- Please note that this position is not eligible for sponsorship now or in the future, and does not accept H-1B applicants. Applicants must be authorized to work in the United States.*
SUMMARY
The Network Engineer is responsible for designing, implementing, monitoring, maintaining, supporting, and optimizing the Bank’s local area, wide area, wireless, and cloud networks across the corporate office, branch locations, and Microsoft Azure.
This role personally designs, configures, and implements moderately complex network solutions, and partners with the Bank’s managed service providers for joint design and implementation on high-risk and highly complex projects.
It serves as the Bank’s senior technical authority for network architecture and as the internal owner of network-related managed service partners, remaining a hands-on engineer rather than solely a reviewer of partner work.
The role leads the resolution of network and systems incidents escalated from the service desk, ensures network controls and documentation meet regulatory, audit, and examination expectations, and is expected to develop toward broader infrastructure and operations leadership responsibility.
ESSENTIAL DUTIES AND RESPONSIBILITIES
Primary
Network Operations & Support
- Provide day-to-day operational support of network hardware and operating systems, including evaluation of system utilization and response-time monitoring, and the detection, analysis, and resolution of network hardware, software, and incidents escalated from the service desk.
- Perform adds, moves, and changes to voice and data networks in accordance with the Bank’s change management process, including documented change records, testing, back-out plans, and scheduled maintenance windows.
- Monitor and support hybrid connectivity between the data center, branch locations, and Microsoft Azure — including virtual networks, network security groups, site-to-site VPN, Azure Firewall, and hybrid DNS — for outages, capacity constraints, and performance issues.
- Assist Tier 1 & 2 tickets as needed.
Architecture, Design & Implementation
- Design, configure, and implement moderately complex network solutions end to end — including branch and multi-site connectivity, LAN switching and routing, firewall policy, VPN, wireless, and routine segmentation — as a hands-on engineer
- Partner with partners on high-risk and highly complex initiatives (such as core network or data-center redesign, Azure network architecture, and major security-architecture changes) through joint design and implementation, retaining technical ownership and ensuring knowledge transfer to the Bank.
- Perform administration and configuration of all network equipment, including but not limited to routers, SD-WAN edge devices, next-generation firewalls, core and access switches, wireless access points and controllers, network access control, load balancers, and secure remote access platforms.
- Engineer and support the network foundation for the Bank’s unified communications and contact center platforms, including QoS design and validation, SIP/SBC connectivity, bandwidth planning, and WAN readiness for real-time voice and media traffic.
- Create and maintain technical documentation and architecture diagrams.
Managed Services & Vendor Ownership
- Serve as the Bank’s technical owner and escalation for network-related managed service providers, carriers, and contractors — engaging partners primarily for high-risk and highly complex projects and for specialized or overflow capacity; defining requirements, reviewing designs and change tickets before implementation, holding partners accountable to service levels, running the recurring operational cadence, and retaining accountability for outcomes regardless of who executes the work.
Security, Risk & Compliance
- Design, implement, and document network segmentation and access controls in support of internal audit and regulatory examinations; produce and maintain evidence and artifacts requested by auditors and examiners.
- Own firmware currency, patching, and vulnerability remediation for network infrastructure, and remediate findings from penetration tests, vulnerability scans, and audit reviews within agreed timeframes.
- Implement network security controls under the governance and oversight of Information Security, maintaining appropriate separation between control design and control implementation.
- Participate in annual disaster recovery and business continuity testing, including network failover validation, and support incident response activities in partnership with Information Security.
Planning, Governance & Team
- Maintain network asset, license, and support contract inventory; provide input into technology lifecycle planning, capital and operating budgets, and vendor contract renewals.
- Report network availability, capacity, and risk metrics to IT leadership on a recurring basis.
- Proactively identify, assess, and recommend solutions to improve the effectiveness, efficiency, and security of the network.
- Mentor and provide guidance to other members of the team.
- Other duties as assigned.
Secondary
- Support server and storage infrastructure (Azure, physical, and virtual), including Virtual, Windows Server, and MS AD.
- Install servers, software, and other devices on the LAN according to schedule or as requested, ensuring that all work is documented for future reference.
- Verify completion and integrity of system backups, participate in periodic restore testing, and confirm that retention and recovery objectives are met in accordance with the disaster recovery plan.
MINIMUM KNOWLEDGE, SKILLS AND ABILITIES REQUIRED
- Minimum 5 years’ progressive experience in network engineering, including TCP/IP, DNS/DHCP/IPAM, SNMP and network monitoring, dynamic routing (BGP/OSPF), VLANs, LAN switching, wireless, and multi-site WAN and SD-WAN technologies
- Hands-on experience with network security design, configuration, and administration, including next-generation firewalls, VPN, network segmentation, NAC/802.1X, and SASE or Zero Trust network access concepts
- Minimum 3 years of hands-on systems administration experience, including Hyper-V, Windows Server, and Microsoft AD, with working knowledge of server hardware and infrastructure architecture
- Working experience with Microsoft Azure networking, including virtual networks, network security groups, ExpressRoute or site-to-site VPN, Azure Firewall, and hybrid identity and DNS integration
- Working knowledge of enterprise storage and backup platforms
- Familiarity with supporting the SQL Server platform in partnership with application and vendor teams Strong troubleshooting and problem-solving skills are required
- Good interpersonal and communication skills, with the ability to interact effectively with all levels of staff, leadership, auditors, examiners, and outside vendors and partners
- Personal attributes: service-oriented, self-directed, disciplined and documentation-minded, calm under escalation, comfortable holding vendors and partners accountable
- Participation in an on-call rotation, with evening and weekend work required for scheduled change windows, maintenance, and incident response
- Demonstrated experience working with managed service providers as an extension of an internal team, including directing partner work, reviewing designs and changes, and managing service levels and escalations
- Strong technical writing and diagramming skills, with the ability to produce and maintain current network documentation, architecture diagrams, and audit- and examination-ready artifacts
EDUCATIONAL REQUIREMENTS
- BS degree in Information Technology/Systems, Computer Science, Engineering, or a related field, or an equivalent combination of education, certification, and directly relevant experience
- Prefer a combination of current industry certifications, such as Cisco CCNP (or equivalent) and Fortinet; reflecting the Bank’s Cisco and Fortinet environment, plus Microsoft AZ-700 (Azure Network Engineer Associate) and a security foundation such as Security+ or CCNP Security
ADDITIONAL RESPONSIBILITIES
Every employee of Republic Bank is responsible for knowing and practicing Bank Secrecy Laws (AML/CIP/SAR/CTR/OFAC), the USA Patriot Act, and other related regulations as they relate to their specific job function. Training will be provided during your Introductory Period and annually thereafter. If you need additional training, you are responsible for contacting your immediate supervisor.