Principal Infrastructure Engineer

Cetera Financial Group, Inc.
Dallas, United States
about 1 month ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Wireless LAN Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Microsoft Azure Border Gateway Protocol VoIP Cisco Hardwares Cloud Computing Cloud Engineering Cyber Security System Configuration
+49 more
Data Centers Data Governance Dynamic Host Configuration Protocol Network Address Translation Domain Name System (DNS) Enhanced Interior Gateway Routing Protocol Hot Standby Router Protocol Internet Protocol Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Intrusion Detection Systems IP Routing Subnetting Virtual Private Networks (VPN) Multi-protocol Systems Python (Programming Language) Network Security Microsoft Office Network Architecture Network Control Network Monitoring Routing Network Segmentation Cisco Nexus Switches Open Shortest Path First (OSPF) Remote Access Technology Ansible Zero Trust Network Access Terminal Access Controller Access-Control System (TACACS) TCP/IP Virtual Local Area Networks Wide Area Networks Wireless Access Point Wi-Fi Technology Identity Services Engine Load Balancing Computer Network Operations In-Plane Switching (IPS) Multi-Cloud HybridCloud Firewalls (Computer Science) Build Management Information Technology Palo Alto Networks Cloud Migration Terraform Open Network Automation Platform Cisco Switches Cisco

Job description

Cetera Financial Group is seeking a highly skilled and experienced Principal Network Engineer to serve as the senior technical authority for enterprise network architecture, cloud networking, security, and network operations. This role is responsible for designing, implementing, and supporting highly available, secure, scalable, and resilient network solutions across on-premises, data center, branch office, and multi-cloud environments.

  • Serve as an expert-level subject matter expert for routing, switching, wireless, network security and IP communications across traditional office, data center, AWS and Azure environments.
  • Design, implement and support WAN and LAN environments consisting of SD-WAN, MPLS, Internet, IPSEC VPN and hybrid cloud connectivity, with accountability for 24/7 network availability.
  • Architect, configure and troubleshoot Cisco Catalyst and Nexus switching, Cisco routing, Meraki MX firewalls, MR wireless access points and MS switches.
  • Design, implement and support Palo Alto Networks next-generation firewalls, GlobalProtect, security policies, NAT, VPN, intrusion prevention and threat-protection capabilities.
  • Design and support AWS networking services, including VPCs, subnets, route tables, security groups, Transit Gateway, Direct Connect, VPN, ALB/ELB and related services.
  • Design and support Azure networking services, including Virtual Networks, Network Security Groups, Azure Firewall, Virtual WAN, ExpressRoute, VPN Gateway and load-balancing services.
  • Lead complex troubleshooting, incident response, root-cause analysis and problem management through final resolution.
  • Develop network architecture standards, engineering patterns, operating procedures, lifecycle plans and infrastructure requirements in partnership with the Director and Sr. Manager Network Engineering & Operations.
  • Review and implement network changes in accordance with change-management and security processes.
  • Drive automation of network provisioning, configuration validation, compliance reporting and operational tasks through APIs, Infrastructure as Code and orchestration tools.
  • Research and implement best-of-breed networking, observability, anomaly-detection, AIOps and proactive-monitoring capabilities.
  • Analyze performance, capacity and availability trends and recommend improvements that increase resiliency, scalability and operational efficiency.
  • Partner with Cybersecurity to implement network segmentation, Zero Trust, secure access and effective firewall, IDS/IPS and related controls.
  • Provide technical leadership, mentoring and knowledge transfer to network engineers and support teams without requiring direct supervisory authority.
  • Lead technical workstreams for network modernization, office integrations, cloud migrations, hardware refreshes and other enterprise infrastructure initiatives.
  • Collaborate with onshore and offshore teams, vendors and stakeholders across multiple U.S. time zones.
  • Create and maintain architecture diagrams, configurations, standards, runbooks, support documentation and implementation plans.
  • Participate in vendor evaluations, proofs of concept and technical recommendations for network products and services.
  • Ability to work after hours, nights and weekends and provide emergency response support 24 hours a day, 7 days a week, 365 days a year when required.
  • Perform all other responsibilities and duties deemed necessary. AI Networking Agents:

  • Design and build AI-enabled networking agents that assist with network monitoring, configuration analysis, troubleshooting, incident triage and operational documentation.
  • Develop agent workflows that securely collect and correlate telemetry from Cisco, Meraki, Palo Alto, AWS and Azure networking platforms.
  • Integrate AI networking agents with approved monitoring, IT service management, collaboration and automation platforms to accelerate detection, analysis and response.
  • Establish human-in-the-loop controls, validation steps, access boundaries, auditability and rollback procedures for AI-generated recommendations and automated actions.
  • Create and maintain trusted knowledge sources, prompts, runbooks and test scenarios to improve agent accuracy, consistency and usefulness.
  • Evaluate agent performance, false positives, operational risk and measurable outcomes, and continuously refine solutions based on engineering feedback.
  • Partner with Cybersecurity, Cloud Engineering, Architecture and Operations teams to ensure AI networking agents comply with enterprise security, data governance and change-management requirements.
  • Mentor network engineers on responsible use, development and operational support of AI agents and agentic automation.

Requirements

  • 10+ years of progressive network engineering or administration experience in large enterprise environments.
  • 5+ years of advanced hands-on experience with Cisco, Meraki, Palo Alto, AWS and Azure networking technologies.
  • Bachelor’s degree in engineering, computer science, MIS or a related field, or equivalent technical training and experience.
  • Cisco CCNP certification or equivalent expert-level routing and switching experience.
  • Demonstrated experience designing and supporting highly available hybrid and multi-cloud network architectures.
  • Expert knowledge of TCP/IP, BGP, OSPF, EIGRP, VLANs, STP, HSRP, VRF, DNS, DHCP, NAT, wireless and VPN technologies.
  • Hands-on experience configuring and troubleshooting Palo Alto next-generation firewalls and GlobalProtect.
  • Hands-on experience with Cisco Catalyst, Cisco Nexus and Cisco Meraki platforms.
  • Strong analytical and troubleshooting skills with the ability to make sound decisions during critical incidents.
  • Experience leading complex infrastructure projects and coordinating implementation across technical teams.
  • Strong written and verbal communication skills, including the ability to influence technical and business stakeholders.
  • Experience mentoring engineers, developing standards and providing expert-level technical guidance.
  • TECHNOLOGY: AWS, Azure, SD-WAN, MPLS, IP Networking, VoIP, TCP/IP, BGP, OSPF, EIGRP, VPN, WiFi, WLAN, TACACS, IPS, IDS, DNS, DHCP, Cisco ISE, Palo Alto, GlobalProtect, Cisco Catalyst 9500/9300/8500, Cisco Nexus 9K/7K/5K, Meraki MX/MR/MS, GRE/IPSEC VPN, Zscaler, AWS Transit Gateway, Direct Connect, Azure Virtual WAN, ExpressRoute, Terraform, Ansible, Python, APIs and AIOps. Really catch our eye with (Preferred Qualifications- subjective):

  • Cisco CCIE Enterprise Infrastructure certification.
  • Palo Alto Networks Certified Network Security Engineer certification.
  • AWS Certified Advanced Networking - Specialty or AWS Solutions Architect - Professional certification.
  • Microsoft Certified: Azure Network Engineer Associate certification.
  • Experience supporting financial services, regulated or highly controlled enterprise environments.
  • Experience with network automation, Infrastructure as Code, SASE and Zero Trust architectures.
  • Demonstrates ownership and approaches work with a solutions-oriented, end-to-end mindset.
  • Focused on execution, delivery, accountability and commitment to dates.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:59 min

Designing HTTP and HTML for familiar document sharing

Tim Berners-Lee · World Congress 2023

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa · LIVE

4:18 min

Prioritizing communication and structural awareness over strict tool mastery

Liam Hurrel +1 · World Congress 2021

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

Videos

See all

Related articles

See all