RESPONSIBILITIES :
Kforce has a client that is seeking an L4 Network Architect in Plano, TX. Summary : Our client is hiring for an L4 Network Architect / Engineer to lead design and delivery of multi-site Cisco Software Defined Access (SD Access) solutions at scale. In this role, you will contribute to and implement architecture direction, drive complex deployments across distributed campuses, and mentor engineers while partnering closely with security and operations.
Key Responsibilities :
- Own end to end SD Access architecture for large, multi-site enterprises : fabric design (control / edge / border), transit options, segmentation (SGTs / TrustSec), identity policy, and integration with WAN and data center
- Lead Catalyst Center-driven automation : design templates, SDA workflows, network assurance, SWIM, and closed loop operations aligned to reliability / SLOs
- Design identity centric security with ISE : policy sets, authorization profiles, posture, PxGrid integrations, wired / wireless 802.1X / MAB, guest / BYOD, and scalable group policies
- Engineer secure edge and campus perimeters : Cisco FTD / Firepower policy design, NAT, VPN, IDS / IPS, SSL decryption strategy, and high availability
- Architect SD WAN underlay / overlay : transport independence, application aware routing, DIA / Cloud on ramp, security integration, and multi region scale
- Expert routing at scale : BGP (policy, route reflectors, communities), OSPF, EIGRP, ECMP, redistribution strategies, route filtering, summarization, and IPv6 planning
- Drive modernization roadmaps : brownfield to SDA migration, hierarchical campus design, QoS, multicast, wireless controller (Catalyst 9800) alignment, and resiliency patterns
REQUIREMENTS :
Active CCIE (any track; Enterprise Infrastructure and / or Security strongly preferred)10+ years enterprise networking experience, including 3-5+ years leading SD Access architecture and deployment across multiple sitesRequired experience : Telco / Carrier experience; MPLS (L2VPN / L3VPN / MPLS Lite / Tagging); DWDM; IP WAN and Routing (BGP / iBGP / eBGP / AS Networks); Cloud (AWS or Azure) networking expertise is a strong plusProven, exceptional hands-on skills with Cisco routing / switching and Catalyst Center (formerly Cisco DNA Center) for SDA automation and assuranceDeep expertise with Cisco ISE (policy, 802.1X, SGT / TrustSec) and Cisco FTD (Firepower) firewalls (threat, access control, NAT / VPN, high availability)Strong experience with Cisco SD WAN (design, policy / templating, security integration, operationalization)Expert level knowledge of BGP, EIGRP, OSPF, redistribution, and route policy design for large enterprisesDemonstrated success leading complex, multi-phase migrations and mentoring senior engineersPreferred Qualifications :
CCDE or dual CCIE; Cisco Certified Specialist certifications in SDA, ISE, or SD WANAutomation fluency (Ansible, Python, Terraform), Git based workflows, and API integration with Catalyst Center / ISE / FTD / SD WANWireless (Catalyst 9800 / Prime / Catalyst Center Assurance), QoS strategy, multicast, NAC posture, and Zero Trust segmentationCloud networking (Azure / AWS), hybrid connectivity, and DNS / DHCP / IPAM integrationFamiliarity with data center and campus interconnect (e.g., ACI concepts beneficial but not required)