Tier4 Group is a rapidly growing healthcare-focused technology organization seeking a Senior Network Security Engineer. The role involves architecting and supporting secure network infrastructures across multi-site healthcare environments, while leading Zero Trust initiatives and representing the engineering team in high-visibility meetings.
Responsibilities:
- Architect, deploy, and support LAN/WAN and wireless networks across multi‑site healthcare environments (Ubiquiti, Meraki, Cambium, Aruba, Cisco, Ruckus)
- Configure and maintain next‑gen firewalls (Palo Alto, Fortinet, SonicWall, Meraki) across diverse environments
- Lead Zero Trust initiatives, including:
- ZTNA
- Network Access Control (NAC)
- Micro‑segmentation
- VPN reduction & identity‑based access strategies
- Serve as Tier 3 escalation (approx. 70% of workload)
- Diagnose and resolve high-impact issues including spanning tree loops, routing anomalies, physical mispatch events, rogue devices, and wireless instability
- Perform deep traffic analysis, packet captures, and threat analytics using NetFlow, Auvik, and firewall telemetry
- Execute projects ranging from small firewall upgrades to large-scale deployments involving:
- 50–70 switches
- 400–500 access points
- Multiple redundant firewalls
- Support technology refreshes across newly onboarded communities with widely varying equipment and configurations
- Represent the Network Engineering function in high-visibility meetings, especially at the Des Moines corporate headquarters
- Interface with IT Directors, CIOs, CTOs, and virtual IT leaders — requiring exceptional communication and professionalism
- Partner with community-level leadership (Chicago) and internal NOC teams (Alpharetta) as needed
- Maintain network baselines, configuration repositories, documentation, and disaster‑ready backups
- Contribute to SIEM integrations and ongoing hardening of the security posture
- Mentor L2/L3 engineers and help level up team capability
Requirements:
- 7+ years of senior-level network + security engineering experience
- Strong multi-vendor background — Cisco, Meraki, Palo Alto, Fortinet, SonicWall, Ubiquiti, Ruckus, etc
- Deep knowledge of: Routing & switching, VLAN segmentation & VRFs, QoS, DNS, NAT, 802.1X, RADIUS, EAP-TLS, IDS/IPS, DNS filtering, gateway security layers
- Experience with Auvik or similar monitoring and packet capture tools
- Ability to operate effectively in environments with limited physical control (mispatching, unmanaged local changes, etc.)
- Broad familiarization with adjacent IT domains (Windows servers, infrastructure, general enterprise systems)
- Outstanding communication skills with the ability to converse confidently with senior IT executives
- Highly self-managed — able to operate remotely with limited oversight
- Architect, deploy, and support LAN/WAN and wireless networks across multi-site healthcare environments (Ubiquiti, Meraki, Cambium, Aruba, Cisco, Ruckus)
- Configure and maintain next-gen firewalls (Palo Alto, Fortinet, SonicWall, Meraki) across diverse environments
- Lead Zero Trust initiatives, including: ZTNA, Network Access Control (NAC), Micro-segmentation, VPN reduction & identity-based access strategies
- Serve as Tier 3 escalation (approx. 70% of workload)
- Diagnose and resolve high-impact issues including spanning tree loops, routing anomalies, physical mispatch events, rogue devices, and wireless instability
- Perform deep traffic analysis, packet captures, and threat analytics using NetFlow, Auvik, and firewall telemetry
- Execute projects ranging from small firewall upgrades to large-scale deployments involving: 50–70 switches, 400–500 access points, Multiple redundant firewalls
- Support technology refreshes across newly onboarded communities with widely varying equipment and configurations
- Represent the Network Engineering function in high-visibility meetings, especially at the Des Moines corporate headquarters
- Interface with IT Directors, CIOs, CTOs, and virtual IT leaders — requiring exceptional communication and professionalism
- Partner with community-level leadership (Chicago) and internal NOC teams (Alpharetta) as needed
- Maintain network baselines, configuration repositories, documentation, and disaster-ready backups
- Contribute to SIEM integrations and ongoing hardening of the security posture
- Mentor L2/L3 engineers and help level up team capability