Spring, Texas, United States of America
7 hours ago
Senior Network Engineer / Architect (Cloud & Private Cloud)
Senior Network Engineer / Architect (Cloud & Private Cloud)

  

This role has been designed as ‘Hybrid’ with an expectation that you will work on average 2 days per week from an HPE office.

Who We Are:

Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.

Job Description:

   

We’re looking for a hands-on Network Engineer/Architect to design, implement, and support hybrid network platforms spanning private cloud, VMware-based datacenters, and public cloud (AWS/Azure/GCP). You’ll lead architecture and deep-dive troubleshooting for virtual networking (NSX), SDN, overlays (VXLAN/GENEVE), micro-segmentation, and cloud-native networking—while ensuring scalable connectivity, strong security controls, and high availability.

This role is ideal for an expert who’s equally comfortable whiteboarding target-state architectures, writing Terraform/Ansible, and dropping into packet captures or control-plane traces to resolve complex issues.

What You’ll Do (Key Responsibilities)

Architecture & DesignDesign hybrid network architectures across datacenter, private cloud (VMware), and public cloud (AWS/Azure/GCP), including L2/L3 segmentation, routing domains/VRFs, overlays, and interconnect.Define and implement SDN architectures (e.g., VMware NSX-T) including micro-segmentation, DFW policies, T0/T1 routing, NAT, Load Balancing (L4–L7), and edge services.Architect multi-site solutions: EVPN/VXLAN fabrics, DC interconnect, cloud on-ramps, and zero-downtime migration patterns (e.g., HCX).Design hybrid connectivity: Direct Connect / ExpressRoute, site-to-site VPN, SD-WAN (e.g., VMware VeloCloud), and BGP-based redundancy.Implementation & OperationsImplement NSX-T components (Managers, Edges, Transport Zones, Segment profiles), overlay networks (VXLAN/GENEVE), Tier-0/Tier-1 routing, and micro-seg rules.Configure and maintain datacenter switching (Cisco NX-OS, ACI; Arista EOS; Juniper) including BGP/OSPF/IS-IS, EVPN, MLAG/vPC, QoS, SPT, MST.Integrate identity and access (e.g., Entra ID/Azure AD, Okta, AWS IAM) with network policies (zero trust, group-based policy, NAC/802.1X where applicable).Support VMware vSphere (ESXi, vCenter), physical-to-virtual networking mapping, and L4–L7 services (Palo Alto / Check Point / F5 BIG‑IP / NGINX).Build and maintain cloud networking: VPC/VNet design, subnetting, IGW/NATGW, peering, Transit Gateway/Hub-Spoke, NACLs/NSGs/Security Groups, private endpoints, and Kubernetes (CNI) networking.Automate with Terraform, Ansible, and scripts (Python, PowerShell); manage configuration via Git and CI/CD.Troubleshoot complex packet flow issues using Traceflow, vRNI/Aria Ops for Networks, pcap/Wireshark, NetFlow/IPFIX, and cloud-native tools.Security & ComplianceDefine and enforce micro-segmentation and zero-trust network access; partner with security for policy definition (app identity, tags, security posture).Implement IAM RBAC, secrets management, and least-privilege access patterns for network change and automation pipelines.Contribute to audit readiness, documentation, and compliance with segmentation/traffic control standards.Reliability & PerformanceEngineer for HA/DR, capacity, performance, and failure-domain isolation.Establish monitoring/observability (SNMP/Telemetry, syslog, Prometheus/Grafana, vendor controllers) and SLOs for critical paths.Drive RCAs, corrective actions, and standardization.

Required Qualifications (Must-Haves)

10+ years architecting and operating enterprise/hyperscale networks across datacenter and cloud.Deep VMware networking:NSX‑T (overlay networking, Tier‑0/Tier‑1, DFW micro-segmentation, NAT, LB, Edge clusters, Federation/site DR).vSphere networking (VDS, port groups, teaming/policies) and physical-to-virtual integration patterns.Routing & Switching:Protocol expertise: BGP, OSPF, EVPN, VRF, ECMP, Anycast, IGP/BFD, Multicast (nice to have), MPLS (awareness).Datacenter switching: Cisco (NX‑OS/ACI), Arista EOS, or Juniper at scale.Overlays & SDN: VXLAN/GENEVE, VTEPs, route reflectors, fabric underlay/overlay separation, SDN control-plane concepts.Strong hands-on expertise in SDN & Overlay Protocols: Deep knowledge of VxLAN, EVPN, STP, LACP, vPC/MLAG and OSF/BGP, ACLs for building the scalable fabric that securely connects Private cloud infrastructure stack and platform and external environmentsCloud Networking (one or more):AWS: VPC, TGW, DX, PrivateLink, Route 53, GWLB, NLB/ALB, Security Groups/NACLs.Azure: VNet, vWAN/Hub-Spoke, ER, Private Link, Azure Firewall, App GW, NSGs/UDRs, Route Server.GCP: VPC, Shared VPC, Cloud Router, Interconnect, Private Service Connect, GLB.Security & IAM: micro-segmentation frameworks, network security policies, IAM fundamentals (Azure AD/Entra, AWS IAM, Okta), RBAC.Automation & IaC: Terraform, Ansible, Git, and scripting (Python or PowerShell) for repeatable network builds and policy as code.Troubleshooting: Expert packet and control-plane debugging; able to isolate underlay/overlay issues, asymmetric routing, MTU/fragmentation, ECMP/blackhole, and cloud egress nuances.

Preferred Qualifications (Nice-to-Have)

HCX planning/execution for migrations; cross‑vCenter, L2 extension, bulk migration runbooks.SD‑WAN (e.g., VMware VeloCloud), SASE integration, and zero trust segmentation strategy.Load Balancing & ADC: F5 BIG‑IP (LTM/GTM), NGINX Plus, AVI/NSX Advanced Load Balancer.DNS/DHCP/IPAM (Infoblox), PKI/TLS patterns, and service discovery in hybrid environments.Container/Kubernetes Networking: CNI (Calico/Cilium), Ingress, east‑west policy, eBPF awareness.Observability: vRNI/Aria Ops for Networks, NSX Traceflow/Port Mirroring, Splunk, ELK, Prometheus/Grafana, vendor telemetry/streaming.Compliance: Experience aligning designs with ISO 27001, SOC 2, PCI DSS, or NIST frameworks.Programming: Python for tooling (API-driven config, drift detection, linting/guardrails).

Certifications (Preferred/Relevant)

VMware: VCP‑NV, VCAP‑NV, VCDX-NV (plus for architecture leadership).Cloud: AWS Advanced Networking, Azure Network Engineer Associate, GCP Professional Cloud Network Engineer.Networking: CCNP/CCIE (DC or Enterprise), JNCIP/JNCIE, Arista ACE.Security: NSE, PCNSE, or equivalent.

Key Competencies

Systems thinking across underlay/overlay, physical/virtual, and cloud-native boundaries.Strong documentation: HLD/LLD, diagrams (L2–L7), runbooks, and change plans.Stakeholder leadership: partnering with Security, Cloud Platform, SRE, and App teams.Bias for automation and repeatability; “policy as code” mindset.Calm, methodical approach to high-severity incident response.

Tools & Technologies You’ll Use

VMware: vSphere, NSX‑T, HCX, Aria Ops for Networks (vRNI), NSX ALB.Switching/Routing: Cisco NX‑OS/ACI, Arista EOS, Juniper.Security/ADC: Palo Alto, Check Point, F5 BIG‑IP, NGINX.Cloud: AWS, Azure, GCP (core networking stacks, gateways, LB, private endpoints).Automation: Terraform, Ansible, GitHub/GitLab, Python, PowerShell.Observability: Wireshark, NetFlow/IPFIX, SNMP/telemetry, Prometheus/Grafana, Splunk/ELK.IAM: Entra ID (Azure AD), AWS IAM, Okta.

Working Model

Hybrid/On‑site: as needed for DC work or critical changes.On‑Call: rotational for P1 incidents and major changes.Travel: up to 10–20% for datacenter or site deployments (as required).

Additional Skills:

Cloud Architectures, Cross Domain Knowledge, Design Thinking, Development Fundamentals, DevOps, Distributed Computing, Microservices Fluency, Full Stack Development, Release Management, Security-First Mindset, User Experience (UX)

What We Can Offer You:

Health & Wellbeing

We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.

Personal & Professional Development

We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.

Unconditional Inclusion

We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.

Let's Stay Connected:

Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE.

#unitedstates

Job:

Engineering

Job Level:

TCP_05

    

\"The expected salary/wage range for this position is provided below. Actual offer may vary from this range based upon geographic location, work experience, education/training, and/or skill level.
– United States of America: Annual Salary USD 160,000 - 303,000 in Colorado // 172,000 - 328,000 in Massachusetts // 152,000 - 349,000 in Texas
The listed salary range reflects base salary. Variable incentives may also be offered.\"

Information about employee benefits offered in the US can be found at https://myhperewards.com/main/new-hire-enrollment.html

The estimated job application period closure is June 1 2026; this timeline is provided for transparency and internal planning purposes.

HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: Equal Employment Opportunity.

Hewlett Packard Enterprise is EEO Protected Veteran/ Individual with Disabilities.

   

HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories.

   

No Fees Notice & Recruitment Fraud Disclaimer

 

It has come to HPE’s attention that there has been an increase in recruitment fraud whereby scammer impersonate HPE or HPE-authorized recruiting agencies and offer fake employment opportunities to candidates.  These scammers often seek to obtain personal information or money from candidates.

 

Please note that Hewlett Packard Enterprise (HPE), its direct and indirect subsidiaries and affiliated companies, and its authorized recruitment agencies/vendors will never charge any candidate a registration fee, hiring fee, or any other fee in connection with its recruitment and hiring process.  The credentials of any hiring agency that claims to be working with HPE for recruitment of talent should be verified by candidates and candidates shall be solely responsible to conduct such verification. Any candidate/individual who relies on the erroneous representations made by fraudulent employment agencies does so at their own risk, and HPE disclaims liability for any damages or claims that may result from any such communication.

Confirmar seu email: Enviar Email