Senior Network Engineer / Architect (Cloud & Private Cloud)

Hewlett Packard EnterpriseFort Collins, CO
23hHybrid

About The Position

Senior Network Engineer / Architect (Cloud & Private Cloud) This role has been designed as ‘Hybrid’ with an expectation that you will work on average 2 days per week from an HPE office. Who We Are: Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE. Job Description: We’re looking for a hands-on Network Engineer/Architect to design, implement, and support hybrid network platforms spanning private cloud, VMware-based datacenters, and public cloud (AWS/Azure/GCP). You’ll lead architecture and deep-dive troubleshooting for virtual networking (NSX), SDN, overlays (VXLAN/GENEVE), micro-segmentation, and cloud-native networking—while ensuring scalable connectivity, strong security controls, and high availability. This role is ideal for an expert who’s equally comfortable whiteboarding target-state architectures, writing Terraform/Ansible, and dropping into packet captures or control-plane traces to resolve complex issues.

Requirements

  • 10+ years architecting and operating enterprise/hyperscale networks across datacenter and cloud.
  • Deep VMware networking: NSX‑T (overlay networking, Tier‑0/Tier‑1, DFW micro-segmentation, NAT, LB, Edge clusters, Federation/site DR). vSphere networking (VDS, port groups, teaming/policies) and physical-to-virtual integration patterns.
  • Routing & Switching: Protocol expertise: BGP, OSPF, EVPN, VRF, ECMP, Anycast, IGP/BFD, Multicast (nice to have), MPLS (awareness). Datacenter switching: Cisco (NX‑OS/ACI), Arista EOS, or Juniper at scale.
  • Overlays & SDN: VXLAN/GENEVE, VTEPs, route reflectors, fabric underlay/overlay separation, SDN control-plane concepts.
  • Strong hands-on expertise in SDN & Overlay Protocols: Deep knowledge of VxLAN, EVPN, STP, LACP, vPC/MLAG and OSF/BGP, ACLs for building the scalable fabric that securely connects Private cloud infrastructure stack and platform and external environments
  • Cloud Networking (one or more): AWS: VPC, TGW, DX, PrivateLink, Route 53, GWLB, NLB/ALB, Security Groups/NACLs. Azure: VNet, vWAN/Hub-Spoke, ER, Private Link, Azure Firewall, App GW, NSGs/UDRs, Route Server. GCP: VPC, Shared VPC, Cloud Router, Interconnect, Private Service Connect, GLB.
  • Security & IAM: micro-segmentation frameworks, network security policies, IAM fundamentals (Azure AD/Entra, AWS IAM, Okta), RBAC.
  • Automation & IaC: Terraform, Ansible, Git, and scripting (Python or PowerShell) for repeatable network builds and policy as code.
  • Troubleshooting: Expert packet and control-plane debugging; able to isolate underlay/overlay issues, asymmetric routing, MTU/fragmentation, ECMP/blackhole, and cloud egress nuances.

Nice To Haves

  • HCX planning/execution for migrations; cross‑vCenter, L2 extension, bulk migration runbooks.
  • SD‑WAN (e.g., VMware VeloCloud), SASE integration, and zero trust segmentation strategy.
  • Load Balancing & ADC: F5 BIG‑IP (LTM/GTM), NGINX Plus, AVI/NSX Advanced Load Balancer.
  • DNS/DHCP/IPAM (Infoblox), PKI/TLS patterns, and service discovery in hybrid environments.
  • Container/Kubernetes Networking: CNI (Calico/Cilium), Ingress, east‑west policy, eBPF awareness.
  • Observability: vRNI/Aria Ops for Networks, NSX Traceflow/Port Mirroring, Splunk, ELK, Prometheus/Grafana, vendor telemetry/streaming.
  • Compliance: Experience aligning designs with ISO 27001, SOC 2, PCI DSS, or NIST frameworks.
  • Programming: Python for tooling (API-driven config, drift detection, linting/guardrails).
  • VMware: VCP‑NV, VCAP‑NV, VCDX-NV (plus for architecture leadership).
  • Cloud: AWS Advanced Networking, Azure Network Engineer Associate, GCP Professional Cloud Network Engineer.
  • Networking: CCNP/CCIE (DC or Enterprise), JNCIP/JNCIE, Arista ACE.
  • Security: NSE, PCNSE, or equivalent.

Responsibilities

  • Design hybrid network architectures across datacenter, private cloud (VMware), and public cloud (AWS/Azure/GCP), including L2/L3 segmentation, routing domains/VRFs, overlays, and interconnect.
  • Define and implement SDN architectures (e.g., VMware NSX-T) including micro-segmentation, DFW policies, T0/T1 routing, NAT, Load Balancing (L4–L7), and edge services.
  • Architect multi-site solutions: EVPN/VXLAN fabrics, DC interconnect, cloud on-ramps, and zero-downtime migration patterns (e.g., HCX).
  • Design hybrid connectivity: Direct Connect / ExpressRoute, site-to-site VPN, SD-WAN (e.g., VMware VeloCloud), and BGP-based redundancy.
  • Implement NSX-T components (Managers, Edges, Transport Zones, Segment profiles), overlay networks (VXLAN/GENEVE), Tier-0/Tier-1 routing, and micro-seg rules.
  • Configure and maintain datacenter switching (Cisco NX-OS, ACI; Arista EOS; Juniper) including BGP/OSPF/IS-IS, EVPN, MLAG/vPC, QoS, SPT, MST.
  • Integrate identity and access (e.g., Entra ID/Azure AD, Okta, AWS IAM) with network policies (zero trust, group-based policy, NAC/802.1X where applicable).
  • Support VMware vSphere (ESXi, vCenter), physical-to-virtual networking mapping, and L4–L7 services (Palo Alto / Check Point / F5 BIG‑IP / NGINX).
  • Build and maintain cloud networking: VPC/VNet design, subnetting, IGW/NATGW, peering, Transit Gateway/Hub-Spoke, NACLs/NSGs/Security Groups, private endpoints, and Kubernetes (CNI) networking.
  • Automate with Terraform, Ansible, and scripts (Python, PowerShell); manage configuration via Git and CI/CD.
  • Troubleshoot complex packet flow issues using Traceflow, vRNI/Aria Ops for Networks, pcap/Wireshark, NetFlow/IPFIX, and cloud-native tools.
  • Define and enforce micro-segmentation and zero-trust network access; partner with security for policy definition (app identity, tags, security posture).
  • Implement IAM RBAC, secrets management, and least-privilege access patterns for network change and automation pipelines.
  • Contribute to audit readiness, documentation, and compliance with segmentation/traffic control standards.
  • Engineer for HA/DR, capacity, performance, and failure-domain isolation.
  • Establish monitoring/observability (SNMP/Telemetry, syslog, Prometheus/Grafana, vendor controllers) and SLOs for critical paths.
  • Drive RCAs, corrective actions, and standardization.

Benefits

  • Health & Wellbeing We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.
  • Personal & Professional Development We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.
  • Unconditional Inclusion We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service