Title: Network Engineer III
Location: Portland, Oregon- Hybrid
Duration: 14 months contract
Visa : No USC,Opt
Job Description:
· Secure Network Architecture, Design, and Implementation
· Design and implement scalable, secure, and highly available network solutions across hybrid environments—including regional campuses, data centers, and multi-cloud platforms (AWS, Azure)—to meet evolving business and security requirements.
· Define and enforce architectural standards grounded in zero-trust principles and industry best practices to protect enterprise network services.
· Drive automation initiatives using APIs, infrastructure-as-code, and orchestration platforms to streamline provisioning, enforce security compliance, and reduce human error.
· Design spine-leaf architectures leveraging EVPN-VXLAN for secure Layer 2 overlays and BGP for robust Layer 3 routing across enterprise environments.
· Configure NGFW solutions with advanced threat prevention, SSL/TLS inspection, application control, and integration with security orchestration platforms for proactive defense.
· Architect enterprise wireless solutions with RF optimization, 802.1X authentication, IoT segmentation, and guest isolation to safeguard connectivity.
· Implement and maintain secure VPN solutions—including site-to-site, remote access, and cloud gateways—to protect data in transit across distributed environments.
· Utilize cloud-based platforms (Cisco Meraki, Palo Alto Strata Cloud Manager, Fortinet FortiCloud, Zscaler) for unified configuration, monitoring, and compliance enforcement.
· Develop comprehensive documentation—standards, models, diagrams, templates—and integrate automated compliance checks to ensure continuous security posture.
· Document solutions via runbooks, diagrams, and operating procedures for operational delegation to administrative, managed service provider, and support staff.
· Partner with InfoSec and application teams to audit, monitor, and proactively mitigate threats across wired and wireless infrastructure.
Secure Network Operations, Incident Response, and Continuous Improvement
· Maintain and optimize secure, scalable, and resilient network infrastructure across on-premises, cloud, and hybrid environments, ensuring compliance with zero-trust principles and security standards.
· Oversee campus spine-leaf fabrics, data center switches, internet routing, cloud virtual networking, wireless controllers, and multi-cloud connectivity with a focus on security and high availability.
· Provide architectural direction and escalation support to managed service providers, enforcing security policies, operational standards, and incident response procedures for critical outages and complex issues.
· Administer EVPN-VXLAN overlays and BGP routing for underlay and overlay connectivity, ensuring encrypted and authenticated communication across enterprise fabrics.
· Manage NGFW platforms through policy lifecycle management, threat prevention tuning, IPS/IDS signature updates, URL filtering, and integration with threat intelligence feeds.
· Utilize cloud-based management platforms (Cisco Meraki, Palo Alto Strata Cloud Manager, Fortinet FortiCloud) for proactive monitoring, firmware updates, analytics, and compliance enforcement.
· Engineer and maintain VPN infrastructure with IPsec/SSL configurations, certificate management, MFA integration, and high-availability concentrators to protect remote workforce connectivity.
· Oversee enterprise wireless systems with robust authentication (802.1X), segmentation for IoT, and guest isolation, while ensuring capacity planning and secure onboarding.
· Serve as the escalation point for critical network incidents and outages; lead structured RCA and implement preventative measures to reduce recurrence.
· Respond to internal and external audits by providing technical documentation, system evidence, and compliance reporting; collaborate with audit teams to demonstrate adherence to security standards and organizational policies.
· Participate in disaster recovery exercises and maintain resilient continuity plans for critical network infrastructure.
· Implement automated governance checks, performance baselines, and proactive security audits to maintain architectural integrity and operational resilience.
Strategy, Innovation, and Secure Network Architecture
· Collaborate with key stakeholders to establish a resilient, security-first network infrastructure strategy and technology roadmap aligned with organizational objectives.
· Assess and recommend advanced network services, architectures, and security frameworks that improve operational efficiency, performance, and cost-effectiveness while reducing risk and automating manual processes.
· Design and implement modern networking patterns and cloud-native solutions that ensure secure connectivity across the Port’s hybrid infrastructure.
· Partner closely with Information Security and application teams to securely deploy, audit, and continuously monitor wired and wireless enterprise networks, ensuring compliance with security standards and best practices.
· Conduct comprehensive evaluations of existing network infrastructure to identify vulnerabilities, optimization opportunities, migration pathways, and modernization strategies.
· Translate complex technical and security concepts into clear recommendations for both technical and non-technical stakeholders.
· Delegate responsibilities effectively and mentor IT staff to strengthen security awareness and technical proficiency across the department.
· Share expertise and promote best practices in secure network design, threat mitigation, and resilience strategies to elevate organizational capabilities.
Knowledge Sharing and Learning
· Be continuously learning on acquiring new skills and knowledge through both formal and informal professional development opportunities including online courses, workshops, conferences, professional certifications, mentorship programs, and peer learning.
· Share expertise with staff to elevate technical capabilities across the organization.
· Stay current with industry standards and best practices; draft new policies and procedures and integrate improvements into Port systems
Regards,
Sandy M | 1Point System LLC
Lead Technical Recruiter
Direct:
(803)-828-2974
• Email: sa...@1pointsys.com
• Fax: 803-832-7973 • www.1pointsys.com
115 Stone Village Drive • Suite
C • Fort
Mill, SC • 29708
LinkedIn : https://www.linkedin.com/in/sandy-m-74b06b212/
An E-Verified company | An Equal Opportunity Employer