Candidates should be strong in the below mentioned areas:
โข Telco/Carrier experience
โข MPLS (L2VPN / L3VPN / MPLS Lite / Tagging)
โข DWDM
โข IP WAN and Routing (BGP / iBGP / eBGP / AS Networks)
โข Cloud (AWS or Azure) networking expertise is a strong plus
We are hiring for an L4 Network Architect/Engineer toย lead design and delivery of multiโsite Cisco SoftwareโDefined Access (SDโAccess) solutions at scale. Contribute to and implement architecture direction, drive complex deployments across distributed campuses, and mentor engineers while partnering closely with security and operations. The ideal candidate holds anย active CCIE and demonstrates deep, handsโon expertise across Cisco routing/switching, Cisco Catalyst Center (formerly Cisco DNA Center), Cisco ISE, Cisco FTD firewalls, and Cisco SDโWAN, with expertโlevel command of BGP, EIGRP, OSPF, and related enterprise routing protocols.
What youโll do (Key Responsibilities)
Own endโtoโend SDโAccess architecture for large, multiโsite enterprises: fabric design (control/edge/border), transit options, segmentation (SGTs/TrustSec), identity policy, and integration with WAN and data center.
Lead Catalyst Centerโdriven automation: design templates, SDA workflows, network assurance, SWIM, and closedโloop operations aligned to reliability/SLOs.
Design identityโcentric security with ISE: policy sets, authorization profiles, posture, PxGrid integrations, wired/wireless 802.1X/MAB, guest/BYOD, and scalable group policies.
Engineer secure edge and campus perimeters: Cisco FTD/Firepower policy design, NAT, VPN, IDS/IPS, SSL decryption strategy, and high availability.
Architect SDโWAN underlay/overlay: transport independence, applicationโaware routing, DIA/Cloud onโramp, security integration, and multiโregion scale.
Expert routing at scale: BGP (policy, route reflectors, communities), OSPF, EIGRP, ECMP, redistribution strategies, route filtering, summarization, and IPv6 planning.
Drive modernization roadmaps: brownfield to SDA migration, hierarchical campus design, QoS, multicast, wireless controller (Catalyst 9800) alignment, and resiliency patterns.
Deliver handsโon build and escalation leadership: lab validation, pilot, phased rollout, cutover plans, MOPs, change windows, and rootโcause analysis for P1/P2 incidents.
Mentor and uplift engineering teams: design reviews, standards, runbooks, and enablement sessions for operations and field engineers.
Stakeholder leadership: collaborate with security, EUC, cloud, and application teams; translate business outcomes into technical architectures and measurable milestones.
Documentation & governance: HLD/LLD, asโbuilts, standards, security exceptions, and compliance artifacts; contribute to reference architectures and reusable templates.
Required Qualifications (MustโHave)
Active CCIE (any track; Enterprise Infrastructure and/or Security strongly preferred).
10+ years enterprise networking experience, includingย 3โ5+ years leading SDโAccess architecture and deployment across multiple sites.
Proven, exceptionalย handsโon skills with Cisco routing/switching and Catalyst Center (formerly Cisco DNA Center) for SDA automation and assurance.
Deep expertise withย Cisco ISE (policy, 802.1X, SGT/TrustSec) and Cisco FTD (Firepower) firewalls (threat, access control, NAT/VPN, high availability).
Strong experience withย Cisco SDโWAN (design, policy/templating, security integration, operationalization).
Expertโlevel knowledge ofย BGP, EIGRP, OSPF, redistribution, and routeโpolicy design for large enterprises.
Demonstrated successย leading complex, multiโphase migrations and mentoring senior engineers.
Preferred Qualifications
CCDE or dual CCIE; Cisco Certified Specialist certifications in SDA, ISE, or SDโWAN.
Automation fluency (Ansible, Python, Terraform), Gitโbased workflows, and API integration with Catalyst Center/ISE/FTD/SDโWAN.
Wireless (Catalyst 9800/Prime/Catalyst Center Assurance), QoS strategy, multicast, NAC posture, and Zero Trust segmentation.
Cloud networking (Azure/AWS), hybrid connectivity, and DNS/DHCP/IPAM integration.
Familiarity with data center and campus interconnectย (e.g., ACI concepts beneficial but not required).