Come build, innovate, disrupt, and thrive!
KēSTA I.T is actively seeking a Network Infrastructure Engineer for an immediate contract engagement with our client.
Job Description:
We Are Seeking an experienced Network Infrastructure Engineer to design, implement, operate, and modernize enterprise network infrastructure supporting data center, campus, and mission-critical environments. This hands-on engineering role will focus on Cisco ACI, Cisco Nexus and Catalyst platforms, Software-Defined Access (SDA), identity-driven networking, network security, and enterprise observability technologies. The engineer will be responsible for building reliable, scalable, secure, and highly available network services while supporting modernization initiatives and complex statewide or enterprise operations.
Responsibilities:
· Design, implement, configure, and maintain Cisco Nexus platforms operating in ACI mode, including VRFs, Bridge Domains, EPGs, ESGs, L3Outs, contracts, and fabric policies.
· Deploy and manage Cisco ACI fabrics and support multi-tenant segmentation, fabric health, endpoint learning, contracts, faults, and advanced troubleshooting.
· Integrate Cisco ACI with virtualization and container platforms, including Red Hat OpenShift VMM and Cilium/Isovalent.
· Configure and optimize RoCEv2 within ACI environments to support high-performance and low-latency workloads.
· Design, deploy, and support Cisco Catalyst platforms within enterprise campus environments.
· Design and maintain Software-Defined Access architectures, including SDA wired fabrics and fabric-enabled wireless environments.
· Manage SDA underlay and overlay networks, policy mapping, authentication integrations, and assurance operations.
· Collaborate with wireless engineering teams to optimize network coverage, performance, segmentation, and policy enforcement.
· Configure and administer Cisco Identity Services Engine (ISE), including TACACS+, authentication and authorization policy sets, device administration, and endpoint profiling.
· Integrate Cisco Cyber Vision intelligence into endpoint profiling, segmentation, asset visibility, and access-control workflows.
· Support Zero Trust networking initiatives through identity-centric segmentation and policy integration across ACI and SDA environments.
· Deploy and manage ThousandEyes for end-to-end network visibility, routing-path analysis, performance monitoring, and troubleshooting.
· Implement and support Cyber Vision for OT/IoT asset visibility, device classification, behavioral analysis, and security monitoring.
· Manage DNA Spaces capabilities for location analytics, telemetry ingestion, device behavior analysis, and wireless intelligence.
· Analyze data from network observability platforms and provide meaningful technical insights and recommendations to leadership.
· Troubleshoot complex Layer 2 and Layer 3 networking issues involving VLANs, TCP/IP, OSPF, BGP, STP, multicast, routing, switching, QoS, and network security.
· Design, implement, configure, and troubleshoot Palo Alto Networks security solutions across enterprise environments.
· Develop and maintain network architecture diagrams, technical standards, configuration documentation, operational procedures, runbooks, asset inventories, and other architectural artifacts.
· Support network lifecycle planning, modernization initiatives, platform upgrades, technology evaluations, and procurement activities.
· Collaborate with infrastructure, security, wireless, virtualization, application, and other technical teams to maintain reliable enterprise services.
· Support high-availability and mission-critical network infrastructure across data centers, campus environments, and geographically distributed operations.
· Analyze complex technical issues, identify root causes, and implement sustainable solutions in fast-paced enterprise environments.
· Perform other related engineering and infrastructure responsibilities as assigned.
Required Skills
· 15+ years of experience working with Cisco networking technologies.
· Hands-on production experience with Cisco ACI in enterprise environments.
· Deep knowledge of Cisco ACI constructs, including VRFs, Bridge Domains (BDs), EPGs, ESGs, L3Outs, contracts, and fabric policies.
· Experience integrating Cisco ACI with Red Hat OpenShift VMM and Cilium/Isovalent.
· Strong experience with Cisco Nexus platforms and enterprise data center networking.
· Proficiency with Cisco Catalyst platforms and Software-Defined Access (SDA) technologies.
· Experience designing, deploying, and supporting SDA wired fabrics and fabric-enabled wireless environments.
· Experience administering Cisco Identity Services Engine (ISE), including TACACS+, authentication and authorization policy sets, device administration, and network access control.
· Experience with endpoint profiling and identity-driven network access and segmentation.
· Strong understanding of ThousandEyes, Cisco Cyber Vision, and DNA Spaces, or comparable network visibility, analytics, and observability technologies.
· Solid command of TCP/IP, Layer 2/Layer 3 routing and switching, VLANs, OSPF, BGP, STP, multicast, QoS, and network security fundamentals.
· Experience with network segmentation and identity-centric security architectures.
· Experience designing, implementing, and troubleshooting Palo Alto Networks security solutions.
· Ability to develop clear network diagrams, architecture documentation, technical standards, runbooks, and other engineering artifacts.
· Strong analytical, troubleshooting, written, and verbal communication skills.
· Ability to work effectively in fast-paced, mission-critical enterprise environments.
· Ability to support highly available, scalable, and enterprise-level network infrastructure.
Preferred Skills & Experience
· Cisco certifications such as CCNP Data Center, CCNP Enterprise, CCIE, or equivalent demonstrated experience.
· Cisco Specialist certifications or training focused on ACI, SDA, or ISE.
· Hands-on experience with container networking and virtualization integrations.
· Experience with RoCEv2 and high-performance, low-latency network environments.
· Experience with network automation using Python, Ansible, REST APIs, or comparable automation technologies.
· Familiarity with NIST cybersecurity frameworks and state-level or enterprise cybersecurity requirements.
· Experience supporting large enterprise, public-sector, or similarly complex network environments.
· PCCSA – Palo Alto Networks Certified Cybersecurity Associate certification or equivalent knowledge of next-generation firewall fundamentals, threats, App-ID, and security policy.
· PCNSA – Palo Alto Networks Certified Network Security Administrator certification or equivalent experience with firewall configuration, security profiles, NAT, App-ID, URL filtering, WildFire, and related security technologies.
· PCNSE or other advanced Palo Alto Networks certification.
· ThousandEyes, Cyber Vision, DNA Spaces, or related network observability platform training or certifications.
· Experience supporting enterprise-wide network modernization, lifecycle planning, and technology transformation initiatives.
Available Benefits:
· Medical Benefits (Platinum level plans available)
· Work from home / Hybrid / Onsite options
· PTO
· Holiday Pay
· VTO
· 401K
· Charitable Match
· Training reimbursement
About KēSTA I.T.:
Our name says it all; KēSTA I.T. (Keys-to-I.T.) AND our people are our keys to our success!
KēSTA I.T. is a premier Utah-based technical staffing and consulting services firm. We specialize in temporary and permanent placement of Software, Hardware, Network, Cloud, CRM/ERP, Data, End-User support, Web and Executive / leadership-based positions on a full time and consulting basis.
If you're interested in a role where top performance is rewarded, personal time is valued, and excellence is demanded at every level we want to talk to you today!
Where do you want to go? We've got the keys! ~ KēSTA I.T.