Network Engineer L3
Listed on 2026-07-31
-
IT/Tech
Network Engineer, Systems Engineer, Cloud Computing: Infrastructure & Operations, Cybersecurity
Network Engineer L3
Roles and Responsibilities
Network Design and Architecture – Own HLD/LLD for enterprise LAN, WAN, DC, and cloud connectivity.
- Design redundant scalable topologies: spine–leaf, hub–spoke, SD‑WAN.
- Define IP addressing, VLAN structure, routing domains, and segmentation strategy.
Escalation and Incident Ownership – Final escalation point for L1/L2. You close incidents, not pass them on.
- Lead P1/P2 bridge calls, drive RCA, own post‑mortem.
- Coordinate with NOC, security, and vendors during major incidents.
Routing & Switch Management – Advanced management and tuning of BGP policies, OSPF areas, MPLS VRF, redistribution.
- Handle complex STP issues, VPC/MLAG, LACP, and trunk failures.
- Own inter‑DC and ISP peering configurations.
Security & Compliance – Enforce segmentation, VRF, VLAN isolation, firewall zones.
- Review and approve ACLs, firewall rules, NAC policies.
- Support audits: PCI, ISO 27001, NIST alignment on the network layer.
Cloud & Hybrid Networking – Own AWS and Azure network integration.
- VPN Gateway, Express Route, Transit Gateway.
- Design and troubleshoot hybrid connectivity on‑prem to cloud routing.
- Collaborate with cloud architects on network policy.
Automation & Tooling – Build and maintain automation.
- Python, Ansible, Netmiko.
- Automate config backups, compliance checks, provisioning workflows.
- Integrate with ITSM, IPAM, NMS platforms.
Monitoring & Performance – Own network observability.
- Net Flow, SNMP, syslog pipelines.
- Proactive capacity planning – identify bottlenecks before incidents.
- Define and track SLAs: latency, packet loss thresholds.
Documentation & Change Management – Maintain accurate network diagrams, IP plans, and runbooks.
- Author and review RFCs and change records – no undocumented changes.
- Keep post‑mortems and lessons‑learned documented.
Vendor & Stakeholder Management – Own TAC cases.
- Cisco, Palo Alto, Juniper, Fortinet.
- Evaluate new hardware/software, PoC, testing, recommendation.
- Present technical decisions to management and non‑technical stakeholders.
Mentorship & Leadership – Technically guide L3 engineers, knowledge transfer, not just answers.
- Conduct design and config peer reviews.
- Set team standards: naming conventions, hardening baselines, change process.
Technical Depth
- Can design end‑to‑end – not just configure what's handed to them.
- Understands why a protocol behaves a certain way, not just how to configure it.
- Reads packet captures, interprets routing tables, and diagnoses without a runbook.
- Has broken things in production and fixed them under pressure.
- Core Technical Profile:
Domain, experience, certifications, problem‑solving style, communication, mindset.
- Routing – BGP multihoming, path manipulation, OSPF tuning, MPLS L3
VPN. - Switching – VPC/MLAG, MSTP, Q‑in‑Q, LACP negotiation issues.
- Firewalls – Zone‑based policy, NAT hairpin, asymmetric routing issues.
- SD‑WAN – Policy‑based routing, app‑aware steering, overlay/underlay separation.
- Cloud – Express Route, Direct Connect, Transit Gateway, route propagation.
- Automation – Script‑first mindset – Python, Ansible, REST APIs.
- Monitoring – Build a dashboard, not just read one.
- 5–8 years hands‑on – enterprise, SP, or large MSP environment.
- Has owned a network migration or redesign project end to end.
- Has managed multi‑vendor environments – not just one OEM.
- Has worked on‑call and handled real P1 incidents alone.
- Cert.
Required:
CCNP Enterprise / JNCIP / NSE4+ - Strong Plus: CCIE / JNCIE / NSE7
- Bonus: AWS/Azure Networking Specialty
- Structured – isolates layer by layer, doesn't guess randomly.
- Calm under pressure – incident bridge calls don't rattle them.
- Data‑driven – uses logs, flows, and captures, not assumptions.
- Owns the problem – doesn't deflect to another team without evidence.
- Can explain a routing loop to a CISO without using BGP terminology.
- Writes clean, clear documentation – diagrams match reality.
- Pushes back on bad designs – respectfully, with data.
- Comfortable presenting to management and defending technical decisions.
- Security‑first – thinks about attack surface when designing, not after.
- Automation bias – if done more than twice, it should be scripted.
- Proactive – monitors trends, flags risks before incidents.
- Continuous learner – tracks CVEs, vendor EOL, protocol RFCs.
- Can configure but can't explain why.
- Has never touched a firewall or security policy.
- Relies entirely on GUI – no CLI fluency.
- No experience with change management or documentation discipline.
- Falls apart when the runbook doesn't apply.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).