Seeking a highly experienced and hands-on Tech Lead – Network Engineering to take end-to-end ownership of its global corporate network and network security infrastructure.
The ideal candidate will have strong expertise in Network Design, Routing & Switching, NAC, Wireless Networking, and VPN/SASE migrations, with particular emphasis on Zscaler ZIA/ZPA.
Key Responsibilities :
- Own network architecture and operations across global office locations.
- Design and maintain standards for wired LAN, wireless LAN, WAN, routing, switching, and site connectivity.
- Manage dual-ISP redundancy, failover, and resilient connectivity across office locations.
- Administer and optimize Palo Alto firewalls, including policies, segmentation, NAT, threat prevention, and Panorama.
- Manage Cisco Meraki MX/MS/MR switching and wireless environments across multiple sites.
- Administer and enhance Infoblox DDI, including DNS, DHCP, and IPAM.
- Design scalable network architecture to support new offices and organizational growth.
- Lead the migration from Tailscale/VPN-based remote access to Zscaler.
- Implement and manage Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA).
- Design Zero Trust access architecture incorporating user identity, device posture, application segmentation, and least-privilege access.
- Develop and execute VPN migration and cutover strategies with minimal business disruption.
- Decommission legacy VPN infrastructure following successful migration.
- Implement secure access policies for internal applications and corporate resources.
Routing, Switching, NAC & Wireless
- Design, configure, troubleshoot, and optimize enterprise routing and switching environments.
- Manage VLANs, routing protocols, SD-WAN, NAT, and network segmentation.
- Design and maintain enterprise wireless infrastructure.
- Implement and manage 802.1X/NAC solutions for corporate, BYOD, and mobile devices.
- Integrate NAC controls with endpoint-management and identity solutions.
- Troubleshoot complex wired, wireless, routing, VPN, and network-security issues.
Site & Inter-Office Connectivity
- Design secure and highly available connectivity between offices, data centers, cloud environments, and third-party networks.
- Develop standardized network architectures and deployment playbooks for new office locations.
- Establish repeatable processes for rapidly deploying secure networking infrastructure at new sites.
- Ensure consistent network-security and connectivity standards across all locations.
Technical Leadership & Strategy
- Serve as the technical authority and escalation point for network and network-security issues.
- Work as a hands-on technical lead while providing architectural direction and mentorship.
- Partner with Security and IT leadership to establish a multi-year network and security roadmap.
- Own relationships with key technology vendors, including Palo Alto Networks, Cisco Meraki, Zscaler, and Infoblox.
- Establish network monitoring, alerting, documentation, and operational standards.
- Identify opportunities for network automation, standardization, scalability, and improved observability.
Required Qualifications :
- 7+ years of experience in Network Engineering, Network Architecture, or related infrastructure roles.
- Strong hands-on experience with Network Design, Routing, and Switching.
- Strong understanding of VLANs, SD-WAN, DNS/DHCP, NAT, VPN, and network segmentation.
- Hands-on experience with NAC / 802.1X and enterprise device-access controls.
- Strong enterprise Wireless Networking experience.
- Hands-on experience managing Palo Alto Networks firewalls, including policy, Panorama, segmentation, NAT, and threat prevention.
- Strong experience with Cisco Meraki MX/MS/MR in multi-site production environments.
- Experience with Infoblox or comparable DNS/DHCP/IPAM platforms.
- Experience designing, implementing, or migrating SASE / Zero Trust / ZTNA environments.
- Experience supporting network infrastructure across multiple corporate locations.
- Ability to troubleshoot complex network and security issues independently.
- Strong documentation, architecture, communication, and technical leadership skills.
Highly Preferred Skills :
- Direct hands-on experience with Zscaler ZIA and ZPA.
- Experience leading VPN-to-Zscaler or SASE migrations.
- Experience migrating from Tailscale, WireGuard, or traditional VPN solutions to Zscaler.
- Experience with alternative SASE platforms such as Cloudflare, Netskope, or Palo Alto Prisma Access.
- Experience with network automation, monitoring, and observability.
- Experience with high-growth technology organizations and rapidly expanding multi-site environments.