of client web applications balancing strict OWASP Remote Access amp SASE Design and maintain enterprise VPN solutions GlobalProtect AnyConnect FortiClient and integrate with Zero Trust Network Access ZTNA principles nbsp
Required Skills
- Minimum 8-10 years in Network amp Cyber Security Engineering with at least 3 years in a Systems Integrator SI or Professional Services environment Proven track record of managing simultaneous projects and team workloads for multiple clients
- Vendor amp Technology Expertise Mandatory Networking Hands-on command of Cisco IOS IOS-XE Aruba CX OS Huawei VRP and Dell OS10 OS9 Enterprise SONiC OS is a plus Firewalls Strong hands-on expertise in at least three of the following Palo Alto Strata Check Point Quantum Cisco Firepower Fortinet FortiGate Juniper SRX Huawei
- Deep Domain Knowledge NAC Cisco ISE Aruba ClearPass FortiNAC EDR XDR WAF and PAM
- Collaboration Deep understanding of SIP protocol dial plans and troubleshooting tools Translations Trace routes Wireshark
- Must have deployed either Cisco or Avaya IPT solutions SBC Working knowledge of Ribbon SBC configurations for SIP trunks
- Authentication Hands-on experience with Cisco Duo and FortiAuthenticator
- Networking Knowledge CCNP CCIE level understanding of Routing amp Switching BGP OSPF EIGRP IS-IS VLANs Spanning Tree VRF VXLAN TCP IP DNS DHCP Ability to use Wireshark tcpdump to read packet captures and prove network issues are not the firewall s fault resolving connectivity voice quality VoIP latency or network bottleneck issues
- Soft Skills Communication Excellent written and verbal communication in English Ability to explain complex technical issues and present solutions to client stakeholders and C-level executives
- Leadership Proven ability to motivate a technical team and enforce engineering standards
- Documentation High proficiency in creating High-Level Designs HLDs Low-Level Designs LLDs Migration Runbooks and Network Diagrams Visio PowerPoint Draw io amp other tools
- Certifications Preferred Networking CCNP Enterprise CCIE R amp S Enterprise Security Aruba ACSP ACMP or Huawei HCIP HCIE Security PCNSE Palo Alto NSE 7 8 Fortinet CCSE Check Point JNCIE-SEC or CISSP
Qualifications
Minimum 8-10 years in Network & Cyber Security Engineering, with at least 3 years in a Systems Integrator (SI) or Professional Services environment.Proven track record of managing simultaneous projects and team workloads for multiple clients.Networking: Hands-on command of Cisco IOS/IOS-XE, Aruba CX/OS, Huawei VRP, and Dell OS10/OS9 (Enterprise SONiC OS is a plus).Firewalls: Strong hands-on expertise in at least three of the following: Palo Alto Strata, Check Point Quantum, Cisco Firepower, Fortinet FortiGate, Juniper SRX, Huawei.
Certifications
Networking Certifications: CCNP Enterprise, CCIE (R&S/Enterprise/Security), Aruba ACSP/ACMP, or Huawei HCIP/HCIE. Security Certifications: PCNSE (Palo Alto), NSE 7/8 (Fortinet), CCSE (Check Point), JNCIE-SEC, or CISSP.