Network Engineer (Firepower + AWS)

Network Engineer (Firepower + AWS)

Posted 4 days ago by Xoriant

Negotiable
Inside
Hybrid
London Area, United Kingdom

Summary: The Network Engineer role focuses on providing advanced support for network technologies, particularly in cloud environments like AWS and Azure. The position requires expertise in firewall deployment, routing, switching, and various network protocols, alongside responsibilities for designing and implementing network connectivity solutions. The engineer will also act as an escalation point for managed services and ensure compliance with organizational standards across the network stack. This role is hybrid, requiring in-office presence two days a week in Canary Wharf, UK.

Key Responsibilities:

  • Provide last line support for network solutions in line with IT service management processes.
  • Act as an escalation point for network technology issues and re-engineering efforts.
  • Perform changes across the network stack, including cloud and on-premises datacenters.
  • Design and implement network connectivity between on-premises datacenters and the cloud.
  • Utilize AWS services such as Direct Connect, Transit Gateways, and site-to-site VPN.
  • Manage firewall rules and configurations using tools like Cisco CSM and FMC.
  • Debug network issues and perform packet captures and Wireshark traces.
  • Maintain knowledge of various firewall platforms and network management tools.

Key Skills:

  • Strong knowledge of cloud environments, specifically AWS and Azure.
  • Expertise in firewall deployment and management (Cisco ASA/FirePOWER, CheckPoint, Fortigate).
  • Proficiency in routing protocols (OSPF, BGP) and WAN technologies (MPLS, VPN, SDWAN).
  • Experience with datacenter technologies, including ACI and VxLAN.
  • Strong debugging skills and familiarity with network analysis tools (Wireshark).
  • Knowledge of network security practices and IPS across firewalls.
  • Understanding of Python and Postman is a bonus.
  • Relevant certifications (AWS, Cisco) and a degree in Engineering/Computer Science.

Salary (Rate): undetermined

City: London Area

Country: United Kingdom

Working Arrangements: hybrid

IR35 Status: inside IR35

Seniority Level: undetermined

Industry: IT

Detailed Description From Employer:

description: Network Engineer Hybrid (2 days a week) Contract (6+ Months) Inside IR35 Canary Wharf, UK Knowledge, skills, and abilities A solid network/security/cloud engineer with a strong focus on cloud hosted environments within AWS and Azure as well as excellent skills in firewall deployment, routing and switching. In-depth knowledge of design, implementation, configuration and testing of the following: Routing – OSPF, BGP, knowledge of route redistribution and manipulation. WAN - MPLS, Internet, VPN, SDWAN, understanding of circuit commissioning. Datacenter – ACI spine and leaf, APIC, VxLAN and distribution switching. Encryption - IPsec VPN, MACSec, configuring site-to-site VPN on routers and firewalls. Switching and L3 - HSRP, VRRP, GBLP, NTP, STP, RSTP, QoS, CoS, SVI, VLAN’s, ACL’s. WiFi – Cisco Meraki and Cisco Wireless LAN controllers with Lightweight APs. Firewalls – Cisco ASA/FirePOWER, Conversion from ASA code to Firepower, Checkpoint, Fortigate, ACL’s, CSM/FMC. Job purpose Provide last line support for solutions delivered by the engineering function in line with existing IT service management processes. Act as an escalation point, for the managed service, for problems pertaining to network technology and with a view to re-engineering. Perform all changes to organisation standards across the whole network stack, including cloud, on-premises datacenters, including internet edge and ACI Fabric, branch, WAN, and operate CSM/FMC to deploy firewall rules where required. To design and implement network connectivity between on premise datacenters and the cloud and within the cloud. This will require an extensive knowledge of Direct Connect, leveraged through Equinix Fabric and familiar with AWS DX gateways, AWS Transit Gateways (TGW) and site-to-site VPN, to connect other third parties into the cloud and the on-premises networks to the cloud. A thorough understanding of VPC and VPC peering is essential. Through knowledge of products across the AWS Market Place and familiar with setting up Cloud Services Routers (CSR’s) and firewalls from multiple vendors. These firewalls could be dual stack with separate vendors with HA being essential. This may extend to Autoscaling. Experience of AWS Firewall is preferred. Knowledge of IPS at all layers across the firewalls is required along with an understanding of FirePOWER services. Experience of implementing ExpressRoute within a hybrid Exchange environment, using a combination of on-premises servers and M365 SaaS. Comfortable with firewall platforms such as Cisco ASA/FirePOWER, CheckPoint, multiple context firewalls from Cisco and CheckPoint and the tools used to deploy the rules such as Cisco CSM (Cisco Security Manager), Cisco FMC (FirePOWER Management Centre), Fortigate/Fortinet etc. Strong debugging skills are required with the ability to run packet captures and wireshark traces. Good working knowledge of ACL’s. Good understanding of BGP and OSPF along with policy-based routing and prefixes lists. This routing knowledge should be across ASR/ISR and IOS-XE. A good understanding of NX-OS is required and any knowledge of ACI is preferred. Python and Postman is a bonus. Datacenter switching and routing comprises Cisco ACI Fabric with a spine and leaf topology. The engineer should be familiar with operation of ACI deployed within the core infrastructure. The datacenter also features firewalling between Tenants, such as Production, Secure Management and Dev/Test. Partners and vendors are connected via a separate VRF on the WAN and the webhosting environment features three tiered stacks (Cisco ASA, CheckPoint, Cisco ASA). Throughout this architecture, there are many DMZ’s so there should be a thorough understanding of all these technologies. The engineer will also need to have a good knowledge of the tools used within the network, such as CMC for Riverbed, CSM for Cisco ASA, Voyager and CheckPoint Manager for CheckPoint, CPI for WiFi, ISE for NAC and future deployment of technology, such as TrustSec, RSA tools, Solarwinds Orion, Cisco ACS and Infoblox etc. A strong knowledge of WireShark is also required. Qualifications / certifications: · Engineering/Computer Science Degree or industry related qualifications, such as AWS and Cisco Certifications.