About The Position

CarMax is modernizing and scaling its technology platforms to support secure, reliable, and resilient digital experiences. As a Principal Engineer within the Solutions Delivery and Engineering organization, you will provide senior technical leadership across enterprise networking, cloud networking, and automation, with a specific focus on Identity Services Engine (ISE) and Network Access Control (NAC). This role combines hands-on technical expertise with architectural guidance and cross-team influence. You will partner with engineering teams, operational support teams, architects, and leadership to implement, support, and evolve secure network platforms that support both cloud and on-premise environments. The Principal Engineer is a senior individual contributor role focused on technical depth, architectural consistency, and engineering excellence. This position requires strong problem-solving skills, the ability to work across organizational boundaries, and experience influencing technical direction without direct authority. You will be expected to balance strategic thinking with hands-on involvement, particularly in complex or high-impact initiatives related to network security and identity.

Requirements

  • Bachelor’s Degree in Computer Science, Decision Science, Engineering, Statistics, or a related field, or equivalent alternative education, skills, and/or practical experience is preferred.
  • 7+ years of work experience required in Network, Cloud Network, Network Security, and other areas directly relevant to Network/Cloud/Automation responsibilities and tasks; multiple certifications preferred.
  • Demonstrated experience working in large, complex enterprise environments.
  • 7+ years of experience with enterprise routing, switching, firewalls, and wireless networks, with HPE Aruba and Fortinet experience preferred.
  • 5+ years of experience designing, building, and operating network infrastructure in cloud platforms, with Azure preferred.
  • Strong understanding of hybrid networking models connecting on‑premise environments with public cloud platforms.
  • Experience with network automation and scripting using languages such as Python, Ansible or PowerShell.
  • Proven ability to design and support highly available and resilient network architectures.
  • Experience driving technical improvements or standards across multiple teams.
  • Hands-on experience designing, implementing, and supporting Cisco Identity Services Engine (ISE) in enterprise environments.
  • Strong knowledge of Network Access Control (NAC) concepts and implementations for wired, wireless, and device administration use cases.
  • Experience configuring authentication and authorization policies within Cisco ISE.
  • Experience implementing and supporting TACACS+ for device administration and role-based access control.
  • Ability to act as a technical subject matter expert for ISE and NAC, providing guidance to engineering teams and stakeholders.
  • Strong analytical and troubleshooting skills, with the ability to resolve complex technical issues.
  • Clear and effective communication skills, both written and verbal.
  • Ability to work independently while also collaborating across teams and disciplines.
  • Attention to detail and a focus on operational stability and security.
  • Interest in continuous improvement through automation and process optimization.

Responsibilities

  • Provide senior technical leadership for enterprise network and cloud networking platforms, ensuring reliability, scalability, and security.
  • Partner with technology leadership to support large, cross‑organizational initiatives and address complex technical challenges.
  • Collaborate with engineering, architecture, and product teams to design and deliver network and identity solutions aligned with business needs.
  • Influence technical standards, patterns, and best practices across teams, with an emphasis on security, automation, and operational efficiency.
  • Lead design and implementation efforts for network access control (NAC) and identity-based network security solutions.
  • Mentor and guide engineers through technical reviews, design discussions, and problem resolution.
  • Participate in on-call rotation to support scheduled change windows and incident response for enterprise networks.
  • Display high level leadership skills, being able to drive the overall vision of the organization.
  • Stay current with industry trends in networking, cloud connectivity, automation, and identity services, and apply relevant advancements where appropriate.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service