Principal Network Engineer – Global Infrastructure & Cyber Resilience
Commvault (NASDAQ: CVLT) is the gold standard in cyber resilience. The company empowers customers to uncover, take action, and rapidly recover from cyberattacks – keeping data safe and businesses resilient. The company’s unique AI-powered platform combines best-in-class data protection, exceptional data security, advanced data intelligence, and lightning-fast recovery across any workload or cloud at the lowest TCO. For over 25 years, more than 100,000 organizations and a vast partner ecosystem have relied on Commvault to reduce risks, improve governance, and do more with data.
About the role
As a Principal Network Engineer at Commvault, you will not just sit in an ivory tower drawing diagrams. We are looking for a Player-Coach—a technical heavyweight who possesses the vision to architect a global network and the grit to build and troubleshoot it personally. This role is defined by Deep Execution. You will own the full lifecycle of our global connectivity fabric, from the initial whiteboarding of a Zero Trust framework to the hands-on configuration of the solution and the resolution of complex multi-cloud routing issues. If you are a high-level architect who has moved away from the CLI, this is not the role for you; we need a leader who stays "close to the packets" while guiding our long-term technical strategy.
Responsibilities
- Hands-On Technical Leadership & Execution
- Build & Deploy: Take primary responsibility for the "First Build." Lead the hands-on implementation of global SD-WAN and Cloud nodes, ensuring the transition from design to production is flawless.
- Deep-Dive Troubleshooting: Act as the ultimate technical escalation point. When Tier-3 hits a wall, dive into the logs, PCAPs, and routing tables to identify and fix the root cause.
- Network-as-Code: Personally develop and maintain Terraform and Ansible playbooks to automate the global environment, driving the execution of automation, not just suggesting it.
- Multi-Cloud & SD-WAN Sovereignty
- GCP & Azure Execution: Physically build and manage the transit gateways, VPC/VNet peering, and Cloud Interconnects that power our multi-cloud ecosystem.
- SD-WAN Mastery: Take the lead in configuring Prisma Access and NGFWs. Own the policy engine, hands-on, ensuring security is baked into every route and interface.
- Zero Trust Integration: Move beyond the "Zero Trust" buzzword by executing actual micro-segmentation and identity-based access controls across our hybrid footprint.
- Security & Edge Engineering
- Zscaler and Firewall Expert: Act as the Subject Matter Expert (SME) for Next-Generation Firewalls (NGFW), Zscaler Private Access (ZPA) and Zero Trust Network Access (ZTNA). Own the global policy sets, SSL decryption strategies, and threat prevention profiles.
- Hybrid Connectivity: Manage complex Site-to-Site VPNs, GRE tunnels, and high-speed interconnects that link our global data centers with public cloud regions.
- Mentorship, Leadership & Executive Presence
- Strategic Influence: Partner with the CISO and Director of Infrastructure to align networking goals with broader business initiatives.
- Technical Mentorship: Lead and upskill a global team of senior and mid-level engineers. Conduct architectural reviews and set the "gold standard" for documentation and code-based infrastructure.
- Vendor Management: Lead technical evaluations and QBRs with key partners (Google, Microsoft, Palo Alto), ensuring Commvault is leveraging the latest features and optimal pricing.
- Lead by Example: Set the technical standard for the engineering team by demonstrating best practices in configuration, documentation, and operational discipline.
- Executive Communication: Translate complex technical "war stories" and execution hurdles into concise executive summaries for leadership, providing clear paths for risk mitigation.
- Automation & Excellence
- Infrastructure as Code (IaC): Champion a "Network-as-Code" mindset using Terraform, Ansible, or Python to automate repetitive tasks and ensure 100% configuration consistency.
- Operational Resilience: Own Tier-4 escalations for complex network outages. Lead Root Cause Analysis (RCA) sessions that translate technical failures into actionable business improvements.
Requirements
- 12+ years in Network Engineering, with a career path that proves you have never lost your "hands-on" edge.
- Preferably located in New Jersey to help own the hardware in the corporate data center.
- "In-the-Trenches" Expertise: Proven ability to build, operate, and troubleshoot complex environments across Palo Alto (PCNSE level), GCP, and Azure.
- Direct experience deploying Zscaler SD-WAN and implementing ZTNA frameworks in a global enterprise.
- Expert-level mastery of BGP, EVPN/VXLAN, and stateful firewalling.
- High proficiency in Python or Terraform for infrastructure deployment.
- Exceptional written and verbal communication skills. Ability to explain the "why" behind a $2M infrastructure investment to a Board of Directors as easily as debugging a packet drop with an engineer.
Preferred Qualifications
- Zscaler: ZTDA or ZTDE
- Cloud: Google Professional Cloud Network Engineer or Azure Network Engineer Associate (AZ-700)
- General: CCIE (Route/Switch or Security) is highly valued but not required if equivalent experience is demonstrated
Benefits
- Continuous professional development, product training, and career pathing
- An inclusive company culture, opportunity to join our Employee Groups
- Generous benefits supporting your health, financial security, and work-life balance
- Employee stock purchase plan (ESPP)
Pay
Pay Range: $93,500—$182,850 USD