Infrastructure & Security Engineer
ARCHIVED
We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.
HybridOn-site travel required for project deploymentsPacific or Mountain time zone requiredReports to Technical Operations ManagerAbout the RolePacket6 is looking for a skilled Infrastructure & Security Engineer to take ownership of enterprise-grade infrastructure and security initiatives for our client with sites across the West Coast and Hawaii. This is a technically deep role requiring hands-on expertise in cybersecurity, identity and access management, infrastructure monitoring and systems management, and security management.You will report to the Technical Operations Manager and collaborate closely with the broader Packet6 engineering team, the CISO, and client. The role is hybrid, based on the Pacific or Mountain time zone, with on-site travel to client sites as projects require. You'll be driving infrastructure and security projects from design through implementation — not just executing projects, but shaping how systems are built and secured. This role includes on-call rotation for critical systems support.This is an excellent opportunity for an experienced engineer who wants ownership of meaningful projects, enjoys working across a diverse technology stack, and thrives in a lean, trust-based environment where good work speaks for itself.Day-to-Day ResponsibilitiesLead and execute Okta deployment as the central Identity Provider (IdP), integrating with downstream applications and enforcing phishing-resistant authenticationDeploy and manage Zero Trust Network Access (ZTNA) and SASE solutions, including GlobalProtect VPN and related access control frameworksConduct Google Groups and permissions audits, establishing least-privilege access policies across Google WorkspaceManage endpoint security platforms including CrowdStrike — redeployment, policy tuning, and ongoing monitoringEvaluate, deploy, and manage a SIEM solution for centralized logging and security visibility across all network devices and applicationsDeploy and maintain enterprise network infrastructure across multi-site environments including firewalls, switches, access points, and WAN connectivityMonitor and respond to security events and alerts across endpoint, network, and identity systemsManage Okta policies, user lifecycle, group policies, and access reviewsMonitor Okta for suspicious login activity, MFA anomalies, and indicators of account compromisePerform regular vulnerability scans and remediate findings in collaboration with the vCISOPerform ISP and backup connectivity deployments including Starlink rollouts across all sitesManage IT asset inventory and IP address management (IPAM) in NetBox, ensuring accuracy across all sitesLead and participate in change management activities, coordinating maintenance windows and communicating impact to stakeholders and principalsParticipate in firewall upgrades and replacement projects with the Jr. Network Engineer (e.g., Palo Alto Networks, Meraki, or Ubiquiti) including policy review, migration planning, and cutover executionAssist with configuration and management of site-to-site VPNs with BGP for ISP redundancy and dynamic failover across dual-WAN sitesSupport network camera systems — evaluating vendors, managing migrations, cross-team collaboration, and ensuring systems meet access and retention requirementsMaintain IT SOPs, network & system diagrams, and technical documentation in ConfluenceDrive automation initiatives to reduce manual repetitive tasks and improve consistency across environmentsActive Projects You'll Inherit and DriveFrom day one, you will step into a portfolio of active infrastructure and security initiatives.Current projects include:Security & Access ControlCrowdStrike deployment and policy tuningOkta deployment as central Identity ProviderGoogle Workspace Enterprise upgrade (DLP, attachment protection, link scanning, external sender banner)Ongoing CISO-aligned cybersecurity task executionZero Trust Network Access (ZTNA) architecture and rolloutGlobalProtect VPN RolloutSASE VPN implementationSIEM solution evaluation and deploymentNAC evaluation and deploymentUpgrade Windows servers OSOperations & ComplianceIT inventory and IPAM audit using NetBoxGoogle Groups and permissions auditNetwork camera management systemIT SOP documentationNetwork InfrastructureBackup ISP deployment across all sitesFirewall upgrades at multiple sitesSite-to-site VPN with BGP for dual-ISP sitesNew network deploymentsFiber internet buildoutsTools You Will UseNetworking: Juniper Mist, Palo Alto Networks, Meraki, UniFi, StarlinkSecurity: CrowdStrike, GlobalProtect, Palo Alto SASE/Prisma, SIEMIdentity & Access: Okta, Google Workspace Admin, Microsoft 365Infrastructure & Inventory: NetBox (IPAM), NinjaOne, KandjiAutomation: Scripting tools (Bash, Python), APIs for platform integrationTicketing & Documentation: Jira, ConfluenceCollaboration: Slack, Google Meet, ZoomRequired Qualifications3+ years of hands-on experience in security engineering, infrastructure, and/or network administrationExperience deploying or administering an Identity Provider such as Okta, Azure AD, or Ping IdentityFamiliarity with Zero Trust principles and SASE/ZTNA architectureWorking knowledge of endpoint security platforms (CrowdStrike or equivalent)Deep experience designing and managing enterprise firewall environments (Palo Alto, Juniper, or equivalent)Proficiency with BGP, VPN technologies (site-to-site, remote access), and WAN redundancy architecturesExperience with wireless infrastructure — design, deployment, and management (Juniper Mist, Meraki, or UniFi)Strong documentation habits — you write clear playbooks, diagrams, and SOPsAbility to manage multiple simultaneous projects with competing prioritiesComfortable working in a hybrid remote model with occasional travel to client sitesValid driver's license and ability to travel to West Coast and Hawaii sites as neededPreferred QualificationsExperience in a Managed Service Provider (MSP) or managed security environmentExperience managing Google Workspace at an enterprise level (DLP, security controls, Admin SDK)Familiarity with SIEM platforms (e.g., Splunk or similar)Hands-on experience with Juniper Mist and/or Mist Access AssuranceProficiency with NetBox or another IPAM/DCIM platformScripting or automation skills (Bash, Python, or PowerShell) for infrastructure tasksExperience with physical IT tasks in multi-site environments (rack and stack, cabling, hardware staging)What Success Looks LikeIn your first 90 days, you have a clear handle on the active project portfolio, understand the current state of infrastructure across all sites, and have begun moving key initiatives forward. The Okta deployment roadmap is defined. Firewall upgrades are scoped and scheduled. Documentation gaps are identified and being addressed. You're a trusted voice in architecture decisions, and the team knows they can hand you a complex problem and you'll come back with a plan.At six months, you've delivered multiple projects end-to-end: CrowdStrike is cleanly deployed across endpoints, VPN configurations are live, and the SIEM is ingesting logs. Security posture has measurably improved. You're not just completing tasks — you're anticipating what comes next and helping shape the roadmap.Working at Packet6We're a small, tight-knit team and we like it that way. No corporate fluff, no endless approval chains. Just a group of people who genuinely love technology and take pride in doing the work right.Our team is distributed, so we stay connected through clear communication and a whole lot of trust. You won't have someone breathing down your neck — but you will have a crew that's got your back when things get weird (and in infrastructure and security, things sometimes get weird).As an Infrastructure & Security Engineer at Packet6, you'll have real ownership of real systems. Bring your experience, bring your opinions, and bring your drive — because we're building something here and we want people who are excited to be part of it.If you think infrastructure work is just keeping the lights on, this probably isn't the right fit. But if you care deeply about how systems are built, get fired up about security done right, and want to work alongside people who share that energy — let's talk.Work hard, be kind. Have fun doing it.