Senior Network Engineer

Công ty TNHH Shelby GlobalQuận Bốn, Thành phố Hồ Chí Minhglintspaskelbta 2026-08-12
Privaloma:PythonAWSAzureGoogle CloudCloudSecuritySeniorLeadJuniorRemoteHybrid

Job description Network Implementation & Engineering

  • Lead end-to-end implementation, configuration, upgrade, and migration of all routing and switching infrastructure across CES global sites.
  • Design, deploy, and maintain enterprise-scale network architecture for a multi-site, multi-circuit WAN environment with a focus on high availability, redundancy, and fault tolerance.
  • Architect and implement advanced dynamic routing configurations including BGP, OSPF, and EIGRP in complex, multi-path, multi-vendor environments.
  • Develop and enforce network standards, design patterns, and configuration baselines across the enterprise; maintain and improve change management procedures.
  • Lead network lifecycle projects from requirements definition through cutover and post-implementation review, including rollback and contingency planning.
  • Evaluate and recommend network technologies, vendors, and platforms aligned with CES growth and security requirements.

Security & Firewall Platform Administration

  • Own full lifecycle management of network security platforms including Cisco ASA, Cisco Firepower / FMC, and Palo Alto Networks NGFWs; Fortinet is being evaluated for future remote site deployments and familiarity is valued.
  • Administer Cisco ISE for network access control (NAC), 802.1X enforcement, RADIUS/TACACS+ policy, guest access workflows, and endpoint profiling at enterprise scale.
  • Administer and maintain F5 BIG-IP Application Delivery Controllers and Web Application Firewalls (WAF), including virtual server configuration, SSL offloading, load balancing profiles, and application firewall policy.
  • Develop and maintain firewall rule sets, access control policies, and network segmentation strategies aligned with security, compliance, and business requirements.
  • Serve as the senior escalation owner and subject matter expert for all firewall and network security incidents.

WAN & Connectivity

  • Manage multi-site WAN topology including primary and failover circuit configurations, SLA monitoring, performance optimization, and carrier coordination.
  • Design and maintain VPN infrastructure for site-to-site, DMVPN, and remote access connectivity across a geographically distributed environment.
  • Implement and tune QoS policies to prioritize business-critical and operational technology traffic across WAN and LAN segments.
  • Evaluate and recommend WAN optimization and SD-WAN solutions as the network evolves.

Cloud & Hybrid Network Integration

  • Lead the integration of on-premises network architecture with cloud environments including AWS, Azure, and/or GCP, encompassing Transit Gateway, Direct Connect, ExpressRoute, and IPsec/VPN connectivity.
  • Collaborate with Cloud and IS teams to design hybrid routing architectures that meet performance, security, and cost objectives.
  • Configure and support cloud-native networking constructs including VPCs, VNets, security groups, routing tables, and network ACLs.
  • Contribute to cloud architecture reviews and infrastructure roadmap activities to ensure consistent network design and security posture across the hybrid environment.

Monitoring, Troubleshooting & Operations

  • Monitor network performance, availability, and capacity across all sites and circuits using enterprise monitoring platforms; proactively identify and resolve issues before business impact.
  • Provide Tier 3 escalation support for network incidents, performing root cause analysis and implementing permanent corrective actions.
  • Maintain accurate and current network documentation including topology diagrams, IP address management records, runbooks, and change history.
  • Manage competing operational priorities across concurrent workstreams, communicating status clearly to IS leadership and relevant stakeholders.
  • Engage directly with internal clients across CES business lines and external clients to support connectivity requirements, coordinate resolution of service-impacting issues, and communicate clearly -- in both technical and non-technical terms -- as the situation requires.
  • Participate in a rotating on-call schedule, including nights and weekends, to support 24x7 network availability and rapid incident response.
  • Mentor junior IS team members on networking concepts, tools, and operational practices.

Job requirements Required

  • 7+ years of hands-on enterprise network engineering experience in a multi-site, multi-vendor environment.
  • Demonstrated experience operating at enterprise scale in a globally distributed organization with multiple remote locations and hybrid on-premises and cloud infrastructure.
  • Proven, ownership-level experience with Cisco ASA and Cisco Firepower / FMC, including policy management, NAT, IPS/IDS, and SSL inspection.
  • Proven, ownership-level experience with Cisco ISE for 802.1X NAC, RADIUS/TACACS+, profiling, and posture assessment.
  • Proven, ownership-level experience with F5 BIG-IP, including LTM, AFM, and ASM/WAF modules.
  • Advanced proficiency in BGP, OSPF, and EIGRP dynamic routing protocol configuration, troubleshooting, and optimization in complex, multi-path environments.
  • Demonstrated expertise in WAN architecture, multi-circuit design, redundancy, and fault-tolerant topology.
  • Hands-on experience integrating on-premises infrastructure with cloud environments (AWS, Azure, and/or GCP), including hybrid routing, connectivity, and security. This is a firm requirement.
  • Experience with physical network equipment from multiple vendors; familiarity with Palo Alto Networks and Fortinet platforms is valued, with Fortinet of particular relevance as CES evaluates it for future remote site deployments.
  • Proven ability to manage competing priorities across multiple concurrent projects and operational demands in a fast-paced, dynamic environment.
  • Excellent written and verbal communication skills with the demonstrated ability to engage clearly and professionally with technical and non-technical stakeholders across all levels of an organization. This is a firm requirement of this role.
  • Demonstrated experience in a client-facing capacity, engaging directly with both internal business stakeholders and external clients -- including their technical and non-technical representatives -- to coordinate solutions, convey service impact, and maintain trust during high-pressure situations.
  • Knowledge, demonstrated skills, and breadth of relevant experience are the primary qualifications for this role. A bachelor's degree in Information Technology, Computer Science, Network Engineering, or a related field is preferred; equivalent professional experience is fully considered.

Preferred Certifications

  • Cisco Certified Network Professional (CCNP) -- Enterprise or Security track
  • Cisco Certified Internetwork Expert (CCIE) -- highly desirable
  • Cisco Firepower Specialist or related Cisco Security certification
  • Palo Alto Networks Certified Network Security Engineer (PCNSE)
  • F5 Certified Administrator (F5-CA) or F5 Certified Technology Specialist (F5-CTS)
  • Cisco ISE Specialist certification
  • Fortinet NSE 4 or higher (relevant as Fortinet is evaluated for future remote site deployments)

Preferred / Ideal

  • Experience with SD-WAN platforms such as Cisco Viptela, Meraki, Palo Alto Prisma, or comparable solutions.
  • Proficiency in network automation and scripting (Python, Ansible, Terraform, or similar) to support infrastructure-as-code practices.
  • Experience in regulated or compliance-driven environments (SOC 2, NERC CIP, or similar).
  • Experience with enterprise network monitoring and observability platforms (SolarWinds, PRTG, Kentik, or comparable).
  • Exposure to zero-trust network access (ZTNA) or Secure Service Edge (SSE) frameworks.

Benefits

  • Salary: Negotiable, depending on experience and suitability.
  • 13th-month salary.
  • 12 days of annual leave per year.
  • Health insurance coverage for employees.
  • Additional health insurance support/coverage for family members according to company policy.
  • Free parking.
  • Fitness/gym-related benefits.
  • Regular employee engagement and team-building activities.

Skills: Microsoft Excel, Firewall, LAN, Microsoft Word, Network Monitoring, Teamwork, Microsoft Office, Network Security, Cisco, Customer Service