Principal Network Engineer

Posted Yesterday
Be an Early Applicant
Plymouth, MN, USA
In-Office
150K-185K Annually
Expert/Leader
Healthtech
The Role
Senior individual contributor who designs, operates, and secures the enterprise network across multi-site facilities. Responsibilities include WAN/SD-WAN, data center and cloud connectivity, firewalls and segmentation, physical security networking, monitoring and incident response, automation, standards and audits, and technical leadership and mentorship.
Summary Generated by Built In

HistoSonics is a commercial-stage medtech company advancing the Edison® System, a novel non-invasive sonic beam therapy based on histotripsy. Since receiving FDA De Novo grant for the non-invasive destruction of liver tumors in 2023, the company has progressed beyond initial market entry into commercial expansion, reimbursement momentum, and ongoing clinical and pipeline development. In addition to its current liver tumor indication, HistoSonics is pursuing future indications across multiple applications including kidney, pancreas, prostate, neuro, women’s health, and other significant underserved human health areas, to realize the broader potential histotripsy across multiple disease states and medical specialties.

We offer an exciting work culture where cutting-edge science meets real-world application, and each team member’s contribution is important to our success in ensuring our physicians and their patients get what they need most.

Location: Plymouth, MN

Position Summary (Why this role matters):

The Principal Network Engineer is the senior-most individual contributor within the HistoSonics network engineering function and a member of a larger, multi-site IT team supporting HistoSonics as a whole. This is a hybrid position based out of the Plymouth, MN office. The role owns the design, operation, and reliability of the enterprise network across all sites, spanning office routing, switching, and wireless, site interconnectivity, data center networking, dedicated cloud connectivity, perimeter and segmentation controls, remote access, and physical security network infrastructure. It leads network design and execution for new and expanded facilities and provides the primary technical execution behind network engagement with the AI and R&D Infrastructure team, a partnership owned by the Senior Director, Information Systems and Security. The role is the highest level of technical escalation for network infrastructure and sets technical direction and standards for the function.

Key Responsibilities (What you’ll do):

Network Architecture and Engineering

  • Design, deploy, administer, and maintain the enterprise network across all sites, including routing, switching, wireless, network access control, and IP address management.
  • Own corporate site interconnectivity, including wide area network and SD-WAN topology, carrier and circuit selection, redundancy and failover design, and inter-site capacity planning.
  • Design and administer data center and server room networking, including core and top-of-rack switching, high-availability topologies, and out-of-band management, and maintain dedicated connectivity to cloud platforms, including private interconnects and virtual network routing, in coordination with the System Administration function.

Network Security

  • Own the design, administration, and rule lifecycle of enterprise firewalls, including policy standards, change review, periodic rule base review, and segmentation between corporate, laboratory, manufacturing, guest, and product environments.
  • Design and administer DNS security, web and content filtering, intrusion prevention, and remote access, including site-to-site and client virtual private networking following zero trust principles.
  • Develop forward-looking network security plans and roadmaps supporting the organization’s security maturity objectives, in partnership with Information Security and under the direction of the Senior Director, Information Systems and Security.

Facilities, Data Center, and Physical Security Infrastructure

  • Plan, design, and execute network buildouts for new and expanded facilities, including low-voltage design, wireless surveys and validation, equipment specification, vendor coordination, and cutover planning.
  • Own the network and supporting infrastructure for physical security systems, including access control and video surveillance, partnering with Facilities and Security on design and operational support.
  • Maintain accurate network documentation, including topology diagrams, addressing schemes, circuit and vendor records, and as-built documentation for each facility.

Reliability, Observability, and Operations

  • Define and implement network monitoring, alerting, flow analysis, and performance reporting, and contribute network telemetry and dashboards to centralized reporting.
  • Define service levelobjectives, alert thresholds, and escalation paths for network services supporting mission-critical systems.
  • Serve as a senior technical responder for major network incidents, conduct root cause analysis, drive corrective and preventive actions, and participate in an on-call rotation for after-hours support.

Automation, Governance, and Standards

  • Author and maintain organizational network standards for architecture, addressing, configuration baselines, firmware lifecycle, and change control, and drive adoption across sites.
  • Identify and automate manual network operational processes, including configuration backup, compliance validation, and reporting, using Python, PowerShell, or comparable languages.
  • Serve as control owner for assigned IT controls, provide audit evidence, ensure network configurations and patching adhere to IT policies and applicable regulatory requirements, and support validation of network infrastructure under the HistoSonics Quality Management System.

Technical Leadership and Collaboration

  • Serve as the final internal escalation point for complex network issues and provide technical mentorship and design review to System Administrators and IT Support Specialists.
  • Serve as the primary Information Systems network resource to the AI and R&D Infrastructure team, providing architecture guidance, design review, and escalation support.
  • Represent network infrastructure in architecture reviews, threat modeling, and change control, and advise Security, Data Privacy, Quality, and Regulatory stakeholders.
  • Escalate cross-organizational governance conflicts, scope disputes, and resourcing trade-offs to the Senior Director, Information Systems and Security, and evaluate, recommend, and implement network hardware, circuits, and SaaS solutions to address business needs.

Qualifications and Skills:

Required:

  • Bachelor’s degree in Information Technology, Computer Science, or a related field.  
  • 10+ years in network engineering, including experience above senior level.
  • Intermediate to expert experience with Cisco platforms, including Catalyst and Meraki cloud-managed switching, wireless, and security appliances, with advanced working knowledge of BGP, OSPF, VLANs, spanning tree, and link aggregation.
  • Intermediate to expert experience administering Palo Alto Networks and Meraki firewalls, covering policy design, segmentation, threat prevention, and rule lifecycle management.
  • Demonstrated experience designing networks for larger multi-building or multi-floor campus facilities, including wireless design and validation and structured cabling standards, and with data center design, including high-availability topologies, redundancy, and capacity planning.
  • Demonstrated experience designing corporate location interconnectivity, including wide area network and SD-WAN topologies, carrier and circuit management, failover design, and direct connectivity to cloud environments such as AWS Direct Connect or Azure ExpressRoute.
  • Demonstrated experience operating mission-critical or product production environments, including service level objectives, change control, and incident response.
  • Experience with network monitoring and observability tooling, network authentication and access control, and making changes within an environment compliant with ISO 27001 and SOC 2 standards.

Preferred:

  • Experience in a regulated industry such as medical device, healthcare, or manufacturing.
  • Experience with DNS security platforms, network access control, zero trust network access, and network automation using vendor APIs, Python or PowerShell, Ansible, or Terraform.
  • Relevant industry certifications are a plus.

Key Competencies:

  • Strong problem-solving and troubleshooting skills, with sound judgment when responding to incidents affecting production systems, and a bias toward automation, standardization, and durable documentation.
  • Excellent communication and interpersonal skills, with the ability to explain network decisions, risks, and trade-offs to technical and non-technical audiences, and to prioritize tasks and manage time effectively while working independently and as part of a team.
  • Ability to set technical direction and influence outcomes across teams and departments without direct reporting authority.

Physical Requirements:

  • Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
  • Ability to occasionally lift or move equipment weighing up to 50 pounds, with or without reasonable accommodation.
  • Ability to work in server rooms, data closets, and other equipment areas, including bending, kneeling, reaching, and working from ladders or lifts to install and service equipment.
  • Ability to travel between company facilitiesand toconstruction or buildout sites asrequired.

Benefits: We offer a comprehensive benefits package for full-time employees. This includes health, dental, and vision insurance, life, short-term and long-term disability insurance, 401(k), paid time off, and more.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

U.S. Work Authorization & Sponsorship: Employer will not sponsor visas for position.

#LI-hybrid 

Skills Required

  • Bachelor's degree in Information Technology, Computer Science, or related field
  • 10+ years in network engineering, including experience above senior level
  • Intermediate to expert experience with Cisco platforms including Catalyst and Meraki (switching, wireless, security appliances)
  • Advanced working knowledge of BGP, OSPF, VLANs, spanning-tree, and link aggregation
  • Intermediate to expert experience administering Palo Alto Networks and Meraki firewalls, including policy design and rule lifecycle management
  • Experience designing networks for multi-building or multi-floor campus facilities, wireless design and validation, and structured cabling standards
  • Experience designing data center networking, including core and top-of-rack switching, high-availability topologies, redundancy, and capacity planning
  • Experience designing corporate location interconnectivity including WAN and SD-WAN topologies, carrier/circuit selection and failover design
  • Experience with direct connectivity to cloud environments such as AWS Direct Connect or Azure ExpressRoute
  • Experience operating mission-critical or production environments with SLOs, change control, and incident response
  • Experience with network monitoring, observability tooling, network authentication and access control
  • Experience making network changes compliant with ISO 27001 and SOC 2 standards
  • Experience in a regulated industry (medical device, healthcare, or manufacturing)
  • Experience with DNS security platforms, network access control, zero trust network access
  • Network automation experience using vendor APIs, Python, PowerShell, Ansible, or Terraform
  • Relevant industry certifications
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Plymouth, MN
408 Employees
Year Founded: 2009

What We Do

HistoSonics is a growth phase company developing a non-invasive sonic beam therapy platform and procedure using the science of histotripsy. Histotripsy utilizes the pressure created by focused sound energy to liquefy and destroy targeted tissue, including diseased tissue and tumors, at sub-cellular levels. The company’s new platform delivers personalized, tissue specific treatments with precision and control, and without the undesirable side effects of many of today’s interventional and surgical modalities. HistoSonics is led by a team of experienced domain experts and industry leaders with offices in Ann Arbor, MI, Madison, WI, and Minneapolis, MN.

Similar Jobs

Optum Logo Optum

Network Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Eden Prairie, MN, USA
160000 Employees
113K-193K Annually
Remote or Hybrid
United States
200 Employees
154K-250K Annually

Verizon Logo Verizon

Principal Engineer

Information Technology • Internet of Things • Other • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
11 Locations
107K-205K Annually
In-Office
9 Locations
120K-141K Annually

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account