Job Description: Senior L3 Network Admin– Security, Cloud & Enterprise
Networks
Location
Dubai, UAE (Onsite)
Employment Type
Full-time
Job Summary
We are seeking a highly senior L3 Network Engineer / Network Architect with
8–10 years of hands-on enterprise experience to provide architecture-level
support, lead complex network design validation, and drive network
optimization, security posture, and availability improvements across
enterprise and hybrid cloud environments. The role requires CCIE-level
expertise, deep Azure networking skills at L3 level, and strong leadership in
critical escalations, Zero Trust implementation, and governance.
Key Responsibilities
Architecture & Design Authority
-
Provide architecture-level network support for enterprise and hybrid cloud
environments.
-
Review, validate, and challenge HLDs and LLDs for complex network and
security designs.
-
Drive network optimization, scalability, resiliency, and performance
improvements.
-
Act as the technical authority for multi-vendor network architecture
decisions.
Advanced Network Support & Critical Escalations
-
Act as the final escalation point for business-critical and complex network
incidents.
-
Lead critical incident bridges, drive service restoration, and ensure
minimal business impact.
-
Identify systemic issues and implement long-term availability and stability
improvements.
Security Architecture & Zero Trust
- Lead firewall architecture and security design reviews, including:
- Palo Alto and Cisco FTD firewall policies
-
Rule-base optimization, segmentation, and least-privilege enforcement
-
Drive network segmentation and Zero Trust architecture implementation.
-
Ensure security controls align with enterprise security frameworks and
compliance requirements.
Cloud & Hybrid Networking (Microsoft Azure – L3 Level)
-
Provide L3-level design and operational support for Microsoft Azure
networking, including:
- VNet architecture, routing, UDRs, and NSGs
- Azure VPN Gateway and hybrid connectivity
- Secure connectivity between Azure and on-prem environments
- Optimize cloud network performance, security, and availability.
Core Network Engineering
- Manage and optimize routing and switching using BGP and OSPF.
- Oversee SD-WAN architectures and enterprise WAN optimization.
- Govern DNS, DHCP, and critical network services.
Cisco Platforms – Automation, NAC & Wireless
- Provide expert-level support for:
- Cisco DNA Center (DNAC) – assurance, automation, and analytics
- Cisco Identity Services Engine (ISE) – NAC and policy enforcement
-
Cisco Wireless LAN Controllers (WLC) – enterprise wireless design and
operations
Load Balancing & Application Delivery
-
Provide architecture-level oversight and support for F5 Load Balancers,
including:
- Traffic policies and application delivery optimization
- High availability and resilience design
Governance, Capacity Planning & Compliance
-
Govern network capacity planning, forecasting, and performance management.
-
Ensure compliance, audit readiness, and configuration governance across all
platforms.
-
Support internal and external audits with architecture documentation and
evidence.
Change Management & Leadership
- Chair or act as a senior member of the Change Advisory Board (CAB).
- Review and approve high-risk and major network changes.
- Mentor L3/L2 engineers and provide architectural guidance.
Required Skills & Experience
Experience
-
8–10 years of experience in enterprise network engineering, with senior L3 /
architect-level ownership
-
Proven experience leading large-scale, mission-critical network environments
Technical Expertise (Mandatory)
- CCIE (Enterprise Infrastructure or Security) – mandatory
-
Palo Alto Firewalls (expert level, including segmentation & Zero Trust)
- Cisco Firepower Threat Defense (FTD)
- Microsoft Azure Networking – L3 level
- Cisco DNAC, Cisco ISE, Cisco WLC
- F5 Load Balancers
- Strong expertise in BGP, OSPF, SD-WAN, LAN/WAN
- Solid understanding of DNS, DHCP, and enterprise network services
Certifications (Mandatory / Preferred)
- CCIE – Enterprise Infrastructure or Security (Mandatory)
- Palo Alto Networks: PCNSE (strongly preferred)
- Microsoft Azure: AZ-700 (Azure Network Engineer Associate)
- F5 Networks: F5 Certified Administrator / Specialist
- ITIL® 4 Foundation (preferred)