Network DevOps Engineer (SD-WAN)
Job Title: SD-WAN DevOps Engineer
Location: Plano, TX (Local candidates only)
Type: Contract
Role Overview
The SD-WAN DevOps Engineer will lead the architecture, deployment, and operational lifecycle of SD-WAN solutions within a large-scale, hybrid BFSI enterprise environment. This role requires advanced expertise in routing, cloud integration, security, and automation, with a strong focus on resiliency, compliance, and application performance.
Primary Responsibilities
-
Design, implement, and optimize SD-WAN solutions using Cisco Viptela, Fortinet Secure SD-WAN, VMware VeloCloud, and Silver Peak EdgeConnect.
-
Lead routing architecture across underlay and overlay networks using BGP, OSPF, and EIGRP.
-
Develop and manage application-aware routing strategies including SLA-based path steering and DSCP-based prioritization.
-
Implement WAN optimization techniques such as deduplication, compression, TCP optimization, and FEC.
-
Drive orchestration and provisioning initiatives including ZTP, templates, and multi-tenant segmentation.
-
Integrate SD-WAN environments with AWS, Azure, and Google Cloud Platform through cloud on-ramps, ExpressRoute, Transit Gateway, and cloud-native firewalls.
-
Implement overlay security measures including IPSec, IKEv2, cert-based authentication, and role-based access control.
-
Architect high-availability SD-WAN solutions involving active-active/standby, dual CPE, and resilient transport paths.
-
Develop and maintain QoS frameworks, shaping, policing, and per-application SLAs.
-
Support multicast and VoIP traffic engineering, including MOS-based routing optimization.
Secondary Responsibilities
-
Support diverse transport models including MPLS, broadband, LTE/5G, and satellite with path modeling.
-
Utilize SolarWinds, NetFlow, SNMP, and SD-WAN analytics for monitoring and performance visibility.
-
Collaborate with firewall teams (Fortinet/Palo Alto) for NGFW integration, VPN design, and ZTNA alignment.
-
Create automation workflows using Python, Ansible, and REST APIs.
-
Implement VRF-based segmentation, policy enforcement, and microsegmentation.
-
Manage centralized DNS/DHCP, split-horizon DNS, and resolver forwarding.
-
Integrate logging with SIEM tools (Splunk, QRadar) for event monitoring.
-
Support cloud-native networking constructs such as Transit Gateway Connect, Azure VWAN, and Google Cloud Platform Cloud Router.
-
Configure policy-based forwarding and real-time overlay/underlay correlation for path remediation.
Required Experience
-
8 12 years of network engineering experience with a minimum of 3 years hands-on SD-WAN design and operations.
-
Proven ability to scale SD-WAN in multi-branch BFSI environments.
-
Expertise in documentation including HLD/LLD, runbooks, change plans, and as-built diagrams.
-
Experience in regulated industries (BFSI, healthcare, telecom) with strong compliance orientation.
-
Demonstrated leadership working with cross-functional teams across cloud, security, and infrastructure.
Preferred Qualifications
-
Knowledge of SASE/SSE including ZTNA, SWG, and CASB integrations.
-
Experience with hybrid network service chaining and cloud-native networking.
-
Familiarity with ITIL v4 processes.
-
Exposure to DevNet, NetDevOps methodologies, and CI/CD for network automation.
-
Awareness of compliance standards: ISO 27001, NIST 800-53, RBI, PCI-DSS.