Description
Job Summary:
We are seeking a professional with experience in network administration and optimization, infrastructure security, WAN connectivity management, and advanced operational support.
Key Highlights:
1. Expert administration of Cisco and MikroTik network infrastructure.
2. Implementation of L2/L3 security and device hardening.
3. Advanced diagnostics and N2/N3 support across network layers.
DESCRIPTION
Strong expertise in Switching (STP/RSTP/MSTP, VLANs, 802\.1Q, LACP) and Routing (OSPF, HSRP/VRRP, static routes).
Direct hands-on experience administering Cisco infrastructure (Catalyst, IOS/IOS\-XE, WLC, Meraki) and/or MikroTik (RouterOS).
Wireless network administration (corporate WLAN, SSIDs, 802\.1X, coverage analytics).
Network access security controls (ACLs, Port\-Security, DHCP Snooping, DAI, device hardening).
Proficiency with traffic diagnostic and monitoring tools (Wireshark, PRTG, SNMP).
REQUIREMENTS
LAN Network Administration (Switching): Configuration, maintenance, and optimization of Cisco (Catalyst, Meraki) and MikroTik switches. Layer 2 protocol management: Spanning Tree (PVST/RSTP/MSTP), LACP/EtherChannel, VTP, VLAN segmentation, trunks, and broadcast domain management.
Routing and Layer 3: Configuration and troubleshooting of dynamic routing (OSPF and BGP) in core and distribution layers. Route redistribution, neighbor authentication, redundancy via VRRP/HSRP, and routing table maintenance.
Corporate WLAN Infrastructure: Wireless network administration (Cisco WLC, Meraki Dashboard, Aironet/Catalyst APs / MikroTik). SSID configuration, RADIUS/802\.1X authentication integration, RF channel analysis, roaming optimization, and resolution of coverage and client density issues.
Switched Infrastructure Security (L2/L3 Hardening): Implementation of network device access controls: static and extended ACLs, Port\-Security, 802\.1X, DHCP Snooping, Dynamic ARP Inspection (DAI), Storm Control, and BPDU Guard. Application of basic hardening (disabling unnecessary services, TACACS\+/AAA, NTP, SSH).
WAN Connectivity and VPN Management: Monitoring and administration of data links (MPLS, Fiber Optic, LTE backups), basic QoS policies for traffic prioritization (voice/data), and administration of site\-to\-site (IPsec) and remote-access VPN tunnels.
Advanced Diagnostics and Operational Support: Resolution of N2/N3 incidents at Layers 2 and 3 using traffic analyzers (Wireshark) and monitoring tools (PRTG, Zabbix, SolarWinds, Syslog, SNMP).
Change Management and Documentation: Execution of maintenance windows under formal change processes (CAB), development of implementation plans, conformance testing, and rollback procedures. Maintenance of up-to-date topology diagrams, inventories, and port matrices.
Infrastructure Projects and Escalation: Participation in migrations, firmware/software version upgrades (IOS/IOS\-XE, RouterOS), site expansions, and technical coordination with service providers and integrators (ISPs, vendors) to resolve complex failures.