Senior Network Engineer – Cloud Prem
Listed on 2025-11-24
-
IT/Tech
Systems Engineer, Cybersecurity, Network Engineer
Location: Greater London
Senior Network Engineer – Cloud & On-Prem
Location:
Greater London, England, United Kingdom
If you love beauty, you’re in the right place. As the ultimate curator of over 100 of the most in-demand, highly innovative and boundary-pushing beauty brands, we are the go‑to destination for worldwide beauty discovery. Together through our neighbourhood stores, online presence and loyalty scheme, Space NK has built a flourishing community in which to discover beauty. The customer is at the heart of everything we do, and we will always endeavour to offer everything they need to help them explore, experiment, and enjoy our brands.
AboutThe Role
Space NK operates a hybrid network spanning Microsoft Azure, corporate offices, datacentres, and a nationwide retail store estate. As Senior Network Engineer, you will design, deploy, secure, and operate all network infrastructure across cloud and on‑prem environments, with Azure as the primary cloud platform.
Your RoleThis is a hands‑on engineering role with architectural influence, responsible for routing, switching, firewalls, network security enforcement, hybrid connectivity, SD‑WAN, Express Route, and retail store networking. You will ensure high availability, performance, resilience, and security of all network services supporting both corporate and retail operations.
Key ResponsibilitiesDesigning and maintaining Azure and on‑premises network architectures.
Operating enterprise routing, switching, firewalls, and wireless networks.
Optimising performance and resilience across WAN, SD‑WAN, and hybrid Azure/on‑prem connectivity.
Ensuring secure segmentation and network security best practices.
Supporting retail store networking, POS connectivity, and operational stability.
Monitoring, troubleshooting, and automating network operations.
Managing vendors, carriers, and network service providers.
Contributing to infrastructure projects and network modernisation initiatives.
Azure Cloud Networking- Design, implement, and manage Azure Virtual Networks (VNets), hub-and-spoke architectures, subnets, IP schemas, and VNet peering.
- Deploy and support NSGs, ASGs, Azure Firewall, and network segmentation aligned to Zero Trust.
- Implement and operate Network Virtual Appliances (Cisco, Juniper, Palo Alto, Fortinet) using UDR-based routing and service chaining.
- Manage UDRs, route tables, custom routing, and secure traffic flows.
- Operate Azure Application Gateway, Load Balancer, and Front Door for application delivery.
- Use Azure Network Watcher, packet capture, flow logs, and diagnostics for troubleshooting.
- Configure and maintain Azure VPN Gateways and Express Route circuits, including routing optimisation and HA design.
- Design, operate, and secure enterprise LAN/WAN using Cisco, Juniper, Meraki, or HPE/Aruba switching and routing platforms.
- Configure and optimise routing protocols (BGP, OSPF, EIGRP), static routing, and route summarisation.
- Deploy and manage firewalls such as Sonic Wall, Palo Alto, Fortinet, rule‑based, NAT, segmentation, and HA pairs.
- Support core network services: DNS, DHCP, IPAM, NTP, RADIUS/TACACS+ (for network device authentication).
- Conduct deep packet analysis using Wireshark, tcpdump, or vendor tools.
- Maintain data centre network connectivity including LAG/MLAG/VPC, redundant uplinks, and high‑availability designs.
- Design and support retail store network solutions using Cisco Meraki as the strategic platform.
- Manage SD‑WAN or MPLS store connectivity, breakout policies, WAN performance, and QoS for tills/POS.
- Deploy 4G/5G failover solutions for resilience during provider outages.
- Ensure PCI‑compliant segmentation across tills, IoT, CCTV, staff devices, and guest Wi‑Fi.
- Troubleshoot complex store issues involving tills, PDQs, Wi‑Fi interference, and cloud backhaul.
- Produce deployment playbooks and support new store openings, refurbishments, and relocations.
- Collaborate with ISPs, SD‑WAN vendors, and fit‑out partners to maintain store uptime and connectivity performance.
- Design and operate hybrid connectivity between Azure and on‑prem datacentres using Express Route, IPsec VPN, and private peering models.
- Optimise routing…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: