Job Responsibilities
- Design and manage LAN and WAN topology — Aruba switching, VLAN provisioning and layer 3 routing
- Manage Fortinet and MikroTik firewall policies — rule lifecycle, NAT, CVE patching and security profiles
- Configure and maintain SSL VPN and client VPN services; manage user profiles and monitor tunnel health
- Manage DNS zones, DHCP scopes and IP address management across all environments
- Configure and maintain load balancer rules, health checks and listener configuration
- Manage cloud networking across all provider environments — security groups, routing and cloud VA firewalls
- Operate and maintain anti-DDoS appliances and cloud DDoS mitigation services
- Monitor network performance and availability using Cisco DNA and Cisco Thousand Eyes
- Monitor QoS and conduct regular performance and policy reviews; produce trend analysis reports
- Maintain network security posture; respond to security anomalies and policy violation alerts
- Participate in the change advisory process for all network changes and maintain audit records
- Maintain network documentation, configuration runbooks and topology diagrams
- Provide Level 2/3network incident support and coordinate with vendors where required
- Any other ad-hoc duties as assigned by supervisor
Requirements
- Degree in IT or related discipline
- LAN and WAN — switching, VLAN management, trunking, Spanning Tree and layer 3 routing
- Aruba switching — configuration, VLAN provisioning, port management and policy management
- Firewall management — Fortinet FortiGate and MikroTik; policy creation, NAT and security profiles
- VPN — SSL VPN and client VPN gateway configuration, profile management and monitoring
- DNS, DHCP and IPAM — zone management, scope configuration and IP address lifecycle
- Load balancing — rule configuration, health check management and listener lifecycle
- Cloud networking — virtual networks, security groups, NSG, cloud VA firewall and routing
- Cloud network virtual appliance firewalls — deployment, policy management and monitoring
- Anti-DDoS — on-premises DDoS appliance and cloud-native DDoS mitigation management
- Network monitoring — Cisco DNA Centre and Cisco Thousand Eyes for visibility and synthetic testing
- QoS monitoring — quality of service configuration, monitoring and performance trend analysis
- Network security support — posture monitoring, CVE patching and security policy compliance
- Infrastructure as code — Terraform and Ansible for network configuration management
- Performance and policy review — regular network performance analysis and policy optimisation
Interested applicants, please email your resume to Andre Chua Jing Ming
Email: andrechua@recruitexpress.com.sg
CEI Reg No: R1989053
EA Licence No: 99C4599
Recruit Express Pte Ltd