Network Engineer

NETEFFECT TECHNOLOGIES, LLC
Charlotte, NC, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$75,000.0 - $90,000.0
Working hours
Shift work
Job source

Tech stack

IEEE 802.1Q IEEE 802.1X Wireless LAN Microsoft Azure Border Gateway Protocol VoIP Cloud Computing Protocol Stack Complex Networks Cyber Security Dynamic Host Configuration Protocol Network Address Translation
+41 more
Domain Name System (DNS) Trunking Failover Firmware Network Topologies IT Management Internet Protocol Security (IP SEC) Intrusion Detection Systems IP Routing Subnetting Virtual Private Networks (VPN) Network Security Network Troubleshooting Network Layer Network Architecture Network Diagrams Network Monitoring Network Programming Routing Network Segmentation Open Shortest Path First (OSPF) Peering Windows PowerShell Remote Access Technology Cloud Services Zero Trust Network Access TCP/IP Virtual Local Area Networks Wide Area Networks Wireless Access Point Wireless Networks Document Enterprise Platform Transport Layer Security Firewalls (Computer Science) Web Filtering Information Technology Fortinet Routing & Switching Open Network Automation Platform Cisco SSL VPN

Job description

At neteffect technologies, you’ll architect, deploy, and secure network environments built on Ubiquiti and Fortinet, own network segmentation and access control end to end, and serve as the subject matter expert our team and clients turn to for connectivity, performance, and network security questions. We’re actively standardizing on the Ubiquiti UniFi full stack while continuing to support Fortinet across our client base - so you’ll have real influence on the standards we set as we make that transition., * Own the network stack - from physical layer to cloud, you’ll be the connectivity and network-security SME the team escalates to.

  • Shape the Ubiquiti transition - help define the UniFi standards, designs, and playbooks as we move toward a Ubiquiti-first model.
  • Real security ownership - segmentation, NAC, ZTNA, and firewall policy are yours to design and enforce, not just maintain.
  • Work across a varied client base - no two networks are the same; you’ll see it all, from single-site offices to multi-site WANs.
  • Collaborate with leadership on strategy - not just execution, but helping shape how we approach networking and network security as an MSP.
  • A fully resourced toolset across PSA, RMM, monitoring, and documentation platforms., This Network Engineer role is responsible for the design, implementation, management, and continuous improvement of network and network-security solutions across the neteffect client portfolio. Primary focus areas include routing and switching, Ubiquiti UniFi and Fortinet firewalls, network segmentation and access control, SD-WAN and WAN connectivity, enterprise wireless, voice/telecom, and Azure cloud networking.

You’ll serve as the technical escalation point for network issues, handle complex project work, conduct network and security reviews, and help define standards and best practices for the broader engineering team., Network Architecture & Administration

  • Design, implement, and manage enterprise LAN/WAN environments - routing, switching, VLANs, trunking, and Layer 2/Layer 3 segmentation.
  • Build and manage the Ubiquiti UniFi full stack across the client portfolio: Cloud Gateways, switches, access points, and the UniFi Network application / Site Manager.
  • Design and deploy enterprise wireless - site surveys, RF planning, controller management, and troubleshooting.
  • Configure dynamic and static routing (OSPF, BGP, static) and ensure resilient, high-availability network topologies.

Firewall & Network Security

  • Architect, deploy, and tune firewalls on both Ubiquiti and Fortinet (FortiGate) platforms - security policy, NAT, IPS/IDS, web/content filtering, and application control.
  • Own network segmentation and access control - VLAN segmentation, NAC/802.1X, and Zero Trust Network Access (ZTNA) design and enforcement.
  • Design and manage VPN connectivity: site-to-site IPsec, SSL/remote-access VPN, and secure interconnects.
  • Harden network infrastructure and conduct periodic network security reviews; coordinate with the security team on incidents that touch the network layer.

WAN, SD-WAN & Connectivity

  • Manage ISP relationships, circuit turn-ups, and WAN connectivity across single- and multi-site clients.
  • Design and deploy SD-WAN for performance, resiliency, and failover.
  • Plan and execute network cutovers and migrations with minimal downtime.

Cloud Networking

  • Design and manage Azure networking - VNets, subnets, NSGs, route tables, VPN Gateway, and hybrid connectivity to on-premises networks.
  • Support secure, reliable connectivity between client sites and cloud workloads.

Voice & Telecom

  • Deploy and support VoIP/telecom infrastructure - SIP trunks, handsets/SBCs, dial plans, and QoS for voice quality.
  • Troubleshoot voice and connectivity issues across client environments.

Physical Infrastructure

  • Design and standardize physical-layer infrastructure: IDF/MDF layouts, structured cabling standards, rack design, and switch provisioning.
  • Manage firmware/OS lifecycle for switches, APs, and firewalls; validate stability post-upgrade.

Engineering Standards & Escalation

  • Serve as the escalation point for the engineering team on complex network and network-security issues.
  • Develop and maintain runbooks, configuration standards, network diagrams, and decision frameworks.
  • Conduct post-incident reviews and produce RCAs for significant network events or outages.
  • Deliver internal training on networking and network-security best practices and evolving Ubiquiti/Fortinet technologies.

Client Engagement & Strategy

  • Engage directly with client IT leadership on network posture, roadmap planning, and risk.
  • Produce and present clear, actionable reports on network health, capacity, and security findings.
  • Participate in QBRs and strategic planning meetings as a technical advisor.

Requirements

Do you have experience in Zero trust architecture design?, * 4-7 years of IT experience with at least 3 years focused on enterprise networking at an engineering level.

  • MSP experience required - you understand multi-tenant management, client accountability, and the discipline of working across varied environments simultaneously.
  • Demonstrated hands-on experience designing and managing routing, switching, firewalls, and wireless.
  • Experience designing and enforcing network security controls - segmentation, NAC, and firewall policy.

Technical Skills - Required

  • Routing & Switching: VLANs, 802.1Q trunking, STP/RSTP, Layer 2/Layer 3 design, OSPF/BGP, static routing.
  • Firewalls: FortiGate and Ubiquiti - security policy, NAT, VPN (site-to-site IPsec, SSL VPN), IPS, content/web filtering.
  • Network security: network segmentation, NAC/802.1X, ZTNA principles, firewall hardening.
  • Wireless: Ubiquiti UniFi - enterprise WLAN design, RF planning, controller management.
  • WAN & SD-WAN: circuit/ISP management, SD-WAN deployment, failover and redundancy.
  • Cloud networking: Azure VNets, NSGs, VPN Gateway, and hybrid connectivity.
  • Core protocols & services: TCP/IP, DNS, DHCP, subnetting, QoS.
  • Monitoring & documentation: network monitoring and topology tools, disciplined documentation.

Technical Skills - Preferred

  • Fortinet management & analytics: FortiManager and FortiAnalyzer (strong plus - central to how we manage our Fortinet footprint).
  • VoIP/SIP and voice QoS design.
  • Advanced Azure networking (ExpressRoute, Azure Firewall, peering).
  • PowerShell or scripting for network automation and reporting.
  • Structured cabling and physical-layer / IDF-MDF design.

Preferred Tool Experience

Familiarity with any of the following is a strong plus. You won’t be expected to know all of them on day one, but comfort learning new platforms quickly is essential:

Network & Firewall

  • Ubiquiti UniFi - Cloud Gateways, switching, access points, Network application / Site Manager
  • Fortinet - FortiGate firewalls, with FortiManager and FortiAnalyzer for centralized management and analytics

PSA, RMM & Remote Access

  • ConnectWise Manage - ticketing, time entry, billing, and project management
  • ConnectWise RMM (Asio) - cloud-native RMM for endpoint monitoring and scripted automation
  • ConnectWise ScreenConnect - remote access and support sessions

Monitoring & Documentation

  • Auvik - network monitoring, topology mapping, and configuration backup
  • IT Glue - documentation for network diagrams, credentials, SOPs, and asset records

Certifications (Preferred)

  • Fortinet: NSE 4 / FCP - FortiGate (with FortiManager / FortiAnalyzer specialist exams a plus)
  • Ubiquiti: UniFi Academy certifications - UEWA (Enterprise Wireless Admin), URSCA (Routing, Switching & Cybersecurity Admin), and/or UFSP (UniFi Full Stack Professional)
  • Cisco: CCNA (foundational routing & switching)
  • CompTIA: Network+, Security+
  • Microsoft: Azure Network Engineer Associate (AZ-700)

Soft Skills - Critical for Success

  • Ability to communicate complex networking and security concepts clearly to non-technical stakeholders.
  • Strong documentation discipline - you write things down so others can follow.
  • Self-directed and capable of managing multiple concurrent workstreams without close supervision.
  • Root cause mindset - you want to know why something happened, not just fix it and move on.
  • Professional presence and the ability to represent neteffect technologies at the client executive level., * Bachelor’s degree in IT, Computer Science, or related field - OR equivalent professional experience.
  • Valid driver’s license with clean driving record and appropriate insurance coverage.
  • Ability to lift up to 50 pounds occasionally.
  • Ability to pass background check and drug screening upon offer.

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Health savings account
  • Dental insurance, * Competitive salary ($75,000-$90,000) commensurate with experience
  • Comprehensive health and dental insurance
  • 401(k) with company matching
  • Paid time off
  • Performance-based bonus opportunities

Professional Development

  • Certification support and exam reimbursement
  • Access to Ubiquiti, Fortinet, and Microsoft partner resources, labs, and training
  • Mentorship and collaboration with experienced MSP engineers and leadership
  • Meaningful work that directly shapes client network posture and security maturity

Work Environment

  • Small-company culture that values technical depth, accountability, and autonomy.
  • No excessive bureaucracy - you’ll have room to make decisions and move fast.
  • Time split between the neteffect Charlotte office and client site visits.
  • Monday-Friday, day shift, with occasional after-hours or on-call support as needed., * 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Health savings account
  • Life insurance
  • Paid time off
  • Vision insurance

Compensation Package:

  • Bonus opportunities

About the company

Founded in 1991 and based in Charlotte, NC, neteffect technologies is an established Managed Service Provider delivering managed IT, cloud, security, virtualization, and telecom solutions to businesses across the region. We operate as a true technology partner - taking ownership of our clients’ IT environments so they can focus on running their business. Our engineering team supports a diverse portfolio of clients, backed by strong leadership and a culture of accountability and continuous improvement.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:18 min

Prioritizing communication and structural awareness over strict tool mastery

Liam Hurrel +1 ¡ WWC 2021

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner ¡ LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark ¡ LIVE

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa ¡ LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters ¡ WWC 2022

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas ¡ Europe 2026 Virtual

Videos

See all

Related articles

See all