
Network Engineer
- USA
- $99,300-148,900 per year
- Permanent
- Full-time
- CAE Vision: Our vision is to be the worldwide partner of choice in defense & security and civil aviation by revolutionizing our customers’ training and critical operations with digitally immersive solutions to elevate safety, efficiency and readiness.
- CAE Defense & Security Mission: CAE's Defense and Security business unit focuses on helping prepare military customers to develop and maintain the highest levels of mission readiness.
- CAE Values: Empowerment, Innovation, Excellence, Integrity and OneCAE make us who we are and we strive to make a difference in the world while helping each other succeed.
- Comprehensive and competitive benefits package and flexibility that promotes work-life balance
- A work environment where all employees are valued, respected and safe
- Freedom to succeed by enabling team members to deliver, take initiatives and make decisions
- Recognition, professional development, advancement and having fun!
- Implementing, administering, and troubleshooting network devices including WAPs, firewalls, routers, switches, and controllers.
- Maintaining and administering computer networks and related computing environments including systems software, applications software, hardware, and configurations.
- Performing disaster recovery operations and data backups when required.
- Assist with contractual requirements identification and execution
- Assist with early identification of potential attrition, candidates and expansion opportunities
- Protecting data, software, and hardware by coordinating, planning, and implementing network security measures.
- Troubleshooting, diagnosing, and resolving hardware, software, and other network and system problems.
- Replacing faulty network hardware components when required.
- Configuring, and monitoring SIEM platforms Solarwinds, Splunk, and IBM QRadar.
- Monitoring network performance to determine if adjustments need to be made.
- Conferring with network users about solving existing system problems.
- Operating master consoles to monitor the performance of networks and computer systems.
- Managing network access for both users and administrators via ISE. Account management.
- Coordinating computer network access and use.
- Designing, configuring, and testing networking software, computer hardware, and operating system software.
- TS/SCI security clearance
- DOD 8570 Baseline Certified (Security+, CCNA, CCNA Security)
- 4+ years of networking engineering experience.
- Knowledge of Cisco IPS, firewalls, routers, and switches.
- Strong understanding of network infrastructure and network hardware.
- Ability to think through problems and visualize solutions while under pressure.
- Ability to implement, administer, and troubleshoot network infrastructure devices, including intrusion prevention systems, firewalls, routers, and switches.
- Knowledge of application transport and network infrastructure protocols.
- Ability to create accurate network diagrams and documentation for design and planning network communication systems.
- Provides specific detailed information for hardware and software selection.
- Ability to quickly learn new or unfamiliar technology and products using documentation and internet resources.
- Ability to work with all levels of staff within and outside of IT and outside the organization.
- A self-starter able to work independently but comfortable working in a team environment.
- Good analytical and problem-solving skills.
- Dependable and flexible when necessary.
- Network security experience.
- LAN and WAN experience.
- A deep knowledge of application transport and network infrastructure protocols.
- Extensive knowledge of Cisco Nexus datacenter switches, to include VRF’s, VPC, Features, High availability, and general configuration.
- Knowledge of cisco best practices in creating and maintaining collapsed core environment
- Knowledge of Palo Alto Networks Next-Generation Firewall (NGFW).
- Knowledge of Cisco Adaptive Security Appliance (ASA) firewalls.
- Knowledge of Cisco Next-Gen Firewall Firepower devices.
- Knowledge on configuring firewall access rules and device access-control lists.
- Knowledge of Cisco Firepower Management Center (FMC) and configuring IPS security policies.
- Knowledge of Cisco Sourcefire sensors.
- Knowledge of Cisco Virtual Private Network (VPN) concentrators.
- Knowledge on configuring and troubleshooting Site-to-Site IPsec VPN tunnels on Integrated Services Routers (ISRs) to include IKEv1, IKEv2, and GRE tunnels.
- Knowledge on configuring and troubleshooting TACACS+ Authentication, Authorization, and Accounting (AAA) services on networking devices.
- Knowledge on configuring and troubleshooting Port-based Network Access Control (PNAC) using IEEE 802.1x authentication on layer 2 network switches.
- Knowledge on configuring and troubleshooting Simple Network Management Protocol (SNMP) on networking devices
- Knowledge on configuring and troubleshooting network IP Routing protocols (OSPF, BGP, EIGRP).
- Knowledge of DHCP configuration spanned between multiple devices
- Knowledge of Cisco Identity Services Engine (ISE).
- Knowledge on configuring Cisco ISE security policy sets.
- Ability to stay on top of Cisco IOS & Rommon updates and ensure latest Cisco recommended patches are applied monthly per DISA STIG requirements and Cisco best practices.
- Preferred prior experience with opening help tickets and troubleshooting with DISA concerning DoDIN NIPR / SIPR WAN circuits
- Familiarization with Cisco Technical Assistance Center (TAC)
- Familiarization with Gabriel Nimbus / ARNLD and DISA whitelists.
- Familiarization with DOD Joint Enterprise Level Agreement (JELA) contracting agreements
- Knowledge of VMware infrastructure including configuring vSAN, Virtual Standard
- Switches (VSS), virtual distributed switches (vDS).
- Familiarization with VXRail networking architecture
- Knowledge of SolarWinds NetFlow Traffic Analyzer (NTA) and Network Configuration Management (NCM).
- Knowledge of Netflow and Sflow configuration within a Cisco catalyst and Cisco nexus environment.
- Knowledge on DISA Security Technical Implementation Guides (STIGS).
- Knowledge of configuration and management for KG-175D cryptographic devices
- Incumbent must be eligible for DoD Personal Security Clearance.
- The ability to work at a desk for eight hours