Position Responsibilities:
- Manage and maintain enterprise network infrastructure, including switches, routers, and firewalls.
- Manage and maintain enterprise network infrastructure, including switches, routers, and firewalls, to support secure and compliant operations.
- Configure and optimize routing protocols to ensure efficient, reliable, and secure network performance.
- Implement and manage secure networking solutions, including SD-WAN, IPsec tunnels, and segmentation, aligned with compliance requirements.
- Ensure adherence to industry standards, compliance frameworks (CMMC, NIST 800- 171, SOC 2), and best practices in network security and design.
- Take ownership of network-related issues, troubleshoot problems, and provide timely resolution, applying a proactive approach to prevent recurrence.
- Familiarize yourself with the existing network environment and infrastructure, identifying areas for improvement to meet evolving compliance standards.
- Create, update, and maintain documentation for network systems, processes, and procedures, ensuring compliance evidence is clear and auditable.
- Collaborate with other IT team members to optimize network performance, security, and compliance.
- Proactively stay updated with industry trends, technologies, and compliance requirements to continually improve and future-proof our network infrastructure.
Required Skills & Experience:
- 7+ years of enterprise networking experience, including at least 3 years at a senior or lead level in a multi-site environment.
- Expert-level routing and switching, with a focus on secure and compliant network design across distributed sites.
- Proficiency in SD-WAN and IPsec tunnel configuration, and demonstrated experience implementing network segmentation aligned to compliance requirements.
- Strong understanding of compliance frameworks (CMMC, NIST 800-171, SOC 2) and industry standards in network security.
- Hands-on experience with Cisco Meraki (MX, MS, MR) in a multi-site dashboard environment.
- Hands-on experience with Fortinet FortiGate firewalls and FortiOS, including policy design, security profiles, IPsec and SD-WAN configuration, HA, and firmware lifecycle. Experience with FortiManager, FortiAnalyzer, or other Fortinet Security Fabric components is an advantage.
- Demonstrated ability to operate a multi-vendor firewall estate and to plan and execute migrations between NGFW platforms with minimal disruption. Knowledge of additional platforms (Palo Alto, Cisco Firepower, SonicWall, Aruba, Juniper) is a plus.
- Experience with data center and virtualization networking, including VMware host networking and iSCSI or storage area network connectivity.
- Enterprise wireless design and troubleshooting experience, including surveys, RF optimization, and secure authentication.
- Working knowledge of PKI and certificate management as it applies to VPN, 802.1X, and device trust.
- Proficiency with network monitoring, logging, and analysis tools, including packet capture and structured troubleshooting methodology.
- Proven ability to implement and manage security controls autonomously, with minimal handholding, in an environment where standards may need to be created rather than inherited.
- Strong organizational and documentation skills, with the ability to produce detailed documentation that serves as compliance evidence.
- Fluency in English, written and spoken, with excellent communication skills and the ability to explain technical risk to non-technical stakeholders.
- Problem-solving mindset with the ability to adapt to a dynamic IT environment and proactively address emerging compliance challenges.
- Willingness to travel occasionally to domestic and international JMA sites, and to work on-site in Syracuse, NY.
Desired Skills & Experience:
- Relevant certifications such as Fortinet NSE 4 or above (or the current FCP and FCSS equivalents), CCNP Enterprise, CCIE, Meraki CMNA or ECMS, PCNSE, CISSP, or CMMC-related certifications (RP, CCP, CCA).
- Experience supporting manufacturing or OT networks, and familiarity with IEC 62443 or Purdue model concepts.
- Experience integrating acquired companies, including consolidating domains, addressing schemes, and network platforms.
- Network automation and scripting experience (Python, Ansible, Terraform, REST APIs including the Meraki Dashboard API).
- Microsoft Azure cloud networking experience, including virtual networks and subnetting, VNet peering, network security groups, Azure Firewall or a third-party NVA, VPN Gateway and ExpressRoute connectivity, private endpoints and DNS resolution, and the hybrid identity considerations that accompany a Microsoft 365 and Entra ID environment.
- Experience extending enterprise network and security policy into hosted, colocation, and IaaS environments, including tunnel design and routing between on-premises firewalls and third-party or provider-managed data centers.
- Experience in an organization actively pursuing CMMC certification, ISO 27001, or SOC 2 attestation.
- ITIL Foundation certification or equivalent practical experience with formal service management.
Skills Required
- 7+ years of enterprise networking experience, including at least 3 years at a senior or lead level in a multi-site environment
- Expert-level routing and switching experience focused on secure, compliant network design across distributed sites
- Proficiency configuring SD-WAN and IPsec tunnels and implementing compliance-aligned network segmentation
- Strong understanding of CMMC, NIST 800-171, SOC 2, and network security standards
- Hands-on multi-site Cisco Meraki experience with MX, MS, and MR platforms
- Hands-on Fortinet FortiGate and FortiOS experience, including policies, security profiles, IPsec, SD-WAN, HA, and firmware lifecycle
- Experience operating multi-vendor firewall estates and migrating between next-generation firewall platforms with minimal disruption
- Data center and virtualization networking experience, including VMware host networking and iSCSI or SAN connectivity
- Enterprise wireless design and troubleshooting experience, including surveys, RF optimization, and secure authentication
- Working knowledge of PKI and certificate management for VPN, 802.1X, and device trust
- Proficiency with network monitoring, logging, analysis, packet capture, and structured troubleshooting
- Ability to independently implement and manage security controls in environments requiring standards development
- Strong organizational, documentation, written, verbal, and technical communication skills
- Fluency in written and spoken English
- Ability to problem-solve and adapt to a dynamic IT environment and emerging compliance challenges
- Willingness to travel occasionally to domestic and international sites
- Willingness to work on-site in Syracuse, New York
- Fortinet NSE 4 or higher, FCP, FCSS, CCNP Enterprise, CCIE, Meraki CMNA, ECMS, PCNSE, CISSP, or CMMC-related certification
- Experience supporting manufacturing or OT networks and familiarity with IEC 62443 or Purdue model concepts
- Experience integrating acquired companies, including domain, addressing, and network-platform consolidation
- Network automation and scripting experience with Python, Ansible, Terraform, REST APIs, or Meraki Dashboard API
- Microsoft Azure cloud networking experience, including virtual networks, peering, security groups, Azure Firewall, VPN Gateway, ExpressRoute, private endpoints, DNS, and hybrid identity
- Experience extending network and security policies into hosted, colocation, and IaaS environments
- Experience with CMMC certification, ISO 27001, or SOC 2 attestation initiatives
- ITIL Foundation certification or equivalent formal service-management experience
What We Do
Wireless technology now impacts nearly every aspect of daily life around the world. As the fastest-growing global tech company, JMA Wireless designs and delivers cutting-edge wireless technology solutions that modernize how people learn, work, live and play, like never imagined. We power today’s leading industries through next-generation software-based 5G, private wireless networks, 5G-ready antennas and connectors, and advanced indoor 5G capabilities — all manufactured in the U.S. Our headquarters, along with the first-of-its-kind 5G campus, are located in Syracuse, NY, with innovative tech hubs around the world. Join our team to shape the future of wireless technology and elevate how people experience the world! JMA designs and builds next-generation communication systems, delivering the industry’s most powerful technologies enabling 4G LTE, 5G, CBRS, and LAA on networks worldwide. JMA XRAN™ leads the industry with the only 100 percent software-based RAN platform, combined with TEKO™, NWAV, and RF distribution technologies. JMA’s millimeter-wave IOTA platform provides a best-in-class radio footprint for indoor 5G deployments.

.png)


