[Hiring] Senior Network Engineer @TekCommands
Senior Network Engineer @TekCommands
Engineering
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type contract
Posted YDay

[Hiring] Senior Network Engineer @TekCommands

YDay - TekCommands is hiring a remote Senior Network Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

We're hiring a Senior Network Engineer to lead the design, implementation, and ongoing support of secure, scalable enterprise networks with a strong emphasis on HPE Aruba switching/wireless and Fortinet FortiGate (WAN/SD-WAN + security). This is a senior, hands-on role responsible for network architecture, operational excellence, troubleshooting complex incidents, and driving standards across LAN/WAN/WLAN and perimeter/edge security.

Work model: Remote. Travel: Up to 50% travel for the first 6 months (site assessments, deployments, cutovers), then reduced travel as the environment stabilizes.

Environment scope: ~45 sites, 2 data centers, ~1,100 staff.

Key Responsibilities

  • Own end-to-end network delivery: architecture, design, implementation, and support of enterprise LAN/WAN/WLAN and security services across ~45 sites and 2 data centers.
  • Lead WAN and SD-WAN engineering (FortiGate-centric):
    • Design, deploy, and operate FortiGate SD-WAN for multi-site connectivity, application steering, SLA monitoring, and resilient failover.
    • Engineer and operate BGP over SD-WAN between sites and eBGP with ISPs at data centers, including route policy, filtering, and resiliency.
    • Design and operate multi-homed / dual-ISP data center connectivity with resilient routing and failover.
    • Standardize branch templates, circuit turn-ups, and cutover runbooks; coordinate with ISPs and on-site resources.
    • Build and maintain hub-and-spoke and/or partial mesh VPN topologies as required (IPsec/ADVPN where applicable).
  • Lead Fortinet security engineering:
    • Engineer and administer FortiGate policies, NAT, segmentation, and security profiles (IPS/AV/web filtering/app control).
    • Use FortiManager (required) to manage policy packages, device groups, templates, and controlled change/release processes across the fleet.
    • Implement and operate logging/analytics (e.g., FortiAnalyzer nice-to-have) including reporting and incident support.
    • Design and maintain HA pairs/clusters, firmware lifecycle, and change control.
  • Lead Aruba campus switching + wireless:
    • Design and operate Aruba switching (VLANs, STP, LACP, VRRP, QoS) and ensure consistent standards across sites.
    • Design and optimize Aruba wireless (RF design, AP placement guidance, roaming, guest access, WPA2/3).
    • Administer Aruba centralized platforms and NAC:
      • Aruba Central and/or AirWave for monitoring, configuration, and lifecycle management.
      • ClearPass for 802.1X, guest access, profiling, and policy enforcement.
  • Execute and operationalize Zero Trust networking principles:
    • Implement least-privilege access and segmentation (zones, VLANs/VRFs, policy-based controls) aligned to business/application requirements.
    • Support identity-aware access patterns (802.1X/NAC, MFA-integrated remote access, conditional access concepts where applicable).
    • Partner with security stakeholders to align network controls with Zero Trust initiatives (device posture signals, logging/telemetry, and continuous verification).
  • Deliver secure access and identity-integrated networking:
    • Implement 802.1X with RADIUS/TACACS+, certificate-based auth where applicable, and integration patterns with directory/IdP.
    • Support remote access VPN solutions (SSL/IPsec) and MFA integration patterns.
  • Operate and improve reliability:
    • Lead complex incident response and deep troubleshooting across layers (L1–L7), including packet captures and log analysis.
    • Perform root cause analysis (RCA) and drive permanent corrective actions.
    • Monitor performance, availability, and capacity; tune for resiliency and throughput.
  • Documentation and standards:
    • Maintain network diagrams (logical/physical), IP plans, firewall rule standards, SD-WAN policies, and operational runbooks.
    • Establish configuration baselines, naming conventions, and change/release procedures.
  • Stakeholder and cross-functional collaboration:
    • Partner with security, systems, telecom/ISP providers, and application teams to deliver reliable connectivity.
    • Provide technical leadership and mentorship to junior engineers; review designs and changes.

Qualifications

  • 7+ years of progressive experience in network engineering (enterprise or MSP environments), including multi-site WAN operations.
  • Strong hands-on expertise with Fortinet FortiGate, including:
    • SD-WAN design/operations, VPN (IPsec/SSL), routing, NAT, security profiles, and segmentation.
    • BGP (iBGP/eBGP), route policy, and troubleshooting in multi-site environments.
    • Proven experience designing/operating multi-homed / dual-ISP connectivity at data centers.
    • FortiManager (must-have) for centralized configuration and policy management at scale.
  • Strong hands-on expertise with HPE Aruba in production, including:
    • Aruba switching and enterprise WLAN.
    • Aruba Central/AirWave administration.
    • ClearPass (or equivalent NAC) for 802.1X/guest workflows.
  • Experience executing Zero Trust concepts in real environments (segmentation, least privilege, identity-aware access, and operational telemetry).
  • Deep understanding of core networking:
    • TCP/IP, subnetting, routing (BGP required; OSPF preferred), switching, VLANs, STP, QoS.
    • DNS/DHCP fundamentals and common troubleshooting patterns.
  • Proven ability to troubleshoot complex issues using packet captures, logs, and structured RCA.
  • Experience with change management, maintenance windows, and production cutovers.
  • Strong documentation and communication skills; comfortable leading remote deployments with on-site coordination.
  • Ability to travel up to 50% for the first 6 months.

Preferred Qualifications

  • Fortinet: ADVPN (design, deployment, and troubleshooting), advanced SD-WAN design patterns, HA/cluster design, advanced UTM tuning, ZTNA/SASE exposure.
  • FortiAnalyzer experience (reporting, event investigation, log retention strategy).
  • Aruba: advanced RF optimization, large-scale Aruba Central operations, ClearPass posture/profiling at scale.
  • Multi-vendor experience (Cisco/Juniper/Arista/Palo Alto) and hybrid environments.
  • Automation/scripting: Python, Ansible, Terraform, or API-driven network operations.
  • Monitoring/observability: SNMP/NetFlow/sFlow, syslog/SIEM integration, synthetic monitoring.
  • Cloud networking exposure (Azure/AWS networking, VPN/ExpressRoute/Direct Connect).

Certifications

  • Fortinet: NSE 4+ (or current Fortinet certification equivalents).
  • Aruba: ACMP/ACSP (or equivalent Aruba switching/wireless certs).
  • Other relevant certs: CCNP, JNCIP, Security+.

What Success Looks Like (First 90 Days)

  • Complete discovery and documentation for the 45-site / 2-DC environment (diagrams, IP plan, SD-WAN topology, Aruba Central/ClearPass baselines).
  • Stabilize SD-WAN and BGP routing behavior (reduce outages, improve failover behavior, standardize templates and route policy).
  • Improve operational hygiene: firmware lifecycle plan, backup/restore procedures, configuration standards, and change control via FortiManager.
  • Deliver at least one measurable improvement:
    • Reduced WAN incidents/tickets.
    • Improved site cutover time and consistency.
    • Improved WLAN performance/roaming and reduced wireless escalations.

Working Conditions

  • Remote role with up to 50% travel for the first 6 months (site assessments, deployments, cutovers).
  • After 6 months: travel expected to decrease based on project phase and operational stability.
  • On-call: [Rotation details]

Equal Opportunity Statement

[Insert your standard EEO statement here.]

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Network Engineer @TekCommands
Engineering
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type contract
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later