Network Automation Engineer
Role details
Job location
Tech stack
Job description
Hybrid - Automation (Python/Ansible/Terraform) - Palo Alto
This is an engineering role focused on enterprise network design, implementation, security and modernisation. The successful candidate will take ownership of complex infrastructure initiatives, working closely with architecture teams and senior stakeholders to deliver projects from concept through to full implementation.
There is a focus on Automation (Python/Ansible/Terraform) and Palo Alto experience, particularly within a project environment rather than BAU. Key Responsibilities
-
Implement new network and network security technologies as defined by enterprise architecture.
-
Build, configure and test network infrastructure solutions across on-prem and cloud environments.
-
Contribute to the research and recommendation of innovative technologies to improve performance, resilience and scalability.
-
Engineer solutions using enterprise blueprints and standards.
-
Design and implement resilient architectures with disaster recovery and business continuity in mind.
-
Work with technologies including switches, routers, firewalls, wireless platforms, SDN fabrics, load balancers, NAC and cloud networking components.
-
Provide Tier 3 engineering support for complex incidents and escalations.
-
Participate in a 24x7 on-call rotation as required.
-
Produce and maintain detailed network documentation using Microsoft Visio.
-
Maintain and continuously improve network security posture in line with regulatory frameworks including PCI-DSS, PII, CIS and NIST.
Requirements
- 5-7+ years of experience designing, implementing and supporting medium to large enterprise networks (10,000+ users).
- Palo Alto Firewall platforms (Pan-OS, Threat Prevention, User-ID, GlobalProtect, HA, Prisma Access)
- Automation and Scripting (Python/Ansible/Terraform
- Strong hands-on experience with Cisco enterprise technologies.
- CCNP Enterprise (R&S) level knowledge required.
- 1-2 years' experience designing and supporting data centre spine-leaf fabrics (Cisco/Arista).
- Experience with Cisco DNA Center.
- Experience with SD-WAN technologies (Cisco, Palo Alto ION).
- Enterprise-scale Cisco Wireless experience (WLC, FlexConnect, CAPWAP).
Desirable Experience
- Remote access VPN technologies.
- Certificate lifecycle management (Venafi, PKI).
- NAC solutions (Cisco ISE, Forescout).
- Infoblox DNS/IPAM.
- Cloud networking design and security principles.
- Network monitoring tools such as SevOne, SolarWinds, Datadog or Splunk.
- Knowledge of network security architecture, IDS/IPS, VPNs and SSL technologies.