Senior Specialist Engineer - Networks

UK Health Security Agency
London, UK
24 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£6,650.0
Working hours
Regular working hours
Job source

Tech stack

3d Models Wireless LAN Computer Networks Data Centers Dynamic Host Configuration Protocol Storage Area Network (SAN) Virtual Private Networks (VPN) Python (Programming Language) Network Security Network Architecture Network Planning and Design Network Functions Virtualization
+23 more
Network Monitoring Routing Network Segmentation Network Service Network Virtualization Ansible Zero Trust Network Access Security Information and Event Management Systems Integration Toolchain Virtualization Technology Wide Area Networks Datadog Load Balancing HybridCloud Infrastructure Automation Frameworks Cybercrime Microsoft Sentinel Wireless Technologies Terraform Open Network Automation Platform Splunk Servicenow

Job description

Working alongside the Network Manager, the post holder ensures all systems are optimally configured, resilient, secure, and performant. Beyond day-to-day operational responsibilities, the role carries explicit accountability for network architecture, strategic design, and cross-functional incident response.

This role also attracts a market pay supplement of £6650 per annum (to be reviewed in February 2027).

Own and maintain a comprehensive and current understanding of the network architecture, acting as an authoritative technical reference for network design decisions.

Maintain consistent availability and performance across specialist network systems, collaborating with other specialist engineers and ICT colleagues as required.

Act as a primary network technical authority during major incidents, coordinating resolution activity across multi-disciplinary teams including infrastructure, security, application, and service management functions.

Act as a technical point of expertise, providing advice, guidance, and training to improve and enhance services for end users.

Support the Network Team in ensuring hardware, software, and associated technologies are designed, procured, and delivered efficiently and cost-effectively.

Contribute to and lead the production of network architecture documentation, including High Level Designs (HLD), Low Level Designs (LLD), and As-Built records.

We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce.

UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all.

Please visit our careers site for more information https://gov.uk/ukhsa/careers

Network Architecture, Design & Delivery

Act as the senior technical lead for UKHSA network architecture, owning and maintaining High Level Designs (HLD), Low Level Designs (LLD), topology diagrams and As-Built documentation.

Lead the design, implementation and lifecycle management of resilient, scalable and secure LAN, WAN, WLAN and cloud-connected infrastructure, ensuring alignment with NCSC Secure by Design principles.

Provide technical assurance across estate modernisation, science campus, data centre and hybrid cloud programmes, while collaborating with infrastructure, security, application and cloud teams.

Manage routing, switching, wireless, WAN, load balancing, IPAM, DNS and DHCP services, alongside Extreme Networks Fabric Engine, Site Engine and wireless platforms.

Network Security, Resilience & Incident Management

Provide technical leadership for network security and operational resilience across the UKHSA estate.

Administer Palo Alto NGFW, Panorama, VPN, micro-segmentation, DMZ and Zero Trust architectures, ensuring compliance with security standards and evolving threat landscapes.

Act as the senior network authority during Major Incident Response Team (MIRT) activities, leading diagnosis, resolution, communication, Root Cause Analysis (RCA) and Post Incident Reviews (PIR).

Develop incident runbooks, continuity plans and mitigation strategies to reduce risk, improve service resilience and support secure cloud and on-premises environments.

Service Management, Automation & Technical Leadership

Lead the monitoring, observability, performance and capacity management of network services, integrating operational and security monitoring with ITSM and SIEM platforms.

Drive network automation and Infrastructure as Code using tools such as Ansible and Python to improve consistency and efficiency.

Manage vendor relationships, technology lifecycles, procurement planning and proof-of-concept evaluations.

Produce technical documentation, support ITIL Incident, Problem, Change and Request Management processes, contribute to CAB activities, mentor engineers, provide expert stakeholder advice, maintain compliance with ICT standards and deliver high-quality customer support, including participation in on-call and out-of-hours services.

Requirements

Formal technical qualification equivalent to CCNP level or above, or substantial experience in a senior network engineering role, with advanced knowledge of enterprise routing and switching, network security, wireless technologies, and large-scale network infrastructure management.

Proven experience producing and maintaining network architecture artefacts, including High Level Designs (HLDs), Low Level Designs (LLDs), topology diagrams, reference architectures, and As-Built documentation across enterprise LAN, WAN, WLAN, and security environments.

Demonstrable ability to lead or contribute to network architecture initiatives, provide technical assurance and design reviews, and ensure solutions align with organisational standards, security-by-design principles, and best practice methodologies.

Significant experience acting as a senior technical authority during major incidents, leading network diagnosis and resolution activities, collaborating within multi-disciplinary Major Incident Response Teams, and managing complex, high-pressure situations.

Experience producing Root Cause Analysis (RCA) reports, Post-Incident Reviews (PIRs), and maintaining incident runbooks, playbooks, and escalation procedures while driving continuous service improvement and reducing recurrence of critical incidents.

Skilled in monitoring network infrastructure to optimise performance, support capacity planning, identify risks, and proactively address technical issues to maintain service availability and resilience for large user populations.

Excellent written, verbal, reporting, and presentation skills, with the ability to communicate complex technical concepts to both technical and non-technical audiences, work effectively across multidisciplinary teams, deliver outstanding customer service, and manage competing priorities under changing timescales.

Desirable criteria

Experience with network Function Virtualisation (NFV) and Software Defined Networking (SDN) architectures, including overlay/underlay design models and virtual network appliance deployment.

Experience with advanced network automation toolchains including Terraform, Ansible, or Python-based frameworks applied to infrastructure provisioning and compliance enforcement.

Hands-on experience with SIEM platforms (e.g. Splunk, Microsoft Sentinel) in the context of network security monitoring, alert triage, and threat hunting.

Experience with Zero Trust technologies such as Zscaler ZIA/ZPA, Illumio, or equivalent ZTNA platforms in an enterprise deployment context.

Familiarity with network observability tools such as ThousandEyes, NetBrain, or Datadog Network Performance Monitoring for advanced path analysis and synthetic monitoring.

Experience with ITSM platforms (e.g. ServiceNow or equivalent) including use of the platform for major incident management, problem records, and change advisory workflows.

Familiarity with HPC or scientific network environments, including high-throughput storage networking or research network interconnect requirements.

Skills for communication on complex matters and difficult situations, requiring persuasion and influence across organisational boundaries.

Selection process

This vacancy is using Success Profiles and will assess your behaviours, experience and technical skills., Formal technical qualification equivalent to CCNP level or above, or substantial experience in a senior network engineering role, with advanced knowledge of enterprise routing and switching, network security, wireless technologies, and large-scale network infrastructure management., Behaviours, technical skills and experience will be tested at interview.

The Behaviours tested during the interview stage will be: Leadership (Lead behaviour)

Delivering at pace

Making effective decisions

Communicating and influencing

Managing a quality service, Successful candidates must pass a basic Disclosure and Barring Security check before they can be appointed.

Successful candidates must meet the security requirements before they can be appointed. The level of security needed Security Check vetting.

For meaningful National Security Vetting checks to be carried out, individuals need to have lived in the UK for a sufficient period of time. You should normally have been resident in the United Kingdom for the last 5 years to obtain Security Check (SC) clearance. UK residency less than the outlined periods may not necessarily bar you from gaining national security vetting at this higher level and applicants should contact the Vacancy Holder / Recruiting Manager listed in the advert for further advice.

About the company

Healthjobs UK has a word limit of 1500, but your supporting statement must be no more than 1000 words. We will not consider any words over 1000 words., This role is being offered as hybrid working based at any of our Core HQs in Birmingham, Leeds, Liverpool or London (Canary Wharf).

We offer great flexible working opportunities at UKHSA and operate using a hybrid working model where business needs allow. This provides us with greater flexibility about how and where we work, to get the best from our workforce. As a hybrid worker, you will be expected to spend a minimum of 60% of your contractual working hours (approximately 3 days a week pro rata, averaged over a month) on-site.

Our core HQ offices are modern and newly refurbished with excellent city centre transport link and benefit from benefit from co-location with other government departments such as the Department for Health and Social Care (DHSC).

Eligibility criteria

Open to all external applicants (anyone) from outside the Civil Service (including by definition internal applicants).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

1:36 min

Visualizing memory limits and isolating suspicious endpoints

Dina Matveev Dina Matveev · Europe 2026 Virtual

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:39 min

Streamlining application deployment with agentless Ansible

Goetz Rieger Goetz Rieger · World Congress 2025

Videos

See all

Related articles

See all