DevSecOps Engineer- Level 2
Remote
Client: NYS ITS Information Technology Services
Designated Work Location: CNSE ZEN Bldg., Room 205, 201 Fuller Road, Albany, NY 12203
Anticipated Duration of the Engagement: 36 Month
Project: Data Center Networks (DCN) Hybrid Cloud – GCP
EST Zone Candidate
Only USC, GC and GC EAD
Mandatory Qualifications:
Desirable Qualifications
· Working knowledge of cloud application platforms and their networking requirements (Kubernetes engines/services, serverless, etc.)
· Proficiency in Terraform to assist in the development of Infrastructure as Code (IaC) and CI/CD for uniform cloud configuration and backup solutions
· Proficient Microsoft Azure network infrastructure: VNets, subnets, NSGs, route tables, VNGs, Site-to-site VPN, ExpressRoute Direct, load balancers, logging, alerting, and troubleshooting.
· Proficient AWS network infrastructure: VPCs, subnets, security groups, route tables, Virtual Private GW, Transit Gateway, Cloud WAN, Site-to-Site VPN, Direct Connect,
· NACLs, load balancers, peering, logging, alerting, and troubleshooting.
· Experience working with monitoring and packet capture/analysis tools such as Zenoss, Splunk, Palo Alto Panorama, Arista Cloud Vision as a Service, NfSen, Ixia, Gigastor, Wireshark, etc
· Proficiency in Microsoft Visio for solutions documentation
· Proficiency in Domain Name System (DNS) and managing split-brain public/private resolution design
Project or Program: Data Center Networks (DCN) Hybrid Cloud – GCP
Duties and Responsibilities to be performed by the consultant
· Manage and lead in the orchestration of multi-discipline technologies for the resolution of complex problems; communicate with technology and business leaders for problem resolution and make recommendations for system enhancements as required.
• Provide 24x7x365 on-call network support for advanced troubleshooting, escalation and ticket resolutions on a rotating basis
• Design, deploy, and maintain cloud networking infrastructure in AWS, Azure, and GCP to support new and existing NYS agency application deployments in the cloud
• Design, deploy, and maintain network virtual appliances as needed including Arista CloudEOS and Palo Alto PAN-OS with integrations into CSP network
infrastructure (GCP NCC, AWS TGW Connect, etc.) , etc.)
• Design and implement on-prem to cloud connectivity solutions as required by application needs in collaboration with ISO and network/application architecture
teams
• Assist with application design to ensure connectivity compliance with NYS ITS information security standards
• Collaborate and troubleshoot with direct cloud connectivity providers to develop solutions and solve problems
• Assist in the development of Infrastructure as Code (IaC) uniform cloud configuration, deployment, and backup solutions using Terraform
• Provide in-depth analysis on network performance using monitoring tools such as Zenoss, Splunk, Palo Alto Panorama, Arista Cloud Vision as a Service, NfSen, Ixia,
Gigastor, Wireshark, etc.
• Ensure that network availability of cloud environments is maximized by overseeing Change Control procedures, code upgrades, network monitoring, installations,
moves and changes, and troubleshooting complex issues.
• Oversee network monitoring to ensure maximum network availability.
• Participate in network performance analysis, training, and capacity planning.
• Document all design and implementation work using Microsoft Visio
• Participate in knowledge transfer and training sessions with junior staff
• Occasional travel may be required.