Principal Infrastructure Engineer

Cetera Financial Group Inc

Dallas (TX)

On-site

USD 180,000 - 260,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Cetera Financial Group Inc. seeks a highly skilled Principal Network Engineer to act as senior technical authority for enterprise network architecture, cloud networking, security, and operations.

The role covers on-premises, data center, branch offices and multi-cloud environments. You will design, implement and support WAN/LAN, SD-WAN, MPLS, VPNs and hybrid cloud connectivity while leading complex troubleshooting and automation initiatives.

Qualifications

  • 10+ years of progressive network engineering or administration experience in large enterprise environments.
  • 5+ years of hands-on experience with Cisco, Meraki, Palo Alto, AWS and Azure networking technologies.
  • Bachelor’s degree in engineering, computer science, MIS or related field or equivalent training.
  • Cisco CCNP certification or equivalent expert-level routing and switching experience.
  • Experience designing and supporting highly available hybrid and multi-cloud network architectures.
  • Expert knowledge of TCP/IP, BGP, OSPF, EIGRP, VLANs, STP, HSRP, VRF, DNS, DHCP, NAT, wireless and VPN.
  • Hands-on experience with Palo Alto next-gen firewalls and GlobalProtect.
  • Hands-on with Cisco Catalyst/Nexus/Meraki platforms.
  • Strong analytical/troubleshooting skills and stakeholder communication.
  • Experience leading complex infrastructure projects and mentoring engineers.

Responsibilities

  • Serve as senior technical authority for enterprise network architecture, cloud networking, security and operations.
  • Design, implement and support WAN/LAN including SD-WAN, MPLS, Internet, VPN and hybrid cloud connectivity.
  • Architect, configure and troubleshoot Cisco Catalyst/Nexus, Meraki, Palo Alto firewalls and related gear.
  • Lead incident response, root-cause analysis and problem resolution.
  • Develop architecture standards, runbooks and installation plans with cross-team collaboration.
  • Drive automation of provisioning, validation, compliance reporting via IaC and APIs.
  • Research and implement observability, AIOps and proactive monitoring.
  • Collaborate with Cybersecurity, Cloud, Architecture and Operations teams.
  • Provide mentorship and knowledge transfer to engineers and support staff.

Skills

10+ years network engineering
CCNP
CCIE Enterprise Infrastructure
Hybrid/multi-cloud networking
TCP/IP, BGP, OSPF, EIGRP
WAN/LAN design
Zero Trust / security integration
Network automation/ IaC
Mentoring/leadership
VXLAN/SD-WAN/MPLS experience

Education

Bachelor’s degree in engineering, computer science, MIS or related field

Tools

Terraform
Ansible
Python

Job description

Cetera Financial Group is seeking a highly skilled and experienced Principal Network Engineer to serve as the senior technical authority for enterprise network architecture, cloud networking, security, and network operations. This role is responsible for designing, implementing, and supporting highly available, secure, scalable, and resilient network solutions across on-premises, data center, branch office, and multi-cloud environments.

  • Serve as an expert-level subject matter expert for routing, switching, wireless, network security and IP communications across traditional office, data center, AWS and Azure environments.

  • Design, implement and support WAN and LAN environments consisting of SD-WAN, MPLS, Internet, IPSEC VPN and hybrid cloud connectivity, with accountability for 24/7 network availability.

  • Architect, configure and troubleshoot Cisco Catalyst and Nexus switching, Cisco routing, Meraki MX firewalls, MR wireless access points and MS switches.

  • Design, implement and support Palo Alto Networks next-generation firewalls, GlobalProtect, security policies, NAT, VPN, intrusion prevention and threat-protection capabilities.

  • Design and support AWS networking services, including VPCs, subnets, route tables, security groups, Transit Gateway, Direct Connect, VPN, ALB/ELB and related services.

  • Design and support Azure networking services, including Virtual Networks, Network Security Groups, Azure Firewall, Virtual WAN, ExpressRoute, VPN Gateway and load-balancing services.

  • Lead complex troubleshooting, incident response, root-cause analysis and problem management through final resolution.

  • Develop network architecture standards, engineering patterns, operating procedures, lifecycle plans and infrastructure requirements in partnership with the Director and Sr. Manager Network Engineering & Operations.

  • Review and implement network changes in accordance with change-management and security processes.

  • Drive automation of network provisioning, configuration validation, compliance reporting and operational tasks through APIs, Infrastructure as Code and orchestration tools.

  • Research and implement best-of-breed networking, observability, anomaly-detection, AIOps and proactive-monitoring capabilities.

  • Analyze performance, capacity and availability trends and recommend improvements that increase resiliency, scalability and operational efficiency.

  • Partner with Cybersecurity to implement network segmentation, Zero Trust, secure access and effective firewall, IDS/IPS and related controls.

  • Provide technical leadership, mentoring and knowledge transfer to network engineers and support teams without requiring direct supervisory authority.

  • Lead technical workstreams for network modernization, office integrations, cloud migrations, hardware refreshes and other enterprise infrastructure initiatives.

  • Collaborate with onshore and offshore teams, vendors and stakeholders across multiple U.S. time zones.

  • Create and maintain architecture diagrams, configurations, standards, runbooks, support documentation and implementation plans.

  • Participate in vendor evaluations, proofs of concept and technical recommendations for network products and services.

  • Ability to work after hours, nights and weekends and provide emergency response support 24 hours a day, 7 days a week, 365 days a year when required.

  • Perform all other responsibilities and duties deemed necessary.

AI Networking Agents:
  • Design and build AI-enabled networking agents that assist with network monitoring, configuration analysis, troubleshooting, incident triage and operational documentation.

  • Develop agent workflows that securely collect and correlate telemetry from Cisco, Meraki, Palo Alto, AWS and Azure networking platforms.

  • Integrate AI networking agents with approved monitoring, IT service management, collaboration and automation platforms to accelerate detection, analysis and response.

  • Establish human-in-the-loop controls, validation steps, access boundaries, auditability and rollback procedures for AI-generated recommendations and automated actions.

  • Create and maintain trusted knowledge sources, prompts, runbooks and test scenarios to improve agent accuracy, consistency and usefulness.

  • Evaluate agent performance, false positives, operational risk and measurable outcomes, and continuously refine solutions based on engineering feedback.

  • Partner with Cybersecurity, Cloud Engineering, Architecture and Operations teams to ensure AI networking agents comply with enterprise security, data governance and change-management requirements.

  • Mentor network engineers on responsible use, development and operational support of AI agents and agentic automation.

What you need to have (Basic Qualifications- minimum 5 quantitative needs):
  • 10+ years of progressive network engineering or administration experience in large enterprise environments.

  • 5+ years of advanced hands-on experience with Cisco, Meraki, Palo Alto, AWS and Azure networking technologies.

  • Bachelor’s degree in engineering, computer science, MIS or a related field, or equivalent technical training and experience.

  • Cisco CCNP certification or equivalent expert-level routing and switching experience.

  • Demonstrated experience designing and supporting highly available hybrid and multi-cloud network architectures.

  • Expert knowledge of TCP/IP, BGP, OSPF, EIGRP, VLANs, STP, HSRP, VRF, DNS, DHCP, NAT, wireless and VPN technologies.

  • Hands-on experience configuring and troubleshooting Palo Alto next-generation firewalls and GlobalProtect.

  • Hands-on experience with Cisco Catalyst, Cisco Nexus and Cisco Meraki platforms.

  • Strong analytical and troubleshooting skills with the ability to make sound decisions during critical incidents.

  • Experience leading complex infrastructure projects and coordinating implementation across technical teams.

  • Strong written and verbal communication skills, including the ability to influence technical and business stakeholders.

  • Experience mentoring engineers, developing standards and providing expert-level technical guidance.

  • TECHNOLOGY: AWS, Azure, SD-WAN, MPLS, IP Networking, VoIP, TCP/IP, BGP, OSPF, EIGRP, VPN, WiFi, WLAN, TACACS, IPS, IDS, DNS, DHCP, Cisco ISE, Palo Alto, GlobalProtect, Cisco Catalyst 9500/9300/8500, Cisco Nexus 9K/7K/5K, Meraki MX/MR/MS, GRE/IPSEC VPN, Zscaler, AWS Transit Gateway, Direct Connect, Azure Virtual WAN, ExpressRoute, Terraform, Ansible, Python, APIs and AIOps.

  • Cisco CCIE Enterprise Infrastructure certification.

  • Palo Alto Networks Certified Network Security Engineer certification.

  • AWS Certified Advanced Networking – Specialty or AWS Solutions Architect – Professional certification.

  • Microsoft Certified: Azure Network Engineer Associate certification.

  • Experience supporting financial services, regulated or highly controlled enterprise environments.

  • Experience with network automation, Infrastructure as Code, SASE and Zero Trust architectures.

  • Demonstrates ownership and approaches work with a solutions-oriented, end-to-end mindset.

  • Focused on execution, delivery, accountability and commitment to dates.

Really catch our eye with (Preferred Qualifications- subjective):
  • Cisco CCIE Enterprise Infrastructure certification.

  • Palo Alto Networks Certified Network Security Engineer certification.

  • AWS Certified Advanced Networking – Specialty or AWS Solutions Architect – Professional certification.

  • Microsoft Certified: Azure Network Engineer Associate certification.

  • Experience supporting financial services, regulated or highly controlled enterprise environments.

  • Experience with network automation, Infrastructure as Code, SASE and Zero Trust architectures.

  • Demonstrates ownership and approaches work with a solutions-oriented, end-to-end mindset.

  • Focused on execution, delivery, accountability and commitment to dates.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Network Architect
Network Architect

Saicon • Pleasanton (CA)

On-site
USD 120,000 - 180,000
Network Engineer 2
Network Engineer 2

Condé Nast • New York (NY)

On-site
USD 120,000 - 180,000
Hybrid work schedule
Technology Engineer, Principal - Data Center Networking (Remote)
Technology Engineer, Principal - Data Center Networking (Remote)

Community Health Systems • United States

On-site
USD 140,000 - 200,000
Network Engineer
Network Engineer

Farm Credit Services • Omaha (NE)

On-site
USD 90,000 - 120,000
Network Engineer
Network Engineer

Protera • Northern (KY)

Hybrid
USD 95,000 - 140,000
Senior Network Engineer
Senior Network Engineer

Sonny's Enterprises Inc. - Conveyorized Car Wash Equipment Leader • Town of Florida (NY)

On-site
USD 120,000 - 160,000
Senior Network Engineer
Senior Network Engineer

The Phoenix Group • New York (NY)

On-site
USD 150,000 - 190,000
Senior Network Engineer
Senior Network Engineer

Agile Resources, Inc. • Atlanta (GA)

On-site
USD 96,000 - 160,000
Medical
Dental
Vision
+5
Senior Network Engineer
Senior Network Engineer

Panzer Solutions LLC • Orange (CT)

On-site
USD 90,000 - 150,000
Senior Network Engineer
Senior Network Engineer

Teal Drones • Salt Lake City (UT)

On-site
USD 120,000 - 180,000