Role Summary
The L3 Network Engineer is responsible for advanced troubleshooting, architecture design, complex change execution, platform integration, and optimization across enterprise LAN, WLAN, security, and network management systems. They provide technical leadership, mentor L2 engineers, and drive network improvements.
Key Responsibilities
Cisco DNAC (Design + Assurance + Automation)
- Architect and maintain DNAC infrastructure (clusters, HA, patching).
- Build and optimize network provisioning templates and automation workflows.
- Perform root-cause analysis using DNAC Assurance (RF issues, path trace, latency).
- Lead design of SDA fabrics, segmentation, and policy automation.
Cisco ISE (NAC / EAP-TLS / MDM / RADIUS / TACACS)
Design and maintain ISE deployment : PSN load balancing, certificates, profiling, posture, SGTs.Design 802.1X policies, TrustSec / SGACLs, and multi-node architecture.Troubleshoot complex authentication issues, certificate chain failures, posture deviations.Integrate ISE with MDM tools (Intune, Workspace ONE, Jamf).Manage TACACS for network device access policies.Cisco ThousandEyes
Architect and deploy enterprise-level TE Endpoint, Cloud, and Enterprise Agents.Design synthetic tests for SaaS, WAN, VPN, and application monitoring.Perform deep-dive RCA on packet loss, latency, path-changes and BGP route hops.Fortinet — FortiGate / FortiAnalyzer / FortiManager
Architect FortiGate HA, IPSec / SSL VPN, Advanced Routing, SD-WAN.Design firewall policies, NAT, UTM, segmentation.Perform complex troubleshooting : routing loops, HA failovers, performance issues.Build automation scripts via FortiManager APIs.Conduct log forensics and incident analysis using FortiAnalyzer.IT Asset Management
Build asset lifecycle strategies (EOL / EOS planning, firmware governance).Architect CMDB structures for enterprise network assets.Create automation for asset discovery and compliance reporting.LAN & Datacenter Switching (Cisco / Brocade / Nexus)
Architect L2 / L3 networks (HSRP / VRRP, OSPF, BGP, VPC, FabricPath, VXLAN).Design and deploy datacenter solutions (spine-leaf, Nexus 9k / 7k).Perform deep analysis of STP, convergence, load-balancing, multicast.Lead major migrations and network refresh projects.Scripting & Automation
Develop automation using Python, Ansible, REST APIs, Netmiko, NAPALM.Build custom scripts for configuration deployment, compliance checks, and reporting.Create CI / CD pipelines for network automation.DHCP / DNS Architect-Level Responsibilities
Architect scalable and redundant DHCP architectures.Troubleshoot complex relay, failover, and IPAM integration.NIPS
Maintain network intrusion prevention systems.Tune signatures, configure IPS policies, and reduce false positives.Analyze attack patterns, perform RCA, and support SOC teams.Cisco WLC & Wireless
Architect enterprise wireless deployments (RF design, surveys, FlexConnect, HA SSO).Troubleshoot advanced RF issues (co-channel interference, power / channel planning).Integrate wireless with ISE (central / web auth, profiling, posture).Soft Skills & Leadership
Mentor L1 / L2 teams.Handle major incidents and bridge calls.Work with vendors (Cisco / TAC, Fortinet Support) for escalations.Prepare HLD / LLD documents, SOPs, MOPs.Experience
Upto 14 years relevant experience of enterprise network engineering experience.Certifications preferred :
CCNP / CCIE (Enterprise / Security)Fortinet NSE4–NSE7Cisco ENCOR / ENARSICWNP (for wireless roles)'Skills Required
Tcp / ip, Routing Protocols, Network Security, Cisco Ios, Bgp