About the role:
As a Network L2 Engineer, you will handle Day-2 operations and Day-1 project implementation of client network infrastructure. You will play a critical role in ensuring new network infrastructure setup and enhancement to existing network infrastructure, availability, performance, and security of network services.
Key responsibilities
- Plan and design LAN/WLAN solutions tailored to business requirements, including performing RF site surveys and analyzing coverage. Develop and document network topologies, capacity plans, and migration strategies. Implement and tune Wi-Fi networks (802.11 standards), optimize AP placement and coverage to ensure reliability.
- Plan, coordinate, and execute scheduled software and firmware upgrades for routers, switches, firewalls, and security appliances for managed customer networks. Liaise with vendors, service delivery managers, and customer stakeholders to plan maintenance windows and minimize downtime. Maintain comprehensive asset and version control records.
- Act as escalation point for network-related security incidents, coordinating with NOC teams and customer security contacts during investigations. Oversee implementation of security patches, hotfixes, and vulnerability mitigations. Lead root cause analysis activities and drive long-term remediation and security hardening initiatives.
- Maintain accurate and up-to-date inventory of all managed network assets including routers, switches, UPS systems, and firewalls across multiple customer sites. Ensure full lifecycle documentation including installation records, warranty details, maintenance logs, and asset conditions.
- Oversee enterprise-level IP Address Management (IPAM) across managed customer networks, ensuring optimal allocation, capacity planning, and compliance with customer standards. Maintain accurate IP address documentation, subnet inventory, and reservation policies.
- Provide L2 technical leadership for complex network incidents, ensuring rapid response and coordinated resolution across internal teams, service providers, and customer agencies. Lead diagnostic efforts to identify root causes of performance issues or connectivity disruptions.
- Oversee daily operational health checks and proactive monitoring of customer network infrastructure, ensuring early detection of anomalies. Review network performance trends, capacity utilization, and alert patterns to prevent service degradation.
- Lead coordination of facility power shutdown/recovery activities, ensuring network continuity and controlled failover during customer data center maintenance. Maintain and update power recovery runbooks.
- Provide standby and onsite support for operational activities including power shutdowns, routine patching, security remediations, and other scheduled or emergency maintenance activities.
- Own and maintain customer-specific documentation, including network diagrams, LLDs/HLDs, SOPs, runbooks, and configuration repositories. Mentor junior engineers in documentation standards and operational best practices.
- Conduct periodic reviews of network system accounts, validating user access, privilege levels, and compliance with least-privilege principles. Monitor privileged account activity and investigate suspicious or unauthorized access attempts.
- Ensure all network and security devices are integrated with customer SIEM/log repositories. Review logs for anomalies, security alerts, or operational risks.
- Oversee automated configuration backups for all managed network devices and validate backup integrity and accessibility. Lead annual disaster recovery exercises for customer environments.
- Conduct periodic configuration reviews to ensure compliance with customer standards, governance frameworks, and industry best practices. Lead firewall rule reviews and maintain configuration baselines.
- Deploy LAN/WLAN and security solutions including design, build, configure, test and provide required documentation and maintenance support.
- Deploy, configure, manage, and maintain Palo Alto, Check Point and Fortigate firewalls to ensure network security. Analyze, implement and maintain firewall policies. IPSEC configuration and understanding of IKE and Crypto map features.
- Configure, deploy and manage Cisco (Catalyst and Nexus), Alcatel and Juniper switches, ensuring optimal performance and network segmentation. Troubleshoot and resolve LAN connectivity issues in critical environments.
- Configure, deploy and manage Cisco Routers, ensuring optimal performance and network routing standards. Perform analysis and formulate plan for tech-refresh configuration. Troubleshoot and resolve WAN connectivity issues. IPSEC configuration and understanding of IKE and Crypto map features.
- Administer Aruba Clear Pass Policy Manager (CPPM) for user authentication and access control. Radius configuration, certificate upgrade/revocation configuration.
- Deploy and configure WLC on SSO and Flex connect and IAP or EWC concepts in Cisco wireless setup. AP management and RFID understanding. Troubleshoot and resolve WLAN connectivity issues in critical environments.
- Deploy new F5 LTM and setup SSL Proxy configuration, VIP configuration and iRule configuration.
- Ensure that network configurations and policies comply with industry best practices and security standards.
About you
- Bachelor's degree in information technology, Computer Science, or a related field
- Minimum 8 years of experience in handling Network and Security Domain
- Minimum Cisco Certified Network Professional (CCNP) is required
- Proven experience in managing Palo Alto, Check Point and Fortigate firewalls
- Proficiency in configuring and troubleshooting Cisco or equivalent switches and routers
- Hands-on experience with Aruba Clear Pass Policy Manager (CPPM) or similar access control systems
- Proficient in OSPF and BGP configuration
- Strong knowledge of network protocols, routing, and switching, and Wi-Fi standards (802.11 a/b/g/n/ac/ax)
- Excellent problem-solving and analytical skills
- Excellent skillset on network analysis and migration planning to handle network projects
- Effective communication and teamwork abilities
- PCNSE or CCSE equivalent certification is value added
- Familiarity with network monitoring and management tools
- ITIL Foundation certification or higher is preferred
- Experience in advanced network automation and ACI infrastructure deployment
- Experience in hybrid network transition from on-premises networks to cloud
#LPS