Apply early as this job may be removed or filled prior to the closing date, which is approximately seven (7) days after the posting date.
Job Location: Fort Worth
Other Potential Locations: Fort Worth, TX
Anticipated Start Date: 11/01/2023
Number of Positions: 1
Salary Range: $83,500 – $129,000
Who we are and what we do
Do you want to be a part of something that really matters? Team BNSF includes professionals focused on safety and service that play a vital role in delivering the nation’s freight. Together, we help move goods and materials that sustain life and support local, national and global economies. Our rail network is one of the largest freight railroads, spanning 28 western states and serving three Canadian provinces.
What we believe
At BNSF, our Vision and Values drive who we are, not only in our words, but also our actions. BNSF is committed to our foundational values of equality and inclusion. As members of the BNSF community, our employees are entitled to:
- be treated with dignity and respect.
- have equal access to tools, resources, training and development opportunities.
- have equal opportunity to achieve their full potential.
We model the way through our leadership, our BNSF Diversity Councils, our eclectic Business Resource Groups, our deep involvement and investment in the communities we serve and through training programs. Our actions create an inclusive, open and collaborative workplace that encourages diverse perspectives in all interactions.
-BNSF
As the F5 Network Engineer/Architect, you will provide support by analyzing business requirements to design and develop appropriate systems solutions according to specifications. You will provide technical expertise in evaluating, designing, developing, deploying, monitoring, testing and supporting systems and procedures that are cost effective and improve work efficiency. Additionally, you will partner with enterprise and solution architects to ensure that the application meets company service level standards and roadmap requirements.
Primary Responsibilities
- Implementation and maintenance of F5 security devices.
- Mentor less experienced engineers on the team.
- Provide and maintain configuration standards for the infrastructure.
- Administer and support F5 appliances throughout the organization.
- Monitor security bulletins and mitigate as needed.
- Recommend, design, implement, and support application delivery infrastructure integration into business solutions, while meeting the business’ goals and objectives. This includes supporting documentation and diagrams detailing the specific infrastructure.
- Analyze network topologies and traffic/capacity requirements.
- Work on project/tasks assigned to networking team.
- Develop detailed project plans and implementation diagrams.
- Assist in driving the development, testing and implementation of technology solutions.
- Install, configure, and manage traffic management systems supporting Public Key Infrastructure (PKI), Domain Name System (DNS), load balancing and Multi-Factor Authentication (MFA).
- Translate functional business requirements into a technical solution that conforms to global design standards.
- Research developments in assigned technology disciplines, determining business requirements, proposing changes, and developing migration and implementation plans as needed.
- Install, test, maintain and upgrade network operating systems software and hardware in accordance with release management requirements.
- Provide input into the security technology plan for the organization and ensuring that plans for their assigned technology discipline integrate effectively with other aspects of the technical infrastructure.
- Support large scale infrastructure migrations and baseline reviews.
- Support changes in strict accordance with the change management policies, including developing design and implementation plans for approved changes.
- Gain knowledge and experience in other network security technologies.
- Propose appropriate changes to standards, policies, and procedures based on emerging business/technology trends and operational challenges with the existing guidelines utilizing performance metrics and operational SLAs as justification.
- Conduct presentations via training sessions, or 1-to-1 training to network engineers on designs that are being implemented.
- Configure and support application security policies via the F5 ASM and APM security modules.
Knowledge, Skills and Abilities
- Must be able to work unsupervised, be well organized, and able to multi-task.
- Ability to work in a fast paced environment.
- Ability to troubleshoot and resolve issues in a high-pressure environment.
- Design and implementation experience with F5 BigIP LTM and GTM appliances and virtual appliances.
- Excellent understanding of LTM configuration (VIPs, Persistence, SNAT, SSL, etc.).
- Experience writing and troubleshooting iRules.
- Ability to troubleshoot connection issues and services on F5 appliances.
- F5 OS upgrades, backup and restores.
- Managing F5 appliances in HA configurations.
- Knowledge of troubleshooting tools, such as: tcpdump, ssldump, openssl, QKView, logs, curl, Wireshark, Fiddler, Postman.
- Knowledge of http protocol versions, headers, methods, and status codes.
- Task/project oriented.
- Strong oral and written communication skills; ability to communicate technical concepts to non-technical Associates.
- Ability to analyze and troubleshoot network traffic from layer 1 through 7 with utilities including SSH, nslookup, tcpdump, ssldump, cURL, HTTP GET and Open SSL.
- Ability to effectively articulate the implications and impact that proposed architectural changes will have on the business (to technical and non-technical audiences).
- Availability during evenings and weekends for P1 issues and scheduled change controls.
- Availability to provide 24×7 on-call support as scheduled.
- Availability for occasional travel to remote offices/data centers.
- Knowledge of network monitoring solutions.
- Knowledge of application load balancing strategies and advanced techniques for application delivery
- Excellent troubleshooting skills and an ability to identify root causes of issues and provide solutions.
- Ability to team within and outside of the operations group.
- Strong interpersonal and presentation skills, both verbal and written, with the capability to articulate and educate others about complex technology with business acumen.
Basic Qualifications
- Bachelors degree in Technical, Business or related discipline preferred and/or equivalent formal training or work experience.
- Minimum 6 years work experience in a technical/operations environment.
- Minimum 5 years’ experience with F5 Hardware/Software.
- Must be a F5 Certified Big-IP Administrator (F5-CA).
- Must have experience designing, implementing, and supporting environments that include two or more of the following: Enterprise Gateway architectures including: Firewalls, Application Proxies, Global and Local load balancing, and/or Enterprise Management tools.
- Must have experience working in 24 x 7 centers with complex, high transaction, high availability environments.
- Must have experience creating implementation plans, LTM, GTM, and ASM configurations, TMOS code upgrades, and deployment of new load balancing builds for F5 or Kemp load balancing technologies.
- Must have experience with F5 Traffic Management Operating system, CLI commands, and Route Domains.
- Must have experience creating and maintaining technical documentation.
- Must have experience with F5 ASM & APM modules.
- Must have experience with requesting and installing PKI server certificates.
- Must have experience with configuring PKI Certificate Authority (CA) trust bundles, Certificate Revocation List (CRL) and Online Certificate Revocation List (OCSP).
Preferred Skill Sets
- 5 years’ networking experience.
- F5 Certifications such as: F5-CA, F5-CTS LTM, F5-CTS GTM, or F5-CTS APM.
- 10 Years Cisco Enterprise Level Network experience.
- Experience working with cloud-based solutions such as AWS, Azure, or GCP
- Experience with high-level scripting languages (JavaScript, Python, Ruby, etc.)
- Experience with automation and orchestration frameworks (ansible, puppet, salt, jinja).
BENEFITS
BNSF offers competitive benefit programs and services including, but not limited to
- Medical, Dental and Vision Coverage
- 401(k) Plan
- Railroad Retirement
- Life Insurance
- Incentive Compensation Plan (ICP)
- Tuition Reimbursement Program
BACKGROUND INVESTIGATION ELEMENTS
- Criminal history
- Last 7 years of driving history
- Last 5 years of employment history to include military service
- Social Security number
- Education
MEDICAL REVIEW ELEMENTS:
- Medical evaluation
- Drug Screen
- Other elements as needed
DRUG TEST ELEMENTS:
BNSF is committed to a safe and drug free work place and performs pre-employment substance abuse testing. All new hires are required to undergo a hair drug test which detects the presence of illegal drugs for months prior to testing. We appreciate your cooperation in keeping BNSF safe and drug free.
Transportation Worker Identification Credential (TWIC): Federal authority requires BNSF employees, whose work requires unescorted access to secure areas of port facilities, to obtain a TWIC. A TWIC is a condition of employment for such positions and requires candidates to those positions to submit to a TSA security assessment (to include, but not limited to, providing: biographic information; identity documents; fingerprints; digital photograph). More information is available at https://www.tsa.gov/for-industry/twic.
BNSF Railway is an Equal Opportunity Employer, all qualified applicants receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.
SF: MO | ((mfield5)) | Technology Services | Fort Worth, TX | 76131