Network Designer & Implementer
Job Summary
Location: can be located anywhere in Canada within proximity to a CGI location to support a hybrid work environment.
Anticipated start date: Mid December
Accelerate infrastructure delivery through automation by designing developing and implementing innovative solutions that improve operational efficiency enhance service quality and reduce manual effort. Partner with engineering operations and client teams to build scalable secure and reliable automation capabilities that enable faster service delivery continuous improvement and exceptional client outcomes.
CGI is seeking an experienced Senior Network Designer & Implementer to design engineer implement and evolve enterprise network infrastructure for a major financial services client. This is a senior hands on role requiring deep expertise across Cisco networking F5 application delivery/load balancing Palo Alto Networks security and Network Automation / Infrastructure as Code (IaC). The role owns the lifecycle from requirements and HLD/LLD through implementation testing validation documentation operational handover and production support. The environment is highly available security sensitive and regulated with strong expectations for resiliency security scalability automation operational stability auditability and disciplined change governance.
The ideal candidate is a senior Network Designer/Engineer who combines enterprise networking depth with modern automation capabilities. This is not a purely architectural role: the individual must be equally comfortable with solution design hands on configuration troubleshooting production changes validation and technical leadership. Core platform strengths are Cisco (enterprise/data centre) F5 (application delivery/load balancing) and Palo Alto (network security/firewalls) supported by an automation first mindset using Python Ansible REST APIs Git and IaC.
Key Responsibilities
. Lead secure scalable resilient highly available network solution design; translate business application infrastructure cloud security and operational requirements into HLDs/LLDs covering topology routing connectivity security load balancing resiliency performance and operations.
. Develop implementation migration validation and rollback strategies; assess existing infrastructure and recommend modernization/optimization; document design decisions assumptions risks dependencies trade offs; participate in design/architecture reviews.
. Lead hands on implementation across development test staging DR and production; configure deploy upgrade validate and troubleshoot network/security infrastructure; prepare MOPs and implementation plans; support after hours/weekend production windows when required.
. Coordinate end to end implementation with Network Security Application Server Cloud Storage DNS Operations and vendor teams; ensure solutions conform to approved designs and standards and transition completed solutions into operations/support.
. Provide senior technical leadership mentoring design/troubleshooting facilitation vendor coordination POC/product evaluation support and continuous improvement across network engineering automation documentation and standards.
Core Technology Expertise
Cisco Networking
. Design/implement Layer 2/3 networks; advanced routing/switching and troubleshooting; BGP OSPF and EIGRP where applicable; VLANs trunking STP link aggregation segmentation routing domains QoS high availability redundancy and inter data centre connectivity.
. Hands on experience with Cisco Nexus enterprise switching and routing platforms; Cisco ACI strongly preferred; understanding of SDN/controller based networking; capacity/performance engineering lifecycle upgrades and troubleshooting of latency packet loss asymmetric routing and connectivity issues.
. Perform configuration/design reviews identify deficiencies and recommend corrective actions.
F5 Application Delivery & Load Balancing
. Design implement troubleshoot upgrade and migrate enterprise F5 BIG IP/LTM solutions including Virtual Servers Pools/Pool Members Health Monitors Profiles SSL/TLS profiles SNAT Persistence and Traffic Policies; design highly available architectures.
. Understand HTTP/HTTPS TCP TLS DNS application traffic flows SSL termination/offload and certificate management considerations; F5 DNS/GTM and iRules are highly desirable; F5 APIs/automation strongly preferred.
. Partner with application teams to translate availability and traffic management requirements into F5 configurations.
Palo Alto Networks Security
. Design and implement secure Palo Alto NGFW architectures including security rules/policies NAT zones/interfaces routing integration application/service policies segmentation HA and centralized management with Panorama.
. Use App ID/User ID where applicable; understand threat prevention/security profiles; perform troubleshooting policy optimization/rule base hygiene software upgrades lifecycle activities and integration with automated provisioning/configuration workflows.
. Work with Cybersecurity to meet security standards and controls; Prisma Access/cloud based Palo Alto capabilities are an asset.
Network Automation & Infrastructure as Code
Network Automation is a key requirement. Demonstrated ability to move network engineering from manual configuration to repeatable version controlled workflows is expected.
. Develop automation for provisioning configuration validation compliance backups drift detection and pre/post change checks across Cisco F5 and Palo Alto platforms where supported; use APIs for programmatic interaction.
. Build reusable scripts/modules/workflows; integrate automation with CI/CD; maintain code in source control; apply code review testing approval and deployment controls; reduce manual effort configuration errors and implementation risk.
. Core tools: Python Ansible/Ansible Automation Platform REST APIs JSON/YAML Git CI/CD IaC. Beneficial: Terraform NetBox vendor APIs/SDKs Jenkins/GitLab/GitHub Actions/Azure DevOps network validation/testing frameworks Netmiko/NAPALM/Paramiko or equivalents.
. Automation must be supportable reusable secure controlled and suitable for enterprise operations.
Security Resiliency & Financial Services Controls
. Apply secure by design least privilege segmentation defense in depth controlled administrative access privileged access logging/monitoring configuration traceability and approved change management practices; coordinate with Cybersecurity Risk Compliance Architecture and Audit.
. Complete required security assessments/approvals maintain audit evidence support vulnerability remediation and audit findings and meet financial services technology/security requirements.
. Design for redundancy fault tolerance active/active or active/standby as appropriate; minimize single points of failure; validate failover/recovery; support DR planning/testing and resiliency exercises; align to application RTO/RPO where applicable and document service dependencies.
Troubleshooting Change & Documentation
. Provide senior troubleshooting across routers switches firewalls load balancers and applications; analyze end to end traffic; troubleshoot routing DNS TCP SSL/TLS latency packet loss firewall and load balancing issues; perform packet captures/traffic analysis; lead RCA and permanent corrective actions; use automation to prevent recurring issues.
. Prepare change records implementation/validation/communication/rollback plans; participate in technical/CAB reviews; coordinate dependent teams; execute within approved windows; perform post change validation and recovery; maintain strong change hygiene.
. Maintain HLDs LLDs diagrams traffic/security flows implementation/migration plans MOPs test/validation and rollback plans SOPs configuration standards automation runbooks operational support documentation and knowledge transfer materials.
Mandatory Qualifications & Experience
. 10 years of enterprise network engineering experience with significant hands on design and implementation responsibility in large complex environments.
. Strong hands on expertise with Cisco networking F5 BIG IP/LTM and Palo Alto Networks firewalls/Panorama; advanced TCP/IP routing/switching BGP/OSPF and Layer 2/3 troubleshooting skills.
. Demonstrated experience with resilient/high availability architectures and business critical production environments.
. Demonstrated Network Automation experience using Python Ansible APIs and/or IaC plus Git/source control.
. Experience producing HLDs/LLDs implementation plans network diagrams production changes and complex multi tier application connectivity troubleshooting.
. Strong network security/segmentation knowledge; strong written/verbal communication; able to work across infrastructure security application cloud operations vendors and business teams.
Preferred Qualifications & Certifications
. Financial services experience (banking payments capital markets insurance) and highly regulated/security sensitive environments; Cisco ACI; F5 DNS/GTM and iRules; Prisma Access; AWS/Azure/GCP and hybrid/multi cloud networking; SDN; Terraform; network CI/CD; automated testing/validation; ServiceNow/ITSM integration; monitoring/observability/telemetry; DNS/DHCP/IPAM; data centre migration/network transformation; distributed teams/managed service providers.
. Certifications: CCNP Enterprise/Data Center CCIE F5 Certified Technology Specialist Palo Alto PCNSE AWS/Azure/GCP networking Red Hat Ansible Automation HashiCorp Terraform and/or ITIL. Equivalent hands on experience accepted.
Working Conditions
. Location: Anywhere in Canada.
. Work model: Hybrid minimum three days per week in office.
. Schedule: Standard eight hour workday; occasional after hours evening or weekend work may be required based on project or operational needs.
. Travel: No travel required.
Security & Compliance Requirements
. Must be eligible to obtain and maintain Government of Canada Protected B Security Clearance.
. Must adhere to all client security operational and compliance policies.
MANDATORY QUALIFICATIONS & EXPERIENCE
.10 years of enterprise network engineering experience with significant hands on design and implementation responsibility in large complex environments.
.Strong hands on expertise with Cisco networking F5 BIG IP/LTM and Palo Alto Networks firewalls/Panorama; advanced TCP/IP routing/switching BGP/OSPF and Layer 2/3 troubleshooting skills.
.Demonstrated experience with resilient/high availability architectures and business critical production environments.
.Demonstrated Network Automation experience using Python Ansible APIs and/or IaC plus Git/source control.
.Experience producing HLDs/LLDs implementation plans network diagrams production changes and complex multi tier application connectivity troubleshooting.
.Strong network security/segmentation knowledge; strong written/verbal communication; able to work across infrastructure security application cloud operations vendors and business teams.
PREFERRED QUALIFICATIONS & CERTIFICATIONS
.Financial services experience (banking payments capital markets insurance) and highly regulated/security sensitive environments; Cisco ACI; F5 DNS/GTM and iRules; Prisma Access; AWS/Azure/GCP and hybrid/multi cloud networking; SDN; Terraform; network CI/CD; automated testing/validation; ServiceNow/ITSM integration; monitoring/observability/telemetry; DNS/DHCP/IPAM; data centre migration/network transformation; distributed teams/managed service providers.
.Certifications: CCNP Enterprise/Data Center CCIE F5 Certified Technology Specialist Palo Alto PCNSE AWS/Azure/GCP networking Red Hat Ansible Automation HashiCorp Terraform and/or ITIL. Equivalent hands on experience accepted.
WORKING CONDITIONS
.Location: Anywhere in Canada.
.Work model: Hybrid minimum three days per week in office.
.Schedule: Standard eight hour workday; occasional after hours evening or weekend work may be required based on project or operational needs.
.Travel: No travel required.
SECURITY & COMPLIANCE REQUIREMENTS
.Must be eligible to obtain and maintain Government of Canada Protected B Security Clearance.
.Must adhere to all client security operational and compliance policies.
CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level geographic market experience and training and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $75000$125000. This role is an existing vacancy
#LI-AB19
- Cisco
- English
- F5
- Network Security
- Nexus
- TCP/IP
- ITIL Service Manager
- ServiceNow
Together as owners lets turn meaningful insights into action.
Life at CGI is rooted in ownership teamwork respect and belonging. Here youll reach your full potential because
You are invited to be an owner from day 1 as we work together to bring our Dream to life. Thats why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our companys strategy and direction.
Your work creates value. Youll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas embrace new opportunities and benefit from expansive industry and technology expertise.
Youll shape your career by joining a company built to grow and last. Youll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.
At CGI we value the strength that diversity brings and are committed to fostering a workplace where everyone belongs. We collaborate with our clients to build more inclusive communities and empower all CGI partners to thrive. As an equal-opportunity employer being able to perform your best during the recruitment process is important to us. If you require an accommodation please inform your recruiter.
That same commitment to fairness extends to how we use technology. To support our recruitment team AI tools may be used to help assess applications though they never replace human judgement. All hiring decisions remain entirely in the hands of our recruitment professionals.
To learn more about accessibility at CGI contact us via email. Please note that this email is strictly for accessibility requests and cannot be used for application status inquiries.
Come join our teamone of the largest IT and business consulting services firms in the world.
Required Experience:
IC
About Company
The COMPANY is one of the few end-to-end consulting firms with the scale, reach, capabilities and commitment to meet clients’ enterprise digital transformation needs. Our 77,500 consultants and professionals work side-by-side with clients in 10 industries across more than 400 location ... View more