Job Role: Network - SD WAN
Position: Contract
Location : Plano TX-5 Days onsite
Role Overview
We are looking for a highly experienced SD-WAN Engineer to lead the design, deployment, and lifecycle management of software-defined WAN (SD-WAN) solutions across a BFSI-grade hybrid enterprise. The role demands deep technical expertise in routing, traffic engineering, cloud integration, and zero-touch provisioning, with a strong focus on resiliency, security, and application performance.
Primary Technical Skills
? SD-WAN Platforms: Hands-on experience with Cisco Viptela, Fortinet Secure SD-WAN, VMware VeloCloud, and Silver Peak Unity EdgeConnect.
? Routing Protocols: Advanced configuration and troubleshooting of BGP, OSPF, EIGRP, and route redistribution across underlay and overlay networks.
? Application-Aware Routing: Implementation of dynamic path selection, DSCP-based prioritization, and real-time traffic steering based on SLA metrics.
? WAN Optimization: Deep understanding of deduplication, compression, TCP optimization, and forward error correction (FEC).
? SD-WAN Orchestration: Proficient in zero-touch provisioning (ZTP), template-based policy deployment, and multi-tenant segmentation.
? Cloud Integration: Design and deployment of direct cloud on-ramp to AWS, Azure, and GCP, including ExpressRoute, Transit Gateway, and cloud-native firewalls.
? Overlay Security: Implementation of IPSec tunnels, IKEv2, certificate-based authentication, and role-based access control (RBAC).
? High Availability & Failover: Design of active-active/active-standby topologies, dual CPE, and path resiliency mechanisms.
? QoS & Traffic Engineering: End-to-end QoS policy design, shaping, policing, and per-app SLA enforcement.
? Multicast & Voice Optimization: Support for multicast over SD-WAN, VoIP prioritization, and MOS-based routing decisions.
Secondary Technical Skills
? Transport Diversity: Integration of MPLS, broadband, 5G/LTE, and satellite links into SD-WAN fabric with path cost modeling.
? Monitoring & Telemetry: Use of SolarWinds, NetFlow, SNMP traps, and SD-WAN analytics dashboards for proactive monitoring and SLA validation.
? Firewall & VPN Integration: Policy coordination with NGFWs (e.g., Fortinet, Palo Alto), site-to-site VPNs, and ZTNA gateways.
? Automation & Scripting: Development of Python, Ansible, or REST API scripts for bulk provisioning, compliance checks, and config drift detection.
? Network Segmentation: Design of VRF-based segmentation, zone-based policies, and microsegmentation across branches and data centers.
? DNS & DHCP Integration: Centralized DHCP relay, DNS forwarding, and split-horizon DNS for hybrid environments.
? Syslog & SIEM Integration: Forwarding of SD-WAN logs to SIEM platforms (e.g., Splunk, QRadar) for event correlation and compliance auditing.
? Cloud-Native Networking: Exposure to Transit Gateway Connect, Azure Virtual WAN, and GCP Cloud Router.
? Policy-Based Forwarding (PBF): Use of match-action rules to steer traffic based on application, source, or destination.
? Overlay-Underlay Correlation: Mapping of overlay tunnels to underlay health, with real-time path remediation.