Jobs · Information Technology · California

Senior Enterprise L3 Network Engineer

Sibitalent Corp · Pleasanton, CA · 5 days ago
On-siteInformation TechnologyContract

Clorox is seeking a highly experienced Senior Enterprise L3 Network Engineer to serve as a technical Subject Matter Expert across enterprise networking, data center infrastructure, cloud connectivity, cybersecurity, SD-WAN, and manufacturing/Operational Technology (OT) environments. The ideal candidate will have deep, hands-on expertise in BGP routing and enterprise-scale Cisco networking, combined with strong experience in Palo Alto firewalls, OT network security/microsegmentation, industrial Wi-Fi, SD-WAN, and multi-cloud networking. This is a highly technical L3/SME role requiring someone who can independently troubleshoot complex network issues, architect and implement network solutions, lead modernization initiatives, and collaborate effectively with infrastructure, cybersecurity, cloud, manufacturing, and business teams. Candidates must be local to Pleasanton, CA and able to work onsite. Some light travel to other company/manufacturing locations may be required.

Responsibilities

  • BGP Routing & Advanced Core Networking SME
    • Serve as the Subject Matter Expert for BGP routing across enterprise data centers, WAN, campus, and cloud environments.
    • Design, implement, optimize, and troubleshoot eBGP and iBGP architectures.
    • Work extensively with BGP-EVPN, route reflectors, community tagging, route filtering, path manipulation, and traffic engineering.
    • Design and support enterprise-scale Cisco routing and switching infrastructure, including:
      • Cisco Catalyst
      • Cisco Nexus
      • Cisco ISR/ASR
    • Provide advanced L3 routing expertise across:
      • BGP
      • OSPF
      • EIGRP
      • MPLS
      • Route redistribution
    • Design and troubleshoot complex Layer 2/Layer 3 architectures, including:
      • VLANs
      • STP
      • EtherChannel
      • HSRP
      • QoS
    • Analyze complex routing issues and provide permanent solutions rather than temporary workarounds.
    • Lead network performance optimization, traffic engineering, and routing modernization initiatives.
  • OT Network Security & Microsegmentation
    • Lead network security initiatives across manufacturing, industrial, SCADA, PLC, and MES environments.
    • Design and implement Zero Trust and OT microsegmentation strategies to protect critical industrial assets.
    • Develop segmentation architectures that minimize security blast radius while maintaining required manufacturing operations.
    • Apply industry standards and security principles including:
      • IEC 62443
      • NIST SP 800-82
      • Zero Trust networking
      • Purdue Model architectures
    • Work with cybersecurity and manufacturing teams to map OT communication flows and implement appropriate security controls.
    • Utilize technologies such as Cisco ISE, Forescout, Palo Alto, Nozomi, or similar OT/ICS security platforms.
    • Troubleshoot connectivity and security issues across IT/OT network boundaries.
  • OT / Industrial Wi-Fi
    • Architect, deploy, and optimize industrial wireless networks within manufacturing and plant-floor environments.
    • Conduct or support RF site surveys and wireless coverage analysis.
    • Design Wi-Fi solutions for environments with:
      • High interference
      • High device density
      • Industrial equipment
      • Manufacturing-floor mobility requirements
    • Troubleshoot wireless performance, roaming, interference, capacity, and coverage issues.
    • Ensure wireless infrastructure supports both operational requirements and enterprise security standards.
    • Collaborate with plant engineering and OT teams on wireless modernization initiatives.
  • Palo Alto Firewall & Zero Trust Security
    • Administer and support Palo Alto Strata Next-Generation Firewalls in large enterprise environments.
    • Manage Palo Alto Panorama for centralized firewall administration and policy management.
    • Configure and troubleshoot:
      • Security policies
      • NAT
      • Routing
      • VPN
      • GlobalProtect
      • Application controls
      • Network segmentation
    • Translate Purdue Model and IT/OT segmentation requirements into modern firewall architectures.
    • Support Zero Trust network security initiatives across enterprise and manufacturing environments.
    • Perform advanced troubleshooting of firewall, routing, VPN, and security-policy issues.
  • SD-WAN & Hybrid WAN Engineering
    • Design, deploy, maintain, and troubleshoot enterprise SD-WAN environments.
    • Provide hands-on expertise with:
      • Cisco Viptela SD-WAN
      • Palo Alto Prisma SD-WAN
    • Engineer WAN connectivity across:
      • MPLS
      • DIA
      • Internet
      • Hybrid VPN
      • SD-WAN overlays
    • Optimize routing, application performance, resiliency, and traffic paths across distributed locations.
    • Troubleshoot complex WAN and SD-WAN performance and connectivity issues.
    • Participate in enterprise WAN modernization and migration projects.
  • Multi-Cloud Network Architecture
    • Design and support secure network connectivity between enterprise infrastructure and AWS, Azure, and GCP environments.
    • Implement and troubleshoot cloud connectivity technologies including:
      • AWS Direct Connect
      • AWS Transit Gateway
      • Azure ExpressRoute
      • Azure Virtual WAN
      • Cloud VPN
      • Hybrid cloud networking
    • Design routing and segmentation across on-premises data centers and cloud environments.
    • Troubleshoot BGP and hybrid-cloud routing issues.
    • Collaborate with cloud engineering and security teams to develop scalable and highly available network architectures.
  • Network Automation & Infrastructure as Code
    • Develop and maintain network automation solutions using:
      • Python
      • Terraform
      • Ansible
    • Automate repetitive network provisioning, configuration, validation, and operational tasks.
    • Implement Infrastructure-as-Code principles for network infrastructure where appropriate.
    • Improve operational efficiency, consistency, and configuration accuracy through automation.
    • Support automation initiatives across enterprise, cloud, and security platforms.
  • L3 Escalation, Incident Management & RCA
    • Serve as the highest-level technical escalation point for complex enterprise network incidents.
    • Provide advanced L3 troubleshooting and root cause analysis (RCA).
    • Lead technical resolution of major incidents affecting enterprise, data center, cloud, and manufacturing operations.
    • Analyze network performance, routing behavior, firewall policies, packet flows, and application connectivity.
    • Develop corrective and preventive actions following major incidents.
    • Participate in on-call or after-hours support activities when required.
  • Network Monitoring & Performance Management
    • Monitor enterprise network health, performance, availability, and security.
    • Utilize enterprise monitoring and troubleshooting tools such as:
      • Wireshark
      • SolarWinds
      • ThousandEyes
      • Splunk
    • Perform packet captures and deep protocol analysis.
    • Identify network bottlenecks, latency, packet loss, routing instability, and application performance issues.
    • Establish proactive monitoring and alerting strategies to improve network reliability.
  • Infrastructure Support & Modernization
    • Provide network support for enterprise compute and virtualization environments, including VMware/vSAN deployments.
    • Participate in data center network upgrades, migrations, and technology refresh initiatives.
    • Develop detailed network architecture and implementation documentation.
    • Maintain accurate network diagrams, standards, configurations, and operational procedures.
    • Identify opportunities to modernize legacy infrastructure and improve scalability, security, resiliency, and operational efficiency.

Requirements

  • Core Requirements
    • 10+ years of enterprise network engineering experience in large, complex environments.
    • Strong hands-on experience supporting data center, cloud, WAN, LAN, and manufacturing/OT networks.
    • SME-level BGP expertise is mandatory.
    • Strong experience with eBGP, iBGP, BGP-EVPN, route reflectors, communities, path manipulation, and traffic engineering.
    • Extensive hands-on Cisco routing and switching experience.
    • Strong experience with Palo Alto firewalls and Panorama.
    • Demonstrated experience with OT/ICS/SCADA network environments.
    • Hands-on experience designing and implementing OT microsegmentation.
    • Experience with industrial/manufacturing Wi-Fi is highly preferred.
    • Strong SD-WAN experience, particularly Cisco Viptela and/or Palo Alto Prisma SD-WAN.
    • Experience with multi-cloud networking across AWS, Azure, and/or GCP.
    • Strong L3 troubleshooting, incident management, and RCA capabilities

Similar jobs

Senior Network Engineer L2

RehmannMichigan, United States· 4 days ago
RemoteInformation Technologyapply on rehmann.wd108.myworkdayjobs.com

Senior Network Engineer

Impact Networking, LLCChicago, IL· 4 days ago
Information Technology$105k–$125k/yrapply on jobs.ashbyhq.com

Senior Network Engineer

Impact Networking, LLCHouston, TX· 4 days ago
Information Technology$105k–$125k/yrapply on jobs.ashbyhq.com