Job Description
Role & responsibilities
Roles & Responsibilities :
We are seeking a Senior IT/OT Network Engineer with a world-class foundation in Core Networking (Layer 2/3) and Secure Site-to-Site Connectivity who would be working on customer products/projects
Qualifications
SKILLS Needed:
Networking (L2/L3): Switching, STP, VLANs, BGP, OSPF, VRF, routing protocols
Firewall & Security: Cisco ASA / FTD / FMC, DMZ, Context design, segmentation
Zero Trust: ZPA / ZIA / Cisco ZTA, MFA, privileged access
Cloud AWS (Mandatory): VPC, EC2, Transit Gateway, Direct Connect, virtual firewall
Standards (Awareness): IEC 62443, NIST CSF, ISO 27001, Purdue Model
Certifications (Preferred): CCNP / CCIE, AWS Advanced Networking, CISSP
MUST-HAVE REQUIREMENTS
- Layer 2 / Layer 3 Networking — VLANs, STP, BGP, OSPF, VRF — must have designed in real environments, hands-on configuration experience on Cisco devices (Switches/Routers/Firewalls)
- Firewall Architecture — Hands-on Cisco ASA / FTD / FMC, DMZ, Context and segmentation design
- Zero Trust — Replaced VPN with ZTA, experience with Zscaler or Cisco ZTA
- AWS Cloud Networking — VPC, EC2, Transit Gateway, Direct Connect, Security Groups, virtual firewall on EC2 — mandatory, not optional
- Standards Awareness — Knows IEC 62443, NIST CSF, ISO 27001, Purdue Model at a conceptual level — does not need deep implementation experience
CLOUD NETWORKING DETAIL
Candidate must have hands-on AWS experience. Azure or GCP knowledge is a bonus but AWS is required.
- VPC & Subnets — Design public/private subnets, route tables, internet gateway, NAT gateway
- EC2 — Launch and configure instances, assign ENIs, Elastic IPs, IAM roles, Auto Scaling
- Virtual Firewall on EC2 — Deploy Cisco FTDv, Palo Alto VM-Series, or FortiGate as EC2 instances
- Virtual Router on EC2 — Deploy software routers (Cisco CSR 1000V / VyOS), BGP peering in AWS
- Connectivity — Direct Connect, Site-to-Site VPN, Transit Gateway for hybrid and multi-site
- Security — Security Groups, NACLs, AWS Network Firewall, VPC Flow Logs, CloudTrail
STANDARDS — AWARENESS LEVEL IS ENOUGH
Candidate should be able to discuss these standards in an interview — not implement them from scratch.
IEC 62443: Industrial cybersecurity standard — security zones, conduits, and security levels
NIST CSF: Identify, Protect, Detect, Respond, Recover — risk-based security framework
ISO / IEC 27001: Information security management system (ISMS) — how security is governed
Purdue Model: Layered industrial network model — why OT/IT segmentation is designed in levels
NERC CIP: Power grid cybersecurity compliance — awareness is fine for energy sector projects
EXPERIENCE EXPECTATIONS - Mandatory
- Experience — 8 to 10 years in network engineering
- Ownership — Has owned design and implementation decisions — not just followed instructions
- Leadership — Can review team designs, mentor engineers, and drive technical direction along with hands-on demonstration of core skills mentioned above
- Communication — Comfortable speaking to executives, customers, and compliance teams
- Certifications: CCNP
WHAT TO LOOK FOR IN A RESUME
- Job Titles — Sr. Network Security Engineer
- Cloud Projects — VPC designs, hybrid connectivity, virtual firewall/router deployments on EC2
- Certifications (Good-to-have) — CCIE, AWS Certified Advanced Networking, AWS Solutions Architect, CISSP
GOOD TO HAVE — NOT MANDATORY
- Any OT / SCADA exposure — even at project or client level
- Azure or GCP networking — as an addition to AWS
- Infrastructure as Code — Terraform, CloudFormation, or Ansible for network automation
Preferred candidate profile
Perks and benefits
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
