Network Engineer 2
Role details
Job location
Tech stack
Job description
A mid-level network professional with a strong security-first mindset who has grown beyond break-fix and is ready to take ownership of projects and sites. You are comfortable configuring enterprise switching, wireless, firewall, and VPN infrastructure with limited oversight, can lead an acquisition deployment from start to finish, and know when to loop in a Senior engineer. A strong mid-level engineer who bridges entry-level operations and senior-level architecture: execution-focused, security-conscious, and continuing to grow., * Independently configure and deploy enterprise-grade switching and wireless infrastructure at existing sites and acquisition locations; preferred experience with Ubiquiti UniFi/UISP, Dell, and Cisco.
- Perform firewall administration tasks including policy review, rule implementation, and troubleshooting under Senior engineer sign-off; preferred experience with Palo Alto and Panorama.
- Design and enforce network segmentation strategies using VLANs and zone-based security to isolate end-user, server, guest, OT, and management traffic.
- Implement and maintain network access control (NAC) policies to enforce least-privilege access and device compliance at the network edge.
- Apply security-first practices across all network changes: enforce change control, document security implications, and proactively identify misconfigurations or vulnerabilities.
- Lead acquisition network replacement projects end-to-end: site survey, cabling, switch/AP deployment, circuit coordination, and cutover; escalate to Senior engineers for firewall policy and BGP changes.
- Manage and troubleshoot Cradlepoint, Starlink, fiber, and broadband circuits, including ISP coordination and circuit turn-ups.
- Configure and maintain SSL VPN and S2S VPN connections; escalate firewall rule and policy changes to Senior Network Engineers for review and approval.
- Assist with vulnerability management and network hardening initiatives; remediate identified findings within assigned systems.
- Maintain thorough and accurate records in Netbox (IPAM/documentation integration); enforce documentation standards across junior engineers.
- Provide escalation support to Network Engineer 1 staff for complex LAN/WAN, wireless, and security issues.
- Monitor and respond to network incidents; perform root cause analysis and document findings.
- Patch and maintain all network infrastructure; proactively identify end-of-life or at-risk devices.
- Mentor Network Engineer 1 staff; provide knowledge transfer on tools, security practices, and procedures.
- Willingness to travel to branch and acquisition sites when necessary (multi-state).
Requirements
- 5+ years of networking experience in a multi-site or enterprise environment.
- Hands-on proficiency with enterprise-grade managed switching (Ubiquiti, Cisco, Dell, or equivalent); vendor preference for Ubiquiti UniFi/UISP.
- Working knowledge of at least one enterprise next-gen firewall platform (Palo Alto preferred; Fortinet, Cisco FTD, or equivalent acceptable).
- Solid understanding of routing and switching: VLANs, STP, OSPF, and BGP fundamentals.
- Experience designing and implementing VLAN segmentation and network zone isolation strategies.
- Familiarity with network access control (NAC) concepts and implementation.
- Experience with SSL VPN and S2S VPN configuration and troubleshooting.
- Working knowledge of firewall policy, threat vectors, and network hardening practices.
- Proficiency with DNS, DHCP, and IPAM tools (Netbox preferred).
- Experience leading multi-site network deployments or infrastructure replacements.
- Strong documentation skills; experience maintaining network diagrams and asset records.
Preferred Experience
- Networking or security certifications: CCNA, CCNP, CompTIA Security+, Palo Alto PCNSA/PCNSE, or equivalent.
- Hands-on experience with Palo Alto firewalls and Panorama.
- Familiarity with BGP configuration in a multi-site WAN environment.
- Experience with or exposure to operational technology (OT) or industrial network environments.
- Experience with network access control (NAC) platforms such as Aruba ClearPass, Cisco ISE, or similar.
- Familiarity with IDS/IPS concepts and security monitoring tools.
- Bachelor's degree in IT, Computer Science, Cybersecurity, or related field (or equivalent experience).
Benefits & conditions
Pulled from the full job description
- Employee stock purchase plan
- Health insurance
- 401(k) matching
- Vision insurance
- Dental insurance
- Employee assistance program
- Paid holidays, At Construction Partners, we don't just build roads - we build leaders. We provide opportunities for our employees to grow and develop meaningful careers at all levels. In addition, we offer a wide variety of benefits to support our employees' well-being, including:
- Medical, Dental, and Vision coverage
- 401(k) Retirement Plan with employer matching
- Paid vacation and holidays
- Employee Stock Purchase Plan (Construction Partners, Inc.: ROAD)
- Employee Assistance Program
- Professional Development Opportunities
Construction Partners, Inc. is dedicated to the achievement of equality of opportunity for all its employees and applicants for employment without regard to race, color, religion, sex, marital status, age, national origin, disability, veteran status or any other protected group status under federal, state or local law. Construction Partners, Inc. is an E-Verify Participant.
CPI complies with federal and state disability laws and makes reasonable accommodation for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, please let us know.