Senior Network Engineer
Listed on 2026-06-04
-
IT/Tech
Cybersecurity, Systems Engineer
Vestahelps wireless providers make more money by improving a part of their business most don’t think about — payments. Vesta works with major names like AT&T, Rogers, Telcel, and Vodafone, helping them stop fraud, reduce failed transactions, and make sure more transactions are successful. For MNOs, MVNOs and prepaid carriers, this can mean fewer lost customers and more revenue — all without adding friction to the checkout experience.
With over 100 million transactions processed every year in 40+ countries, Vesta helps wireless providers turn their payment systems into a competitive advantage.
Location:
Remote US/Travel as needed
Reports To:
Director of Infrastructure & Network Security
Job Type: Full-time
Position SummaryVesta Corporation is seeking a Senior Network Engineer to lead the design, implementation, and ongoing operations of our global enterprise network. This is a senior individual-contributor role that operates at the intersection of complex multi-site networking, hybrid cloud infrastructure, and PCI compliance. The ideal candidate brings 10+ years of hands-on enterprise networking experience, deep familiarity with both commercial and open-source tooling, and the ability to drive infrastructure modernization initiatives with limited oversight.
Key Responsibilities- Design, implement, and maintain scalable, secure network infrastructure across data centers, remote sites, and cloud environments (AWS and Azure).
- Architect and operate routing and switching infrastructure including BGP, NAT, VLANs, Spanning Tree, IPsec VPNs, P , and HSRP.
- Manage and tune enterprise firewall platforms (Cisco, pf Sense, Check Point) in alignment with PCI DSS segmentation and access control requirements.
- Administer and optimize F5 BIG-IP LTM/GTM for application delivery, load balancing, and traffic steering across production environments.
- Manage Cloudflare DNS, WAF, and network security policies for internet-facing properties.
- Maintain network security policy management via Fire Mon; contribute to access path analysis and rule lifecycle management.
- Evaluate, deploy, and operationalize free open-source software (FOSS) as replacements for commercial products where appropriate (e.g., network monitoring, IPAM, configuration backup).
- Manage Proxmox-based virtualization as it relates to network-adjacent workloads and VM/LXC networking.
- Coordinate with vendors and carriers to manage WAN circuits, resolve outages, and drive cost optimization.
- Maintain comprehensive documentation for network topology, configurations, and operational runbooks; support PCI DSS and SOC 1 Type 2 audit evidence collection.
- Participate in on-call rotation and be available for after-hours work including unscheduled incidents.
- Travel to domestic data center and office locations as needed to support deployments or incidents.
Required
- 10+ years of hands-on enterprise networking experience in large-scale, multi-site environments.
- Expert-level Cisco routing and switching: IOS/NX-OS, BGP, OSPF, EIGRP, VLANs, STP.
- Enterprise firewall administration:
Cisco ASA/FTD, pf Sense, and Check Point — rule management, segmentation strategy, and change control. - F5 BIG-IP LTM/GTM: virtual servers, pools, iRules, traffic policies, GTM topology records.
- Cloudflare: DNS management, WAF rulesets, and security policy administration.
- Fire Mon: policy analysis, rule review workflows, access path validation.
- Deep understanding of TCP/IP, DNS, DHCP, routing/switching protocols, and secure remote access.
- Experience operating in PCI DSS-compliant environments including control implementation and audit evidence collection.
- Strong troubleshooting capabilities with the ability to resolve complex outages under time pressure.
Preferred / Nice to Have
- Proxmox VE: VM/LXC provisioning, cluster management, and software-defined networking.
- Experience deploying FOSS tools to replace commercial networking or monitoring products (e.g., Oxidized, Net Box, or similar).
- Hybrid cloud networking: AWS Direct Connect, Azure Express Route, site-to-site VPN, cloud-native security groups.
- Zero-trust / overlay VPN concepts and implementation (e.g., Tailscale or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).