- Salary
- $120k – $150k/yr
- Location
- Tinley Park, IL
- Workplace
- Hybrid
- Department
- Engineering
- Experience
- 8+ years
- Education
- Bachelor
- Source
- Paylocity
Description
Description
The Project Engineer III - (Networking Specialization) is a senior, hands-on engineer who assesses, designs, and delivers secure, reliable networks for small and mid-sized customers and larger organizations with internal IT teams. The primary stack is Meraki/Cisco, Ruckus, and HP; migrations and upgrades span multiple vendors. The role combines networking depth with solid on-premises, Microsoft cloud, and hybrid-infrastructure knowledge, using designs appropriate to each customer's scale, risk, and support capabilities.
The engineer performs existing-customer pre-sales assessments and solution architecture and owns technical execution within approved Statements of Work (SOWs) and project plans. Working with Project Managers, Sales, account teams, engineering leadership, support/security teams, vendors, and customer IT staff, the engineer develops shared standards and reusable solutions. Project Managers retain responsibility for schedule, budget, resources, change control, status reporting, and acceptance.
SPECIFIC RESPONSIBILITIES: Other duties may be assigned to meet business needs.
• Existing-customer assessments and pre-sales architecture: Assess environments, identify risks and capacity needs, and develop practical designs. Collaborate with Sales, account teams, and engineering leadership on recommendations, diagrams, bills of materials, SOWs, estimates, dependencies, and technical tradeoffs. Explain and validate design decisions with customer IT staff where present.
• Project planning, delivery, and coordination: Own technical workstreams from readiness through completion. Define prerequisites, sequencing, maintenance windows, migration phases, and rollback plans; execute approved scope; maintain accurate tasks, time entries, and status; and promptly escalate scope, schedule, budget, quality, or customer-impact concerns.
• Routing, switching, and modernization: Implement single-site and multi-site networks, IP addressing, VLANs, inter-VLAN routing, spanning-tree, trunks, link aggregation, port security, and QoS. Lead cross-vendor migrations, network rebuilds, equipment replacements, and configuration/firmware upgrades. Verify feature compatibility and translate configurations to the approved design rather than copying legacy settings unchanged.
• WAN, SD-WAN, and hybrid connectivity: Design internet, site-to-site VPN, SD-WAN, and cloud connectivity with appropriate redundancy, failover, and recovery. Configure static or dynamic routing as justified by the environment. Coordinate circuits and cutovers with carriers; validate application performance and failure/recovery behavior across locations.
• Network security and access: Implement firewall rules, ACLs, NAT, secure VPN access, IDS/IPS, segmentation, and protected administration. Validate both permitted and blocked traffic, identity-based access, and logging. Work with security teams to meet customer policies and applicable security and compliance requirements.
• Wireless assessments and optimization: Perform RF/site surveys and capacity assessments; design access-point placement, channels, power, roaming, guest access, and authentication. Validate coverage, interference, client behavior, and application performance using measured evidence, not dashboard status alone.
• On-premises and cloud integration: Integrate networking with Windows Server, Active Directory, DNS/DHCP, RADIUS, virtualization, storage, backup/recovery, and Microsoft 365/Azure services. Identify cross-platform dependencies and coordinate with other engineers to deliver supportable end-to-end solutions.
• Network deployment and lifecycle automation: Use scripts, vendor APIs, templates, and version control for repeatable provisioning, configuration backups, inventory, drift checks, firmware updates, and validation. Test automation before wider deployment, protect credentials, log results, and provide safe failure handling and rollback.
• Testing, cutover, and quality assurance: Obtain technical peer review of designs and material changes before production. Execute documented pre/post-change tests for connectivity, segmentation, VPNs, wireless, QoS, monitoring, and failover/recovery. Record results, resolve material findings, and provide evidence suitable for customer IT review before requesting acceptance.
• Documentation and operational handoff: Maintain accurate physical/logical diagrams, IP/VLAN and port plans, firewall/VPN records, configuration backups, test evidence, change records, and support procedures. Review as-built documentation with internal support and customer IT teams; clarify ownership, known limitations, and recovery procedures.
• Technical standards and solution development: Develop approved reference designs, security baselines, deployment checklists, and reusable solutions across customers and internally. Work with engineering leadership and support teams to review and maintain standards, document justified exceptions, and use lessons learned to reduce recurring mistakes.
• Technical leadership, escalation, and mentoring: Explain designs and findings clearly, mentor Project Engineers I and II, and troubleshoot difficult multi-vendor issues using logs, packet captures, and configuration evidence. Recognize limits and engage vendor or specialist support promptly. Participate in assigned on-call coverage for critical network incidents
networks for small and mid-sized customers and larger organizations with internal IT teams. The primary stack is Meraki/Cisco, Ruckus, and HP; migrations and upgrades span multiple vendors. The role combines networking depth with solid on-premises, Microsoft cloud, and hybrid-infrastructure knowledge, using designs appropriate to each customer's scale, risk, and support capabilities.
Requirements
REQUIRED QUALIFICATIONS:
• Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent relevant experience.
• Minimum 8 years of progressive IT experience, including 5+ years of hands-on network engineering and project delivery. Experience with small/mid-sized businesses and larger customers with internal IT teams is strongly preferred.
• Strong applied knowledge of TCP/IP, subnetting, IPv4/IPv6, VLANs, trunks, spanning-tree, link aggregation, inter-VLAN routing, DHCP/DNS, NAT, ACLs, QoS, and resilient site connectivity. Use static routing and OSPF where appropriate; assess BGP or other advanced routing requirements and obtain specialist assistance when needed.
• Strong hands-on Meraki/Cisco capability and practical Ruckus and HP experience, using dashboards and command-line interfaces. Assess, migrate, upgrade, and troubleshoot mixed-vendor environments with attention to platform-specific behavior.
• Practical firewall, secure remote-access/site-to-site VPN, segmentation, IDS/IPS, identity-based access, SD-WAN, and failover skills. Understand how network security, availability, and configuration choices affect real customer applications.
• Wireless RF, survey, capacity, and troubleshooting skills. Use Meraki Dashboard, relevant Ruckus/HP management tools, network monitoring, packet captures, logs, and diagramming tools to isolate causes and verify outcomes; experience with Auvik and Ekahau or comparable tools is preferred.
• Practical automation using Python, PowerShell, or Bash, vendor APIs, reusable templates, and Git; use Ansible or Terraform when appropriate to the task. Test changes, protect secrets, record results, and troubleshoot automation failures.
• Solid on-premises and hybrid infrastructure knowledge, including Windows Server, Active Directory, DNS/DHCP, RADIUS, virtualization, storage, and backup/recovery, with practical understanding of Microsoft 365, Azure, and cloud networking dependencies.
• Ability to own existing-customer assessments, pre-sales designs, SOWs, and delivery. Produce migration/rollback plans and clear documentation; explain tradeoffs to customer IT staff and business stakeholders. Provide mentoring and improve shared standards.
• Demonstrated quality discipline: identify design/configuration errors, obtain peer review, validate failover and security boundaries, and retain evidence suitable for customer IT review.
• Ability to travel for assessments and implementations, typically locally within the Chicago metropolitan area; work planned after-hours windows and participate in assigned on-call coverage for critical network incidents.
CERTIFICATION EXPECTATIONS:
Certification requirement: Hold CCNA or a manager-approved current networking equivalent at hire. A current CCNP Enterprise satisfies this requirement; maintaining both CCNA and CCNP is not required. Not every listed credential is required.
Primary
• Cisco Certified Network Professional (CCNP Enterprise) - preferred advanced networking credential for design, implementation, troubleshooting, and technical leadership. Not required at hire or within the initial 180-day development period.
• Cisco Meraki Solutions Specialist (500-220 ECMS) - strongly preferred for Meraki design, deployment, and troubleshooting.
Core
• Cisco Certified Network Associate (CCNA, 200-301) - core networking certification baseline, subject to the requirement and approved equivalencies above.
• Microsoft Certified: Azure Network Engineer Associate (AZ-700) - for assigned Azure networking and hybrid-connectivity responsibilities.
Secondary
• RUCKUS product accreditations and training - match deployed platforms: RUCKUS Accredited SmartZone (RASZ), RUCKUS Accredited RUCKUS One (RAR1), or RUCKUS Accredited ICX (RAICX). Use product-specific training for other Ruckus solutions.
• HPE Aruba Networking Certified Associate - Switching - for AOS-CX environments. Use platform-matched training and hands-on validation for other installed HP product families.
• Certified Wireless Network Administrator (CWNA) - preferred vendor-neutral RF, survey, WLAN security, and troubleshooting development.
Service-management development
• ITIL Foundation (current version) - preferred for change, incident, problem, and service-management practices.
Senior-level practical capability is required at hire regardless of certification status, including multi-vendor design, troubleshooting, secure configuration, validation, documentation, and the ability to explain and defend technical decisions to customer IT staff. Match training to installed platforms and update targets as vendor programs change.
PHYSICAL DEMANDS:
Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions. The employee uses computer and telephone equipment, handles tools and equipment, reaches, and may stand, walk, or crouch during onsite work. The role requires lifting up to 50 pounds regularly and sitting for extended periods during design and planning activities.