What are the responsibilities and job description for the IRE Network Engineer position at Northern Trust?
Project Overview / Contractor's Role:
Job Description: IRE Network Engineer
Position Title:
IRE Network Engineer
We are seeking a highly skilled Senior Network Engineer to lead the design, automation, and modernization of enterprise network infrastructure across hybrid environments. This role is responsible for building highly resilient, secure, software-defined network architectures spanning on-premises data centers, private cloud, and public cloud platforms.
The ideal candidate possesses deep expertise in network engineering, Infrastructure as Code (Terraform), scripting, network isolation, micro-segmentation, and cloud networking. This individual will partner closely with Cloud Engineering, Cybersecurity, Infrastructure, SRE, and Application teams to deliver secure, scalable, and automated networking solutions aligned with Zero Trust principles.
________________________________________
Key Responsibilities
Enterprise Network Engineering
• Design, implement, and support highly available enterprise network infrastructure across:
o On-premises data centers
o Private cloud platforms
o AWS
o Microsoft Azure
• Engineer resilient Layer 2/Layer 3 network architectures including:
o Routing
o Switching
o BGP
o OSPF
o VXLAN/EVPN
o SDN technologies
• Design network architectures supporting critical enterprise resiliency and disaster recovery.
________________________________________
Infrastructure Automation
• Build Infrastructure as Code (IaC) solutions using Terraform.
• Develop reusable Terraform modules and standardized deployment patterns.
• Automate network provisioning and configuration management.
• Integrate automation into Git-based CI/CD pipelines.
• Eliminate manual networking activities through automation-first engineering.
________________________________________
Scripting & Automation
Develop automation using:
• Python
• PowerShell
• Bash
• REST APIs
Automate:
• Network provisioning
• Configuration validation
• Compliance verification
• Drift detection
• Operational reporting
• Health monitoring
________________________________________
Network Isolation & Segmentation
Lead enterprise initiatives involving:
• Network isolation strategies
• Secure enclave design
• Air-gapped environments
• Isolated Recovery Environments (IRE)
• Secure management networks
• Recovery network architectures
Design secure separation between:
• Production
• Non-production
• Recovery environments
• Cyber Recovery environments
• Management networks
________________________________________
Micro-Segmentation
Design and implement enterprise micro-segmentation utilizing technologies such as:
• VMware NSX
• Illumio
• Cisco Secure Workload (formerly Tetration)
• Cloud-native security groups
• Azure Network Security Groups
• AWS Security Groups
• Network ACLs
Responsibilities include:
• East-West traffic control
• Zero Trust network architectures
• Least-privilege network access
• Dynamic policy enforcement
• Application dependency mapping
________________________________________
Cloud Networking
Engineer networking solutions across:
AWS
• VPCs
• Transit Gateway
• Direct Connect
• Route Tables
• PrivateLink
• Network Firewall
Azure
• VNets
• ExpressRoute
• Virtual WAN
• Azure Firewall
• NSGs
• Application Gateway
• Azure Load Balancer
________________________________________
Security Engineering
Collaborate with Cyber Security to implement:
• Zero Trust networking
• Network Access Control
• Secure remote connectivity
• Firewall architecture
• IDS/IPS
• DDoS protection
• Secure DNS
• Certificate management
• Encryption in transit
________________________________________
Resiliency Engineering
Design networking solutions supporting:
• High Availability
• Disaster Recovery
• Active-Active architectures
• Active-Passive architectures
• Multi-region cloud deployments
• Automated failover
• Resilient routing
• Critical application recovery
________________________________________
Monitoring & Observability
Implement enterprise network observability using tools such as:
• ThousandEyes
• SolarWinds
• Dynatrace
• Splunk
• Grafana
• Prometheus
• Cloud-native monitoring solutions
Develop dashboards, KPIs, and automated alerting for proactive network operations.
________________________________________
Required Qualifications
• Bachelor’s degree in Computer Science, Information Technology, Engineering, or equivalent experience.
• 8+ years of enterprise network engineering experience.
• 5+ years supporting hybrid cloud networking.
• 3+ years of Terraform Infrastructure as Code experience.
• Strong experience with Python, PowerShell, or Bash scripting.
• Extensive experience with enterprise routing and switching.
• Experience implementing software-defined networking (SDN).
• Hands-on experience designing network isolation and secure segmented environments.
• Experience implementing micro-segmentation in enterprise environments.
• Strong understanding of Zero Trust networking principles.
• Experience supporting mission-critical enterprise platforms.
________________________________________
Preferred Qualifications
• Experience in large financial institutions or other highly regulated industries.
• Experience supporting hybrid multi-cloud environments.
• Knowledge of Kubernetes/OpenShift networking.
• Experience with VMware NSX or Cisco ACI.
• Familiarity with GitHub, GitLab, or Azure DevOps pipelines.
• Experience with disaster recovery and cyber recovery networking.
• Knowledge of Infrastructure as Code governance and policy-as-code.
• Experience with immutable infrastructure and resilient network architectures.
________________________________________
Preferred Certifications
• CCNP Enterprise or CCIE
• AWS Advanced Networking – Specialty
• Microsoft Azure Network Engineer Associate (AZ-700)
• HashiCorp Terraform Associate
• VMware VCP-NV (NSX)
• Palo Alto PCNSE
• CISSP (preferred)
________________________________________
Key Competencies
• Enterprise network architecture
• Hybrid cloud networking
• Infrastructure as Code (Terraform)
• Python, PowerShell, and Bash scripting
• Network automation
• Zero Trust architecture
• Network isolation
• Micro-segmentation
• Cloud networking (AWS & Azure)
• SDN technologies
• Enterprise resiliency
• Disaster Recovery networking
• Cyber Recovery networking
• Infrastructure security
• CI/CD integration
• Cross-functional leadership
• Excellent communication and executive presentation skills
Salary : $85 - $95