At the Monterey Bay Aquarium, we are passionate about creating an inclusive workplace that celebrates and values diversity. We firmly believe that having a team of diverse backgrounds and voices, working together, increases our capacity to serve our visitors and fulfill our mission. We welcome people from all walks of life into our team and strongly encourage people of color, LGBTQ+ individuals, veterans, and people with disabilities to apply.
Job Summary:
With limited oversight, provide senior-level engineering services for the aquarium’s on-premises and cloud networks, including design, documentation, implementation, operation, troubleshooting, and continuous improvement of wired/Wi-Fi networks, routing/switching, firewalls/VPN, and associated services. Lead with data, produce performance reports, build business cases and ROI analyses, and recommend cloud vs. on-prem investments. Partner with Network Systems Engineer, IT Security Analyst, Tech Ops, and vendors. Perform other duties as required.
Core Activities:
- Respond & remediate escalated physical/cloud and logical network issues across sites (break/fix, replace/repair/reconfigure).
- Resolve critical network outages and connectivity failures
- Repair and/or replace faulty network infrastructure components
- Reconfigure and restore misconfigured or degraded network services
- Provide escalation support for Help Desk and monitoring/alerting handoffs to meet expectations/SLAs (Service Level Agreements).
- Prioritize incidents; communicate clearly with leadership/staff during outages (site-specific or system-wide).
- Develop business cases, cost/benefit & ROI analysis for refreshes and cloud vs. on-prem deployment decisions.
- Recommend upgrades/improvements as needed using recurring LAN/WAN/WLAN/cloud performance reports to avoid bottlenecks and stability issues.
- Identify and solution for capacity & stability planning to avoid bottlenecks; advise leadership on future needs (cloud vs. on-prem).
- Operate core platforms (switching, routing, firewalls, VPN, wireless/controllers, cloud networking).
- Perform advanced diagnostics and packet analysis (PCAPs, logs, RF interference, rule/filter testing) to resolve intermittent and persistent issues.
- Design network architecture & roadmap (align to demand, resilience, and security; cloud interconnect patterns).
- Coordinate patch/upgrade with the IT Security Analyst to reduce risk, DR/BC readiness (redundancy design, failover drills, recovery procedures) tied to RTO/RPO, and change management & pre-deployment testing with documented rollback plans.
- Document and maintain system and process diagrams and workflows (L2/L3/RF diagrams, inventories, SOPs/runbooks).
Preferred Knowledge, Skills & Abilities (KSAs):
- Any combination of education, training, and experience that would cover the skills necessary to perform the job effectively and with minimal supervision.
- Advanced industry certifications such as CCNP, CCIE, BICSI RCDD, Network+, CWNP, CISSP, AWS Certified Advanced Networking, and other relevant certifications.
- Knowledge of network protocols and their functions, including TCP/IP, UDP, DNS, DHCP, SMB, SMTP, HTTP/S, FTP, and others as applicable.
- Knowledge of network architecture & design for LAN/WAN/WLAN and hybrid cloud (hub-and-spoke, transit, segmentation)
- Knowledge of firewalls, zone-based rule design, NAT, IPsec/RA-VPN, SSL decryption, IDS/IPS profiles, HA/failover
- Knowledge of troubleshooting & packet analysis, Wireshark/tcpdump fluency; MTU/MSS, asymmetric paths, jitter/loss triage
- Knowledge of L2 switching, VLANs, 802.1Q, STP/RSTP/MST, LACP/port-channels, loop prevention
- Knowledge of cable testing equipment and methodologies to verify proper functionality of installed cabling systems
- Skill in routing at scale, OSPF, BGP (policy/communities, filtering, convergence), static/ECMP; redistribution hygiene
- Skill in Wi-Fi/RF engineering, 802.11k/r/v, capacity planning, roaming, SNR, high-density design, WPA2/3-Enterprise, controller ops, site surveys/heatmaps
- Skill with wired and wireless networking standards, specifications, system design, testing, troubleshooting, and limitations
- Skill in hybrid/cloud networking, AWS/Azure/GCP (VPC/VNet, TGW/Hub-Spoke, Direct Connect/ExpressRoute, GW/LB, SG/NACL), and cloud firewalls
- Skilled at TCO/ROI modeling, refresh justifications, cloud vs. on-prem comparisons; clear leadership-ready summaries and recommendations
- Skill at segmentation and access control, VRFs, ACLs, 802.1X/NAC with RADIUS/TACACS+, Zero-Trust micro-segmentation
- Ability to obtain, exchange, and clarify information and communicate technical information to both technical and non-technical personnel
- Ability to manage vendors and stakeholders, contracts/support escalations/RMAs, translate business goals into actionable designs, crisp outage communications
- Ability to create accurate estimates of charges, both one-time and recurring, when recommending and using cloud-based infrastructure
- Ability to create and maintain authoritative diagrams, inventories, SOPs/runbooks, and maintain a “source of truth”
- Ability to learn and research new concepts, ideas, and technologies
- Ability to work independently, exercise good judgment, and make data-driven decisions
- Ability to keep your knowledge current and informed on existing and emerging technologies, and be able to develop recommendations on the best path forward for the organization
- Ability to work within and maintain Monterey Bay Aquarium’s Core Values
Physical Requirements to Perform Essential Job Functions:
- Typical office equipment
- Constant sitting, standing, walking, bending
- Occasional unassisted lifting up to 50 lbs.
- Typical office environment, main aquarium and exhibits, occasional offsite events, may need to crawl into confined spaces
Annual Compensation Range:
$93,500-$119,000 USD annually. Starting rate will vary based on previous experience and relevant skills/knowledge set.