Senior Network Architect (Security) (Director, Systems & Programming Lvl 3), Enterprise Infrastructure

New York, New York


Employer: NYC Health Hospitals
Industry: ENTERPRISE INFRASTRUCTURE
Salary: Competitive
Job type: Full-Time

Empower Every New Yorker - Without Exception - to Live the Healthiest Life Possible

NYC Health + Hospitals is the largest public health care system in the United States. We provide essential outpatient, inpatient and home-based services to more than one million New Yorkers every year across the city's five boroughs. Our large health system consists of ambulatory centers, acute care centers, post-acute care/long-term care, rehabilitation programs, Home Care, and Correctional Health Services. Our diverse workforce is uniquely focused on empowering New Yorkers, without exception, to live the healthiest life possible.

At NYC Health + Hospitals, our mission is to deliver high quality care health services, without exception. Every employee takes a person-centered approach that exemplifies the ICARE values (Integrity, Compassion, Accountability, Respect, and Excellence) through empathic communication and partnerships between all persons.

Job Description

Under broad guidance and direction from the Unified Communications (UC) Sr. Director/Director/Division Lead of Enterprise Information Technology Services (EITS). This position, Senior Network Architect UC, is responsible for all aspects of architecture, design, implementation, optimization, administration, support and technical documentation of the network Facilities & Datacenters, LANs, WANs, wireless and traditional telecommunications across the enterprise infrastructure. This individual will provide advanced level architecture, design, implementation, and support with particular focus on modern datacenter network virtualization, convergence, and security to end users and IT operational personnel.

Duties & Responsibilities

  • Experience architecting, designing, implementing, and support of network infrastructure across LANs, WANs, wireless, and traditional telecommunication networks.
  • Demonstrated success improving an enterprise's security posture with networking technologies.
  • Design, implement and manage security and networking architecture.
  • Hands on experience in architecture/design, implementation & support of data/VoIP networks.
  • Demonstrated experience in producing network designs from functional requirements, maintaining network topology information, and network standards documents.
  • Experience with Software-defined Datacenter (SDDC) technologies including Software-defined Networking (SDN), SD-Access and Software-defined Wide Area Networks (SD-WAN).
  • Extensive experience with VXLAN and ACI.
  • The candidate should have mastery-level skills and experience in high-end network equipment (i.e., Cisco, Arista, Riverbed, Bluecoat, F5, Citrix), LAN/WAN protocols, network applications such as DNS, DHCP, and in-depth knowledge of network security policy and configuration.
  • Experience providing high-level direction during the troubleshooting of complex service outages.
  • Manages all contracted WAN providers and their services and is accountable for ensuring delivery from the vendors of WAN service as per defined SLA's.
  • Provides leadership and direction for technology core personnel in dealing with a variety of organizational and programmatic issues.
  • Collaborates with the Network Service Owner in aligning goals, objectives, and work plans for the delivery of timely and quality technology services.
  • Oversees administration of network Infrastructure and the resources on which it relies, including vendors, dependent services\organizations, enterprise engineering.

Communicates and consults with technology personnel and advisory groups to administer network infrastructure.
  • Builds trust and develops effective working relationships between Core technology team and constituencies ensuring the office's programs and standards are implemented in a manner consistent with the goals and objectives of the organization.
  • Maintains 24 hours/seven days a week on-call status for critical core systems
  • Responsible to provide Tier-3 support for production issues.
  • Operates and maintains networks, tracks significant problems, monitors performance, and performs upgrades to hardware and software as required
  • Trains technical staff at the system and building level to follow proper operating procedures necessary to maintain the integrity of the network
  • Defines and Maintains documentation regarding network configurations, operating procedures, and service records relating to network hardware and software
  • Maintains certification in network technology such as Cisco, Juniper or other relevant technology, and/or experience which provides the required knowledge, skills, and abilities
  • Performs other duties and responsibilities as assigned by supervisor
  • Has strong understanding of cabling standards, IP address management, VPN, Firewalls, network security, wireless and network management platforms
  • Provide high level network design and implementation skills and combine technical intelligence with communication and presentation abilities.
  • Individual contributor capable of self-directed work showing strong leadership and client relationship skills and who is focused on driving the complete network project


Required Technical Skills
  • Cisco ISR/ASR routers. Cisco Catalyst 2k,3k, 4k,6500,9K Nexus 2000, 5500, 6000, 7000, 9000, ASR 1K,9K class switches
  • Cisco 1200, 2600, 2700, 3700, 3800 series Wireless Access Points and Cisco 5500, 5700, 8500 Wireless LAN Controllers
  • TCP/IP, SSL, LACP, LLDP/CDP, EIGRP, OSPF, BGP, MPLS, HSRP, GLBP, SNMP, STP, VPC, VSS, VDC, MSDP, PIM, IGMP, RTP, SIP, H.323, LWAPP, RADIUS, TACACS+, Fiber Channel, FCoE, iSCSI, 802.11abg, 802.11n, 802.11ac
  • Strong experience in Network Security IPSec VPN, AAA Architecture, DNS, TCP/IP, VPN, SMTP, Firewalls, Infoblox, IPAM, Cisco WiFi, Prime, Cisco ACS, Cisco VOIP basic, Cisco VPN Gateways
  • F5 Application Delivery Controllers
  • ASA, Firepower and Palo Alto Firewalls
  • Intrusion Detection Systems
  • VXLAN, ACI, SD-ACCESS, NSX technologies
  • Web Application Firewalls
  • Strong knowledge of LAN/WAN infrastructures, topologies and protocols
  • Strong understanding of network protocols and applications, such as DNS, DHCP, SMTP, HTTP/HTTPS, Multicast, SNMP, NetFlow
  • Strong experience and concept in modern datacenter architecture and Software Defined Network SDN)
  • Strong in troubleshooting different OSI layer issues and performance analysis by using sniffer tools
  • Broad knowledge of current IT infrastructure trends and different cloud services
  • Protocols, Technology, features like BGP, OSPF, IS-IS, EIGRP, RIP, loop avoidance, Multicast PIM - DM, SM, SSM, IGRP v1, v2, v3 etc., Protocol Security, Ethernet, STP, RSTP, MSTP, VTP etc., features/techniques like VPC, VDC, FEX, ISSU, VSS, OTV, LISP, Fabric Path, QFabric Features, Fast Convergence, MPLS VPNs, VXLAN etc.
  • Software - IOS, IOS-XR, IOS-XE, CatOS, JunOS, FortiOS
  • Implementation of 1Gb, 10Gb,25Gb,40Gb and 100Gb Ethernet
  • Firewalls/IPS, load balancers, WAN optimization
  • Data Center facilities: power/cooling/cabling
  • Familiarity with the following in a DC Network Environment to enable an end-to-end design & inter-working with teams


Minimum Qualifications
1. Baccalaureate degree from an accredited college or university in Computer Science, Mathematics, Business Administration, Statistics or a related discipline, and five (5) years of experience in systems analysis and design of information systems, two (2) years of which must have been in a managerial or supervisory capacity; or
2. A satisfactorily equivalent combination of certificates, education and/or experience, in which thirty (30) graduate-level semester credits from an accredited college or university can be substituted for one (1) year of experience, and each month spent completing relevant certificates can be credited for one (1) month of experience. However, all applicants must have at least a Bachelor's Degree.

Department Preferences

Certification(S)/NYS Licenses:
  • Cisco Certified Internetwork Expert (CCIE) -Routing and switching, Datacenter, Enterprise Infrastructure


Knowledge, Skills, Abilities and other Requirements:
  • "Required Technical Skills",
  • In-depth and up-to-date knowledge of System architecture, design, implementation, and support with particular focus on modern datacenter network virtualization, convergence, and security.
  • Excellent analytical, problem-solving, communication, documentation, and interpersonal skills
  • Ability to work well with others, independently with minimal supervision and in a timely fashion.
  • Highly self-motivated and team oriented.
  • Accuracy, attention to detail, confidential, strong customer-service orientation.


Years of Experience:
  • 10 years of network architecture and design


If applying online, please include your cover letter in the same file attachment with your uploaded resume.

NYC Health and Hospitals offers a competitive benefits package that includes:
  • Comprehensive Health Benefits for employees hired to work 20+ hrs. per week
  • Retirement Savings and Pension Plans
  • Loan Forgiveness Programs for eligible employees
  • Paid Holidays and Vacation in accordance with employees' Collectively bargained contracts
  • College tuition discounts and professional development opportunities
  • Multiple employee discounts programs

Note: Candidates selected for a position are required to come to NYC as part of their onboarding.

Created: 2024-05-17
Reference: 103985
Country: United States
State: New York
City: New York
ZIP: 10036


Similar jobs: