Position Summary:
We are seeking a strong, hands-on Network Engineer to join our IT infrastructure team. Reporting to the Senior Network Engineer, this role owns the day-to-day operation, maintenance, and improvement of the company's network, firewall, and connectivity infrastructure across on-premises data centers and a growing Microsoft Azure environment, including the Cisco compute fabric, NetApp storage networking, and Palo Alto security platforms that support it. The ideal candidate is a deeply technical engineer with strong fundamentals, disciplined troubleshooting, and excellent documentation.
Technical Environment:
- Security: Palo Alto Networks next-generation firewalls (PAN-OS) across on-premises data centers and Azure, GlobalProtect VPN, Cloudflare, and Zero Trust / network access control.
- Switching and compute fabric: Cisco Catalyst campus switching and Cisco Nexus (NX-OS) data-center switching; Cisco UCS X-Series (chassis, Fabric Interconnects, Intersight).
- Routing and WAN: BGP, OSPF, and EIGRP across a multi-site WAN (MPLS / DIA circuits) with site-to-site IPSec VPN.
- Storage networking: NetApp ONTAP (FAS / AFF) with SnapMirror replication; Tintri.
- Cloud: a substantial and growing Microsoft Azure networking footprint (hub-and-spoke VNets, peering, VPN Gateway, Azure Firewall, NSGs, and user-defined routes).
- Wireless and monitoring: UniFi wireless; Site24x7 monitoring.
Key Responsibilities:
- Operate, maintain, and monitor enterprise LAN, WAN, and UniFi wireless infrastructure across multiple sites.
- Administer Palo Alto Networks firewalls (PAN-OS), including security policy, NAT, threat prevention, URL filtering, and GlobalProtect VPN; tune App-ID and SSL / TLS decryption.
- Design, implement, and support Microsoft Azure networking, including hub-and-spoke VNets, peering, VPN Gateway, Azure Firewall, NSGs, and user-defined routes.
- Configure and troubleshoot routing and switching (BGP, OSPF, EIGRP) across Cisco Catalyst and Cisco Nexus (NX-OS) switches and the Cisco UCS X-Series Fabric Interconnect environment in a multi-site network.
- Build and maintain site-to-site IPSec VPN connectivity with business partners and vendors.
- Support NetApp ONTAP storage networking and replication.
- Administer network monitoring platforms; maintain alerting, dashboards, NetFlow, and device-health visibility.
- Administer and support network security applications and Zero Trust / network access control.
- Respond to network alerts and incidents; perform root-cause analysis and permanent remediation.
- Participate in planned maintenance windows, including change preparation, verification, and rollback procedures.
- Create and maintain network documentation, diagrams, IP address management (IPAM), and runbooks.
- Install, rack, and cable network hardware; support equipment lifecycle and refresh projects.
- Assist with network security tasks, including certificate management, vulnerability remediation, and access reviews.
- Participate in an on-call rotation.
Why Windward Risk Managers:
- Windward Risk Managers is proud to be recognized on Fortune's 2026 Best Medium Workplaces list, ranking #28 among the Top 100 companies
- 100% employer paid health insurance for employees
- Up to 6% 401(k) match with immediate vesting
- Long-term and short-term disability insurance
- 3 weeks PTO to start + generous paid holidays
- Tuition reimbursement and continuing education support
- Collaborative and growth focused culture
Qualifications
Required Qualifications:
- 5+ years of hands-on network engineering or network administration experience.
- Strong understanding of TCP/IP fundamentals, including subnetting, routing, NAT, DNS, and DHCP.
- Production experience with enterprise-class routers and switches, including Cisco Catalyst, Cisco Nexus (NX-OS), and Cisco UCS X-Series Fabric Interconnects.
- Hands-on production experience with Palo Alto Networks firewalls (PAN-OS), including security policy, NAT, and VPN.
- Working knowledge of at least one dynamic routing protocol (OSPF, EIGRP, or BGP).
- Demonstrated experience with Microsoft Azure networking (VNets, peering, VPN Gateway, NSGs, and routing).
- Experience with NetApp (or comparable enterprise) storage and its supporting network connectivity.
- Experience with network monitoring tools and alerting platforms.
- Experience supporting network security applications.
- Methodical troubleshooting skills using packet captures, logs, and device diagnostics.
- Strong written documentation skills.
- Works well in a collaborative team environment, with strong self-motivation to drive projects through to completion.
Preferred Qualifications:
- Palo Alto Networks Network Security Professional, the entry-level certification in the current role-based program. The legacy PCNSA also applies.
- Cisco Certified Network Associate (CCNA).
- Microsoft Azure Network Engineer Associate (AZ-700) and / or Azure Administrator Associate (AZ-104).
- NetApp Certified Technology Associate (NCTA).
- Experience with Cisco UCS X-Series and Intersight data-center compute fabric.
- IPSec VPN design and troubleshooting experience.
- Familiarity with server, virtualization, or storage environments.
Work Environment:
- Reports to: Senior Network Engineer.
- Scope: owns day-to-day network operations and project execution; partners with the Senior Network Engineer, who leads network architecture and standards.
- Full-time position with participation in an on-call rotation.
- Occasional travel between company sites may be required.
Due to current business and operational considerations, we currently hire employees residing in the following states at this time: AL, AR, CA, CT, FL, GA, KY, MO, NC, NV, OH, SC, TN, TX, VA, and WI.
Candidates must be authorized to work for any employer in the U.S. without requiring visa sponsorship now or in the future.
WRM is committed to providing equal employment opportunities to all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, or veteran status. We take affirmative action to ensure that all employment decisions are based on merit, qualifications, and abilities.
Notice to Third Party Agencies: WRM does not accept unsolicited resumes from third party recruiting firms. Absent a signed Service Agreement by WRM's Human Resources Department, WRM reserves the right to pursue and hire these candidates without financial obligation to recruiters or agencies.
