We are looking for a senior hands-on Network Architect / Engineer to take ownership of the organisation’s network architecture, engineering, and day-to-day technical delivery.
This is a hands-on architecture and engineering role, rather than a pure design or governance position. You will be responsible for designing network solutions, configuring infrastructure, executing production changes, troubleshooting complex incidents, and driving network improvements across a multi-site environment.
The environment includes enterprise networking across multiple locations, an Azure hub-and-spoke architecture, hybrid connectivity through ExpressRoute and VPN, as well as connectivity to external partners and business-critical services.
Network availability, resilience, and latency are particularly important to the business, so the role requires someone who is comfortable operating in a high-performance environment where network issues can have a direct business impact.
Key Responsibilities
- Take ownership of the overall network architecture and engineering standards across multiple sites, covering campus networks, data centres, WAN, and remote access.
- Design, configure, and maintain routing, switching, wireless, and firewall infrastructure hands-on, including developing and implementing network configurations.
- Lead and execute production network changes, maintenance activities, and cutovers, ensuring appropriate testing and rollback plans are in place.
- Troubleshoot complex network issues using packet captures, traffic-flow analysis, and device-level diagnostics, taking ownership from initial incident through root-cause identification and permanent resolution.
- Manage the network segmentation strategy and firewall policies, ensuring appropriate separation between business-critical, corporate, guest, and management environments.
- Design and implement the Azure network environment in collaboration with the Cloud Solutions Architect, including hub-and-spoke architecture, network peering, routing, security groups, ExpressRoute, and VPN connectivity.
- Lead network implementation for new office deployments, relocations, and regional expansion, covering activities from carrier coordination and connectivity procurement through to final cutover.
- Manage connectivity with external market data providers, brokers, counterparties, and other third parties, including cross-connects, extranet connectivity, and associated resilience requirements.
- Oversee network capacity, latency, resilience, and failover, as well as firmware/patch management and network monitoring to maintain reliable operations and adequate security visibility.
- Develop network automation and configuration standards using tools such as Python, Ansible, and Terraform, while maintaining architecture documentation aligned with relevant technology risk and cybersecurity frameworks.
Requirements
- 8+ years of hands-on network engineering experience, including at least 3 years in network architecture and design. Experience within regulated financial services or similarly controlled environments is advantageous.
- Must remain technically hands-on, with current experience configuring, troubleshooting, upgrading, and maintaining network infrastructure rather than purely managing or overseeing other engineers.
- Strong expertise in enterprise routing and switching, including BGP, OSPF, VLANs, Spanning Tree, QoS, and multicast.
- Solid experience in next-generation firewall design and administration, including policy management, ruleset governance, NAT, IPS, and secure remote access.
- Strong knowledge of Azure networking, including Virtual Networks, hub-and-spoke architecture, ExpressRoute, VPN Gateway, Azure Firewall, Network Security Groups, and Application Security Groups.
- Experience across WAN and network-edge technologies, including SD-WAN, MPLS, Internet edge architecture, carrier management, and diverse connectivity across multiple locations.
- Strong understanding of core network services, including DNS, DHCP, IP address management, DNS security, enterprise wireless, and RF planning.
- Advanced troubleshooting capabilities, including packet capture and analysis, latency/jitter troubleshooting, and structured fault isolation across Layers 1–7.
- Experience implementing network automation and monitoring using Python, Ansible, Terraform, and enterprise monitoring or network-flow analysis platforms.
- Proven track record of delivering multi-site network implementations and cutovers from planning through completion.
- Willingness to support out-of-hours maintenance activities and escalation/on-call rotations, with strong communication skills and the ability to clearly explain the business impact of technical decisions and network issues.