Network Engineer III
Listed on 2026-07-13
-
IT/Tech
Cybersecurity, Network Engineer, Network Security, Systems Engineer
Network Engineer III
Senior Enterprise Network Security Engineer designed, secures, and operates the University’s enterprise network across campus, data centers, and cloud interconnects. The role blends advanced network engineering with cybersecurity, emphasizing Palo Alto (PAN OS/Prisma Access) and Juniper (EX/QFX/SRX/Junos). Responsibilities include complex projects, staff training, and network automation (Ansible, Python, Git/Terraform) to enhance reliability, security, and delivery speed. Scope includes Internet and research/education connectivity;
campus LAN/WLAN; firewalls and VPN; segmentation and NAC/802.1X; and integration with monitoring, logging, and incident response.
Associate’s degree and four (4) years of related experience or an equivalent combination of related education and experience.
PreferredEducation and Experience
- Bachelor’s degree in a related field and four (4)+ years of progressive network engineering and security experience, including hands‑on administration of Palo Alto and Juniper platforms.
- Five (5)+ years in large–scale/complex networks; higher education experience preferred.
- Advanced certifications (one or more):
Palo Alto and/or Juniper, or equivalent expertise. - Proficiency with Ansible, Python, and Git; experience with Terraform or templating frameworks.
- Deep knowledge of routing (BGP, OSPF; EVPN/MPLS desirable), QoS, VPN, and HA designs. Demonstrated success leading projects, coordinating cross‑functional teams, and mentoring engineers.
- Strong troubleshooting methodology, communication skills, and customer focus.
- Expert configuration and policy management on Palo Alto and Juniper (Junos), including Juniper firewall filters.
- Network security architecture (segmentation, least privilege, Zero Trust), VPN design/operations, and NAC implementations.
- Automation, scripting, and infrastructure‑as‑code practices; comfort with code reviews and CI/CD workflows.
- Clear documentation and diagramming; ability to explain complex topics to non‑technical audiences.
To the extent this position requires the holder to research, work on, or have access to critical infrastructure as defined in Texas Business and Commerce Code, the ability to maintain the security or integrity of the critical infrastructure is a minimum qualification.
Essential Duties and Responsibilities- Engineer, configure, secure, and maintain campus and data center LAN/WAN, including BGP/OSPF/EVPN and high‑availability designs across Juniper switching/routing and Palo Alto firewalls.
- Lead troubleshooting and root‑cause analysis; implement durable fixes aligned to SLAs/SLOs.
- Maintain accurate diagrams, standards, runbooks, and asset documentation under change control.
- Serve as primary technical liaison to stakeholders, vendors, and OIT teams.
- Monitor performance and capacity; implement improvements for availability, reliability, and security.
- Deliver changes via automation pipelines and change management; operate LAN/WAN, WLAN, VPN, and firewall services.
- Lead security projects end‑to‑end—requirements through turnover—with clear timelines, risks, and communications.
- Provide technical leadership and mentoring; conduct design reviews and knowledge sharing.
- Participate in the 24×7 on‑call rotation and incident response; maintain current technical knowledge.
- Network and security design
- Palo Alto/Juniper policy/filter design
- NAC/802.1X
- VPN architecture/operations
- Documentation and diagramming
- Project and capacity planning
- Device implementation
- VLAN planning
- Performance monitoring
- Incident response
- Lifecycle/technology refresh
- Contribution to project budgets
- Engineer and operate Palo Alto firewalls (policy, NAT, User , Global Protect), Juniper SRX (zone policies), threat prevention, and segmentation aligned to Zero Trust.
- Maintain NAC/802.1X and identity‑based access; manage Juniper firewall filters and campus ACL standards.
- Provide secure remote access, site‑to‑site VPNs, and cloud interconnectivity with appropriate encryption and routing controls.
- Integrate telemetry with monitoring and SIEM/SOAR; define alerting thresholds and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).