Job Description
Required Education
• Bachelor’s degree in Computer Science, Information Technology, Engineering, or equivalent work experience.
Required Skills
• Enterprise network engineering (routing, switching, BGP, OSPF, VXLAN/EVPN, SDN).
• Hybrid cloud networking (5+ years supporting on-prem, private cloud, AWS, and Azure).
• Network isolation, secure enclave design, air-gapped environments, and recovery network architectures.
• Micro-segmentation (VMware NSX, Illumio, Cisco Secure Workload, cloud-native security groups).
• Zero Trust networking principles and least-privilege access.
• Infrastructure as Code using Terraform (3+ years) – building reusable modules and standardized patterns.
• Scripting with Python, PowerShell, or Bash for provisioning, validation, compliance, drift detection, and monitoring.
• CI/CD pipeline integration (Git-based).
• AWS: VPCs, Transit Gateway, Direct Connect, Route Tables, PrivateLink, Network Firewall.
• Azure: VNets, ExpressRoute, Virtual WAN, Azure Firewall, NSGs, Application Gateway, Load Balancer.
• Firewall architecture, IDS/IPS, DDoS protection, secure DNS, encryption in transit.
• High Availability, Disaster Recovery, active-active/passive architectures, multi-region failover, automated failover.
• Tools such as ThousandEyes, SolarWinds, Dynatrace, Splunk, Grafana, Prometheus, and cloud-native solutions.
• Dashboard development, KPI tracking, and automated alerting.
Preferred (Nice-to-Have) Skills
• Experience in large financial institutions or regulated industries.
• Kubernetes/OpenShift networking.
• VMware NSX or Cisco ACI.
• GitHub/GitLab/Azure DevOps pipelines.
• Disaster Recovery and Cyber Recovery networking.
• Infrastructure as Code governance and policy-as-code.
• Immutable infrastructure.
Preferred Certifications
• CCNP Enterprise or CCIE
• AWS Advanced Networking – Specialty
• Microsoft Azure Network Engineer Associate (AZ-700)
• HashiCorp Terraform Associate
• VMware VCP-NV (NSX)
• Palo Alto PCNSE
• CISSP (preferred)
We are seeking a highly skilled Senior Network Engineer to lead the design, automation, and modernization of enterprise network infrastructure across hybrid environments. This role is responsible for building highly resilient, secure, software-defined network architectures spanning on-premises data centers, private cloud, and public cloud platforms. The ideal candidate partners closely with Cloud Engineering, Cybersecurity, Infrastructure, SRE, and Application teams to deliver secure, scalable, and automated networking solutions aligned with Zero Trust principles.
Key Responsibilities:
• Enterprise Network Engineering – Design, implement, and support highly available network infrastructure across on-prem data centers, private cloud, AWS, and Azure. Engineer resilient Layer 2/Layer 3 architectures including routing, switching, BGP, OSPF, VXLAN/EVPN, and SDN technologies. Support enterprise resiliency and disaster recovery.
• Infrastructure Automation – Build IaC solutions using Terraform; develop reusable modules and standardized deployment patterns. Automate network provisioning and configuration management. Integrate automation into Git-based CI/CD pipelines. Eliminate manual networking activities through automation-first engineering.
• Scripting & Automation – Develop automation using Python, PowerShell, Bash, and REST APIs to handle provisioning, validation, compliance verification, drift detection, operational reporting, and health monitoring.
• Network Isolation & Segmentation – Lead enterprise initiatives for network isolation, secure enclaves, air-gapped environments, Isolated Recovery Environments (IRE), secure management networks, and recovery architectures. Design secure separation between production, non-production, recovery, cyber recovery, and management networks.
• Micro-Segmentation – Design and implement enterprise micro-segmentation using VMware NSX, Illumio, Cisco Secure Workload, cloud-native security groups, Azure NSGs, AWS Security Groups, and Network ACLs. Manage East-West traffic control, Zero Trust architectures, least-privilege access, dynamic policy enforcement, and application dependency mapping.
• Cloud Networking – Engineer networking solutions across AWS (VPCs, Transit Gateway, Direct Connect, Route Tables, PrivateLink, Network Firewall) and Azure (VNets, ExpressRoute, Virtual WAN, Azure Firewall, NSGs, Application Gateway, Load Balancer).
• Security Engineering – Collaborate with Cyber Security to implement Zero Trust networking, Network Access Control, secure remote connectivity, firewall architecture, IDS/IPS, DDoS protection, secure DNS, certificate management, and encryption in transit.
• Resiliency Engineering – Design networking solutions supporting High Availability, Disaster Recovery, active-active/passive architectures, multi-region cloud deployments, automated failover, resilient routing, and critical application recovery.
• Monitoring & Observability – Implement enterprise network observability using tools like ThousandEyes, SolarWinds, Dynatrace, Splunk, Grafana, Prometheus, and cloud-native monitoring. Develop dashboards, KPIs, and automated alerting for proactive network operations.
Working for Rose International was the most pleasant assignment I have ever had. They were always on top of situations when necessary, and very helpful. I was very proud to be an employee of Rose International, and would recommend anyone to try to work with them.
Melvon, Consultant
Your team at Rose International is always very helpful and responsive.
Barbara, Consultant
Thanks for the opportunity. If in the future I ever need a job, I would like to work for Rose International.
David, Consultant
Rose International was not only attentive and responsive, but they were very professional and helpful whenever I called or needed any assistance.
Diane, Consultant
It is a great pleasure being a part of the Rose International Team.
Toni, Consultant
EMPLOYEE COMMENTS