28 Aug
|
Precision Group
|
Chennai
28 Aug
Precision Group
Chennai
We are looking for an experienced Network & Security Engineer to design, implement, and troubleshoot enterprise and data center network infrastructure, including multi-tenant environments, firewall policy architecture, and dynamic access control systems. This role suits a candidate from an ISP, MSP, Data Center, or large enterprise network operations background who has hands-on experience with switching, routing, MPLS, VRF-based multi-tenancy, and FortiGate firewalls.
Experience Required:
- 58+ years in network engineering / network security, ideally within a service provider, MSP, or data center environment.
- Proven hands-on (not just theoretical) experience — this role involves live troubleshooting and design work, not just monitoring.
Key Responsibilities:
- Design and implement Layer 2/Layer 3 network architecture including VLANs, trunking, and switch redundancy (LACP/MLAG/stacking).
- Implement Network Access Control (NAC) using 802.1X, RADIUS, MAB, and dynamic VLAN assignment for wired and wireless networks.
- Configure and manage multi-tenant data center environments using VRF-Lite and MPLS L3VPN to isolate overlapping customer IP address spaces.
- Design and maintain firewall architectures (FortiGate preferred) including VDOMs, inter-VDOM routing, SD-WAN, and policy-based access control.
- Build segmented access control models — e.g., group-based internet access,
restricted admin-only RDP/SSH access to servers via jump hosts.
- Troubleshoot complex L2/L3 issues including STP loops, MAC flapping, err-disable states, and link aggregation failures.
- Configure link redundancy and aggregation (LACP/802.3ad) across switches and firewalls with minimal service disruption.
- Document network designs, IP schemas, VLAN mappings, and firewall policy matrices.
- Work directly with vendors/onsite technicians to guide physical infrastructure changes (cabling, rack identification) in live environments.
Required Technical Skills
- Switching: VLANs, trunking (802.1Q), STP/RSTP, LACP, MLAG/VSS/stacking, port security
- Access Control: 802.1X, RADIUS (Cisco ISE / Aruba ClearPass / FreeRADIUS), MAB, agile VLAN assignment
- Routing: L3 switching, static/dynamic routing, VRF-Lite, MPLS L3VPN (RD/RT concepts)
- Firewalls: FortiGate (VDOMs, SD-WAN, policy routing) — Palo Alto / Check Point / Cisco ASA-Firepower also relevant
- Data Center: Multi-tenant network isolation, chassis switches, overlapping IP address space handling
- Troubleshooting: MAC flapping, STP loops, err-disable recovery, LACP negotiation issues
- Identity Integration: Active Directory / LDAP integration with network access policies (FSSO/User-ID/Identity Awareness)
📌 Network Engineer (Chennai)
🏢 Precision Group
📍 Chennai