Network Engineer / Hands-On Network Manager - Houston, TX

Zedcor Security Solutions•Houston, TX
•$110,000 - $135,000•Onsite

About The Position

This is a player-coach position. You will own Zedcor's network end to end: office LAN/WAN and wireless, datacenter networking for our on-premises virtualization and Azure Local buildout, hybrid Azure connectivity, and the edge connectivity that keeps surveillance towers streaming. You help set the standards, do the hands-on engineering, and build the operational discipline our compliance program depends on. This role is based full-time at our Houston office in the Willowbrook area.

Requirements

  • 7+ years of hands-on network engineering, with at least 2 years leading network operations or projects.
  • Ability to Manage Vendors and do excellent Asset tracking and Change Management.
  • Deep routing and switching expertise: BGP, VLANs, spanning tree, QoS, and link aggregation in production environments.
  • Production experience with Azure networking: ExpressRoute, virtual networks, VPN gateways, NSGs, and load balancing.
  • Firewall and WAF administration experience in a production, internet-facing environment.
  • Strong documentation habits: diagrams, IPAM discipline, and change management as a default, not an afterthought.
  • Comfort in a hands-on role: racking, cabling, console access, and after-hours maintenance windows when the work requires it.
  • An active, verifiable professional certification such as CCNP Enterprise or equivalent.
  • Authorization to work in the United States.

Nice To Haves

  • F5 BIG-IP administration (LTM/Advanced WAF); F5 certification a plus.
  • Microsoft Certified: Azure Network Engineer Associate (AZ-700).
  • Datacenter networking for hyperconverged or Kubernetes environments (Azure Local, AKS, Proxmox VE).
  • Experience supporting SOC 2, ISO 27001, or similar audit programs.

Responsibilities

  • Design, build, and operate LAN, WAN, and wireless networks across the Houston headquarters, Calgary and remote sites across the US and Canada, including structured cabling, switching, wireless, 802.1x, VPN.
  • Own datacenter networking, Telcom connection management and monitoring.
  • Engineer and operate hybrid cloud networking: ExpressRoute, VPN gateways, virtual networks, NAT gateways, DNS, and Azure Front Door.
  • Administer the F5 BIG-IP with WAF fronting production, including policy tuning, upgrades, and failover testing.
  • Manage firewalls, network segmentation, and access controls aligned to Zero Trust principles and Entra ID-based identity.
  • Own IP address management, DNS/DHCP, and network documentation; drive the IPAM platform operation.
  • Manage ISP and carrier relationship across multiple sites/countries, including circuit provisioning, escalation, and cost control
  • Build network monitoring and alerting into our monitoring stack and respond to network-related security events
  • Produce and maintain the change records, diagrams, and configuration evidence required for SOC 2 Type II, and participate in audit walkthroughs
  • Mentor and direct junior IT staff on network tasks; establish runbooks so the network survives without heroics
  • Design, build, maintain, and troubleshoot IPsec and SSL VPN networks.
  • Manage and support a Cradlepoint environment of 20,000+ devices.
  • Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform.
  • Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls.
  • Patch, monitor, log, audit, and secure network infrastructure.
  • Ensure network links, management access, VPNs, and sensitive data flows are encrypted.
  • Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks.
  • Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness.
  • Use Zedcor’s internal PKI solution for device identity, certificates, authentication, encryption, and secure management.
  • Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting.
  • Ensure firewalls are used as security enforcement points, not as core infrastructure service providers.
  • Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door.
  • Configure and troubleshoot dynamic routing, including internal BGP.
  • Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms.

Benefits

  • We provide the tools, mentorship, and the environment to help you thrive and grow in your career.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service