02 Oct
|
ALOIS UK
|
City of Perth
02 Oct
ALOIS UK
City of Perth
Role Title: Senior Network Engineer (Onsite)
Role Summary
We are seeking a Senior Onsite Network Engineer with 8-10 years of hands-on experience managing enterprise network infrastructure across physical datacentres and campus/site environments. You are a seasoned network qualified who understands the core fundamentals of networking and datacentre operations - from cabling and rack-and-stack through to advanced routing, switching, and application delivery. You bring deep expertise in Cisco and Aruba platforms (physical and virtual, modern and legacy), and are an F5 BIG-IP expert with strong load balancer administration skills.
Critically, you have led or significantly contributed to IT separation programs at both a physical datacentre/site level and at an individual device level. This is an onsite role requiring physical presence for hands-on infrastructure work, incident response, and site-level project delivery.
Key Responsibilities
Core Network Services Management
- Manage and maintain all core network services across the enterprise - LAN, WAN, WLAN, DNS, DHCP, NTP, and internet edge
- Ensure high availability, performance, and resilience of network infrastructure supporting business-critical applications
- Design, implement, and maintain network segmentation (VLANs, VRFs, ACLs) aligned with security and operational requirements
- Manage network address planning (IP addressing schemes, subnetting, IPAM)
- Administer and troubleshoot routing protocols - OSPF, EIGRP, BGP (eBGP/iBGP), static routing
- Administer and troubleshoot switching technologies - STP/RSTP/MSTP, VTP, EtherChannel/LACP, port security, 802.1Q trunking
- Manage WAN connectivity - MPLS, SD-WAN, site-to-site VPN (IPSec, GRE), internet breakout
- Administer wireless network infrastructure - controller-based and cloud-managed deployments
- Manage DNS and DHCP services (Windows DNS, Infoblox, or equivalent)
- Monitor network health and performance using SNMP, NetFlow, syslog, and enterprise monitoring platforms
Cisco Platform Administration
- Administer and maintain Cisco routing platforms - ISR series (ISR 4000, ISR 1000), ASR series, CSR (virtual routers), Catalyst 8000
- Administer Cisco switching platforms - Catalyst 9000 series, Catalyst 3000/4000/6000 (legacy), Nexus 5000/7000/9000 (datacentre)
- Configure and manage Cisco ACI fabric or traditional Nexus-based datacentre switching where deployed
- Manage Cisco Wireless LAN Controllers (WLC) and Catalyst 9800 series controllers
- Administer Cisco firewalls - ASA and Firepower Threat Defense (FTD) managed via FMC
- Manage Cisco ISE for network access control (802.1X, MAB, profiling, posture assessment)
- Maintain Cisco DNA Centre / Catalyst Centre for network assurance and automation where deployed
- Support legacy Cisco platforms still in production (Catalyst 2960/3750, ISR G2 series) through to decommission
- Perform IOS/IOS-XE/NX-OS upgrades, patch management, and configuration standardisation
Aruba Platform Administration
- Administer Aruba wireless infrastructure - Aruba APs, Mobility Controllers, and Aruba Central (cloud-managed)
- Configure and manage Aruba CX switching platforms (CX 6000/8000 series) for campus and datacentre
- Manage Aruba legacy platforms (ArubaOS-Switch / ProCurve heritage) where still in production
- Implement and maintain Aruba Dynamic Segmentation and role-based access
- Administer Aruba ClearPass Policy Manager for network access control, guest access, and device profiling
- Manage Aruba SD-Branch and EdgeConnect SD-WAN where deployed
- Perform ArubaOS firmware upgrades, AP provisioning, and RF optimisation
- Maintain Aruba virtual platforms (VMC - Virtual Mobility Controllers) alongside physical appliances
F5 BIG-IP &
- Load Balancer Administration
- Serve as the F5 BIG-IP subject matter expert for the organisation
- Administer F5 BIG-IP LTM (Local Traffic Manager) - virtual servers, pools, nodes, monitors, persistence profiles, and iRules
- Configure and manage SSL offloading, certificate management, and TLS profiles on F5 platforms
- Administer F5 BIG-IP GTM/DNS for global server load balancing and DNS resolution
- Manage F5 BIG-IP ASM/Advanced WAF policies where deployed for application security
- Implement and maintain F5 BIG-IP APM for remote access and application-level access control where applicable
- Manage F5 platform upgrades (TMOS), hotfix deployment, and HA (active/standby, active/active) failover configurations
- Design and implement new load-balanced virtual services in collaboration with application teams
- Troubleshoot complex load balancing issues - health monitor failures, SSL handshake errors, persistence problems, iRule logic
- Manage F5 BIG-IP virtual editions (VE) alongside physical appliances
- Administer F5 via GUI (TMUI), CLI (TMSH), and iControl REST API for automation
- Produce and maintain F5 configuration documentation including VIP inventories, pool mappings, and certificate expiry tracking
IT Separation Programs (Datacentre &
- Device Level)
- Lead or significantly contribute to IT separation/divestiture programs involving physical network infrastructure
- Plan and execute site-level network separations - splitting shared datacentre environments into isolated network domains for divesting entities
- Perform device-level separations - reconfiguring shared routers, switches, firewalls, and load balancers to logically or physically segregate traffic between entities
- Design and implement transitional network architectures (DMZ interconnects, cross-connects, transit VLANs) to maintain service during separation transitions
- Migrate network services (DNS, DHCP, NTP, RADIUS/TACACS+) from shared to standalone infrastructure during separations
- Coordinate physical datacentre activities - cross-connect installations, cable migrations, rack relocations, and power/cooling considerations
- Manage firewall rule migrations and access control changes to enforce separation boundaries
- Decommission shared network infrastructure post-separation and validate clean removal
- Develop separation runbooks, cutover plans, rollback procedures, and risk registers
- Coordinate with project managers, application teams, and receiving entities on separation timelines and dependencies
- Validate post-separation network integrity - routing isolation, no traffic leakage, performance baseline confirmation
Datacentre &
- Physical Infrastructure
- Maintain physical datacentre network infrastructure - structured cabling (copper/fibre), patch panels, cable management, rack layout
- Manage datacentre interconnects - dark fibre, DWDM, cross-connects between cages/suites
- Understand and manage power and cooling considerations as they relate to network equipment placement
- Coordinate with datacentre facility teams on capacity planning, rack space allocation, and physical access
- Maintain physical network documentation - rack elevations, port maps, cable schedules, floor plans
- Manage hardware lifecycle - RMA processes, spare parts inventory, vendor hardware support contracts
- Perform hands-on rack-and-stack activities for new deployments and hardware refreshes
- Manage out-of-band management (OOBM) networks and console server access for remote recovery
Network Security
- Implement and manage firewall policies (Cisco ASA/FTD, Palo Alto, or equivalent)
- Configure and maintain VPN infrastructure - site-to-site IPSec, DMVPN, remote access VPN (AnyConnect)
- Administer network access control (Cisco ISE, Aruba ClearPass) - 802.1X, MAB, guest portals
- Implement micro-segmentation and zero-trust network access principles where applicable
- Manage DDoS mitigation and traffic scrubbing configurations
- Conduct regular firewall rule reviews and cleanup in coordination with security teams
- Support penetration testing and vulnerability remediation activities from a network perspective
Operations, Documentation &
- Leadership
- Serve as L3/L4 escalation point for all network infrastructure incidents and problems
- Provide onsite incident response for P1/P2 network outages - hands-on troubleshooting and restoration
- Participate in on-call rotation for critical network infrastructure
- Mentor and upskill junior network engineers on Cisco, Aruba, F5, and general networking
- Maintain comprehensive network documentation - topology diagrams (Visio/draw.io), configuration standards, runbooks, SOPs
- Participate in Change Advisory Board (CAB) meetings and own network change requests
- Plan and execute maintenance windows for firmware upgrades, hardware replacements, and configuration changes
- Collaborate with Security, Server,
Cloud, and Application teams on cross-functional projects
- Manage vendor relationships and support contracts (Cisco TAC, Aruba TAC, F5 Support)
- Drive network modernisation and tech debt reduction initiatives
Required Experience &
- Skills
- 8-10 years of progressive experience in network engineering, with significant onsite/datacentre exposure
- Deep Cisco expertise - routing (ISR, ASR, CSR), switching (Catalyst, Nexus), wireless (WLC/9800), security (ASA/FTD), across modern and legacy platforms
- Strong Aruba expertise - wireless (APs, Mobility Controllers, Aruba Central), switching (CX series), ClearPass, including legacy ProCurve/ArubaOS-Switch platforms
- F5 BIG-IP expert - LTM administration (virtual servers, pools, monitors, iRules, SSL offloading), GTM/DNS, platform upgrades, HA management
- Proven experience in IT separation programs - physical datacentre/site-level separations and device-level logical/physical segregation
- Deep understanding of networking fundamentals - OSI model, TCP/IP, subnetting, routing protocols (OSPF, BGP, EIGRP), switching (STP, VLANs, LACP)
- Strong datacentre knowledge - structured cabling, rack-and-stack, cross-connects, power/cooling, physical documentation
- Experience with network security - firewalls, VPN, NAC (802.1X), ACLs, network segmentation
- Hands-on WAN/SD-WAN experience - MPLS, IPSec VPN, SD-WAN overlays
- Proficiency with network monitoring tools - SolarWinds (NPM/NCM), PRTG, or equivalent
- Experience with network automation - Ansible, Python (Netmiko, NAPALM), or equivalent
- Robust troubleshooting skills - packet capture analysis (Wireshark), protocol debugging, systematic root cause analysis
- Experience working within ITIL frameworks and ITSM tools (ServiceNow, Jira)
- Comfortable working in physical datacentre environments - lifting equipment, working in raised-floor environments, managing cabling
- Excellent communication skills - able to produce clear documentation and communicate with technical and non-technical stakeholders
Desirable / Differentiating Experience
- Cisco certifications: CCNP Enterprise (or higher), CCNP Security, CCIE (any track)
- Aruba certifications: ACNP, ACNX, or equivalent
- F5 certifications: F5 Certified Administrator, F5 Certified Technical Specialist (LTM)
- Experience with Palo Alto firewalls (additional to Cisco ASA/FTD)
- Hands-on with Cisco ACI fabric administration
- Experience with SD-WAN platforms (Cisco Viptela/SD-WAN, Aruba EdgeConnect, Fortinet)
- Background in network automation at scale - Ansible playbooks, Python scripting, CI/CD for network config
- Experience with cloud networking - AWS VPC/TGW, Azure VNets, or hybrid connectivity (Direct Connect/ExpressRoute)
- Familiarity with network-as-code principles and source-controlled configurations
- Experience in M&A; or divestiture programs spanning multiple sites or geographies
- Background in regulated industries (financial services, healthcare, government) with compliance requirements
- Experience managing large-scale network refresh programs (multi-site switch/router replacements)
Key Performance Indicators
- Network availability maintained at >99.95% across core infrastructure
- IT separation milestones delivered on schedule with zero unplanned outages or traffic leakage
- F5 virtual service availability >99.99% for business-critical applications
Network incident MTTR within agreed SLAs (P1:
- Zero critical audit findings related to network security (firewall rules, segmentation, NAC)
- Firmware/patch compliance across network estate within defined SLA windows
- Network documentation accuracy - quarterly audit with >95% accuracy
- Change success rate >98% (changes implemented without causing incidents)
- Successful mentoring - junior engineers handling L2 incidents independently within 6 months
Category Tools
Routing &
- Switching Cisco ISR, ASR, Catalyst 9000, Nexus 5K/7K/9K, Aruba CX
Wireless Cisco WLC/9800, Aruba Mobility Controllers, Aruba Central
Load Balancing F5 BIG-IP (LTM, GTM, ASM, APM), F5 VE
Firewalls Cisco ASA, Firepower/FTD (FMC managed)
NAC Cisco ISE, Aruba ClearPass
WAN/SD-WAN MPLS, IPSec, Cisco SD-WAN, Aruba EdgeConnect
Monitoring SolarWinds (NPM, NCM), PRTG, NetFlow collectors
Automation Ansible, Python (Netmiko, NAPALM), REST APIs
Documentation Visio/draw.io, NetBox, IPAM
ITSM ServiceNow / Jira
Packet Analysis Wireshark, tcpdump, SPAN/TAP
Datacentre Structured cabling, fibre (SM/MM), cross-connects, OOBM
📌 Senior Onsite Network Engineer (City of Perth)
🏢 ALOIS UK
📍 City of Perth