- Location
- WP (Rotterdam - Wilgenplas), Netherlands · HBP (Amsterdam - Haarlerbergpark)
- Workplace
- Remote, Hybrid
- Type
- Full-time
- Department
- IT
- Seniority
- Senior
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
As a Senior Network Designer, you are responsible for designing secure, resilient, and scalable network, security, and application delivery solutions across ING's hybrid infrastructure. You act as a design authority for F5 BIG-IP LTM and GTM/DNS services, AS3-based onboarding models, Palo Alto security solutions, router ACLs, network segmentation, routing, VPN services, leased-line connectivity, and certificate management.
You contribute to cloud migrations, Lifecycle Management (LCM) projects, F5 certificate automation, platform modernization, and the delivery of new network and application delivery capabilities. You translate business and technical requirements into target-state architectures, High-Level Designs, Low-Level Designs, reusable service patterns, and secure connectivity solutions.
You work effectively with engineers, architects, service consumers, security specialists, and management. You combine clear communication with strong conceptual thinking and a structured approach to solution design. You are thorough, detail-oriented, and committed to producing accurate, maintainable, and high-quality architecture documentation.
We are looking for you if you have:
Extensive experience designing enterprise network, security, and application delivery solutions.
Strong knowledge of F5 BIG-IP LTM and GTM/DNS technologies and application delivery architectures.
Experience designing F5 services, including virtual servers, pools, health monitors, traffic steering, persistence, SSL/TLS, and high-availability solutions.
Experience with F5 AS3 and declarative application onboarding models.
Knowledge of certificate management, PKI integration, and SSL/TLS certificate lifecycle requirements.
Experience designing Palo Alto firewall rulebases, security policies, NAT configurations, security zones, and traffic flows.
Experience designing routing solutions, router ACL changes, network segmentation, VPN connectivity, and leased-line services.
Strong knowledge of DNS, Infoblox DDI/IPAM, traffic management, resilience, and disaster recovery principles.
Experience working in complex hybrid infrastructure environments.
The ability to translate business, security, and technical requirements into scalable and supportable designs.
A strong focus on security, availability, resilience, and operational stability.
The ability to work in accordance with ING standards, architecture principles, controls, and governance processes.
Clear communication skills and experience working in an Agile environment.
You'll get extra points for:
Experience contributing to F5 certificate automation and automated certificate lifecycle management.
Experience designing integrations between F5 platforms, enterprise PKI services, certificate management tooling, and automation platforms.
Experience defining reusable AS3 templates and standardized application onboarding models.
Experience supporting cloud migration programmes.
Experience contributing to Lifecycle Management (LCM) and technology refresh projects.
Experience designing Global Server Load Balancing, high-availability, and disaster recovery solutions.
Experience developing reusable service patterns, design standards, and reference architectures.
Your responsibilities:
Design secure, resilient, and scalable network, security, DNS, connectivity, and application delivery solutions across ING's hybrid infrastructure.
Act as design authority for F5 BIG-IP LTM and GTM/DNS platforms and related application delivery services.
Produce and maintain High-Level Designs, Low-Level Designs, reference architectures, service blueprints, and reusable design patterns.
Design F5 LTM services, including virtual servers, pools, pool members, health monitors, SSL/TLS profiles, traffic steering, load-balancing methods, persistence mechanisms, and Source NAT.
Design F5 GTM/DNS solutions, including Global Server Load Balancing, wide IPs, pools, health monitoring, geographic traffic distribution, failover, and disaster recovery architectures.
Define AS3-based onboarding models, reusable declarations, and standardized service templates for automated application delivery.
Contribute to F5 certificate automation by defining design requirements, onboarding standards, integration patterns, and certificate lifecycle processes.
Design scalable approaches for certificate issuance, deployment, renewal, replacement, revocation, and retirement on F5 application delivery platforms.
Define integration requirements between F5 platforms, AS3 services, enterprise PKI, certificate management services, and automation tooling.
Ensure certificate automation designs support secure key handling, certificate traceability, expiry monitoring, controlled renewal, and operational resilience.
Design Palo Alto firewall solutions, including security rulebases, security policies, NAT configurations, security zones, segmentation, and application traffic flows.
Review application connectivity requirements and translate them into appropriate Palo Alto rulebase and NAT design changes.
Design router ACL changes supporting network segmentation, controlled connectivity, infrastructure protection, and application onboarding.
Define end-to-end traffic flows incorporating firewall policies, router ACLs, routing controls, DNS services, load balancing, and security boundaries.
Design site-to-site VPN solutions, leased-line connectivity, partner integrations, inter-datacenter communication, and hybrid infrastructure connectivity.
Define routing changes, route filtering requirements, failover behaviour, network paths, and connectivity models for new business and infrastructure services.
Assess the impact of firewall rulebase, NAT, router ACL, routing, VPN, DNS, and application delivery changes on security, availability, and resilience.
Translate business and technical requirements into approved network, security, DNS, certificate management, and application delivery designs.
Support IPC migrations, internal cloud migrations, infrastructure transformations, and application onboarding through solution design and architecture governance.
Contribute to Lifecycle Management projects by assessing design impacts and defining target-state solutions for platform upgrades and technology refreshes.
Review proposed solutions and ensure alignment with ING security standards, resilience requirements, risk controls, and architecture principles.
Maintain architecture repositories, design documentation, service standards, decision records, and audit-compliant evidence.
Ensure traceability between design deliverables, Azure DevOps epics and user stories, architecture decisions, and ServiceNow change records.
Provide architectural guidance during major incident reviews, root cause analysis, and structural service improvement activities.
Support Disaster Recovery (DR) testing activities through architecture validation, design reviews, failover scenario assessments, and periodic Standby Duty participation to ensure resilience and recoverability objectives are met.
Provide architectural guidance during major incidents, troubleshooting activities, and service degradation scenarios to support rapid issue identification and resolution.
Contribute to root cause analysis by evaluating network, security, connectivity, and application delivery designs, identifying structural improvements to enhance platform resilience, availability, and operational stability.
Your education and background:
A bachelor's degree or equivalent professional and intellectual ability in Information Technology.
Extensive experience in network architecture, network security, connectivity, and application delivery design.
Strong knowledge of F5 BIG-IP LTM, F5 GTM/DNS, AS3, SSL/TLS, and application delivery technologies.
Knowledge of PKI, digital certificates, certificate lifecycle management, and certificate automation principles.
Strong knowledge of Palo Alto Networks, Panorama, rulebase design, NAT, and security zoning.
Experience with routing and switching, router ACLs, VPN technologies, leased-line connectivity, and network segmentation.
Experience with DNS, Infoblox DDI/IPAM, high availability, and disaster recovery design.
Experience working within Agile delivery organisations and architecture governance processes.
Excellent command of spoken and written English.
Technical Environment
F5 BIG-IP LTM, F5 BIG-IP GTM/DNS, F5 AS3, GSLB, Virtual Servers, Pools, Health Monitors, SSL/TLS Profiles, Traffic Management, Load Balancing, Persistence, iRules, PKI Integration, Digital Certificates, Certificate Lifecycle Management, F5 Certificate Automation, Palo Alto Networks, Panorama, Palo Alto Security Policies, Rulebase Design, NAT Design, Security Zoning, Router ACL Design, Routing and Switching, Network Segmentation, Site-to-Site VPN, Leased-Line Connectivity, Infoblox DDI/IPAM, DNS, Hybrid Infrastructure Connectivity, Azure DevOps, ServiceNow, Infrastructure as Code, High Availability, Disaster Recovery, and Enterprise Network Security Architecture.
Stand-by shifts
Business critical systems, such as client processes, payment processes, software applications and websites, require a 24/7 accessibility and availability of several (groups) of employees to act quickly during unforeseen circumstances, such as calamities or incidents. For these (groups) of employees ING have set up a Stand-by regulation. To compensate for the inconvenience of being available currently, a Stand-by compensation is awarded. If you are designated by your lead for stand-by shifts to be available for incidents outside of your regular working hours, a Stand-by compensation is awarded.
Rewards and benefits
We want to make sure that it’s possible for you to strike the right balance between your career and your private life. Find out more about our employment conditions.
The benefits of working with us at ING include:
25-28 vacation days depending on contract
Pension scheme
13th month salary
8% Holiday payment
Hybrid working
Personal growth and challenging work with endless possibilities
An informal working environment with innovative colleagues
About us
Curious about how ING empowers people and businesses to move forward?
Discover what we do and what we can offer you.
Questions?
Please visit our Frequently Asked Questions section to find some answers on questions you might have.
Contact the recruiter attached to the advertisement. Want to apply directly? Please upload your CV and motivation letter by clicking the ‘Apply’ button.