Network Infrastructure Engineer, AVP

State StreetQuincy, MA
17h

About The Position

We are seeking a Network Infrastructure Engineer to design, build, and operate a modern global network based on Versa, Cisco and Arista technologies including SD-WAN, Network Segmentation, Wireless, Client and Vendor Connectivity and Cloud Computing. The engineer will also be responsible for third party connectivity for SD-WAN and IPSec access. This role sits at the intersection of networking and security and is critical to our transition toward Zero Trust and cloud-first architectures. The engineer will work across campus, office, WAN, cloud, and third party access environments within large, globally distributed enterprise environments, integrating SD‑WAN, segmentation, and cloud‑delivered security controls to deliver resilient, scalable, and secure connectivity. This role plays a key part in evolving the firm’s global network, security and segmentation posture. The engineer will implement standards and architecture decisions across campus, branch, and cloud environments globally. This role is ideal for an engineer who is strong in one or more of these domains and motivated to deepen their expertise across secure edge, Zero Trust, and modern network architectures. We value curiosity, adaptability, and sound engineering judgment as much as prior exposure to specific tools or platforms. What you will be responsible for Candidates are not expected to have deep expertise in every area listed below. Strength in several of these domains, combined with the ability to learn and adapt, is highly valued. Strong routing and switching especially strong BGP and BGP to OSPF routing redistribution. SD-WAN technologies and architectures (Versa SD-WAN preferred). Network segmentation including VRFs, VLANs, access control, and micro segmentation. Designing and supporting enterprise campus networks, including wired and wireless with Cisco and Arista technology. Engineering and configuration of IPSec VPNs. Configuration and Troubleshooting skills across WAN, LAN, wireless, and secure access domains both with management tools and CLI. Experience with Dot1X and Port Level Security deployments. What We Value These skills will help you be successful Candidates are not expected to have deep expertise in every area listed below. Strength in several of these domains, combined with the ability to learn and adapt, is highly valued. Strong understanding of why the technology is being deployed. Strong sense of ownership and accountability. Ability to work across networks, security, and cloud teams. Clear and effective communication of complex technical concepts. Analytical thinking and structured problem-solving. Continuous learning mindset in a rapidly evolving technology landscape.

Requirements

  • Strong routing and switching especially strong BGP and BGP to OSPF routing redistribution
  • SD-WAN technologies and architectures (Versa SD-WAN preferred)
  • Network segmentation including VRFs, VLANs, access control, and micro segmentation
  • Designing and supporting enterprise campus networks, including wired and wireless with Cisco and Arista technology
  • Engineering and configuration of IPSec VPNs
  • Configuration and Troubleshooting skills across WAN, LAN, wireless, and secure access domains both with management tools and CLI
  • Experience with Dot1X and Port Level Security deployments
  • Strong understanding of why the technology is being deployed
  • Strong sense of ownership and accountability
  • Ability to work across networks, security, and cloud teams
  • Clear and effective communication of complex technical concepts
  • Analytical thinking and structured problem-solving
  • Continuous learning mindset in a rapidly evolving technology landscape
  • Bachelor's degree in computer science, Engineering, or equivalent practical experience
  • 5-10 years of experience in enterprise network engineering roles

Nice To Haves

  • Relevant networking or security certifications are desirable but not mandatory
  • Past experience in Banking or the Finance vertical
  • Experience or exposure to Security Service Edge / Zero Trust platforms such as Zscaler (ZIA, ZPA, ZDX, Zero Trust Branch) or similar
  • Identity–aware networking and integration with NAC / identity platforms – Cisco ISE and Arista Agni
  • Palo Alto Firewall Configuration and Troubleshooting
  • Enterprise Network tooling – Splunk, Forward Networks and Service NOW

Responsibilities

  • design, build, and operate a modern global network based on Versa, Cisco and Arista technologies including SD-WAN, Network Segmentation, Wireless, Client and Vendor Connectivity and Cloud Computing
  • responsible for third party connectivity for SD-WAN and IPSec access
  • work across campus, office, WAN, cloud, and third party access environments within large, globally distributed enterprise environments, integrating SD‑WAN, segmentation, and cloud‑delivered security controls to deliver resilient, scalable, and secure connectivity
  • implement standards and architecture decisions across campus, branch, and cloud environments globally

Benefits

  • Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service