Network Designer & Implementer

CGI

Toronto, CAhybrid$75k-$125k/yrPosted Aug 26, 2026
Posting intelligenceActively listed

Skills

programmaticazure devopsterraformjenkinsansibleworkdaygithubgitlabpythonprismaazurecicdgooglecloudaws

About the role

Location: can be located anywhere in Canada within proximity to a CGI location to support a hybrid work environment.

Anticipated start date: Mid December

Accelerate infrastructure delivery through automation by designing, developing, and implementing innovative solutions that improve operational efficiency, enhance service quality, and reduce manual effort. Partner with engineering, operations, and client teams to build scalable, secure, and reliable automation capabilities that enable faster service delivery, continuous improvement, and exceptional client outcomes.

CGI is seeking an experienced Senior Network Designer & Implementer to design, engineer, implement, and evolve enterprise network infrastructure for a major financial services client. This is a senior hands on role requiring deep expertise across Cisco networking, F5 application delivery/load balancing, Palo Alto Networks security, and Network Automation / Infrastructure as Code (IaC). The role owns the lifecycle from requirements and HLD/LLD through implementation, testing, validation, documentation, operational handover, and production support. The environment is highly available, security sensitive, and regulated, with strong expectations for resiliency, security, scalability, automation, operational stability, auditability, and disciplined change governance.

The ideal candidate is a senior Network Designer/Engineer who combines enterprise networking depth with modern automation capabilities. This is not a purely architectural role: the individual must be equally comfortable with solution design, hands on configuration, troubleshooting, production changes, validation, and technical leadership. Core platform strengths are Cisco (enterprise/data centre), F5 (application delivery/load balancing), and Palo Alto (network security/firewalls), supported by an automation first mindset using Python, Ansible, REST APIs, Git, and IaC.

Your future duties and responsibilities

Key Responsibilities

. Lead secure, scalable, resilient, highly available network solution design; translate business, application, infrastructure, cloud, security, and operational requirements into HLDs/LLDs covering topology, routing, connectivity, security, load balancing, resiliency, performance, and operations.

. Develop implementation, migration, validation, and rollback strategies; assess existing infrastructure and recommend modernization/optimization; document design decisions, assumptions, risks, dependencies, trade offs; participate in design/architecture reviews.

. Lead hands on implementation across development, test, staging, DR, and production; configure, deploy, upgrade, validate, and troubleshoot network/security infrastructure; prepare MOPs and implementation plans; support after hours/weekend production windows when required.

. Coordinate end to end implementation with Network, Security, Application, Server, Cloud, Storage, DNS, Operations, and vendor teams; ensure solutions conform to approved designs and standards and transition completed solutions into operations/support.

. Provide senior technical leadership, mentoring, design/troubleshooting facilitation, vendor coordination, POC/product evaluation support, and continuous improvement across network engineering, automation, documentation, and standards.

Core Technology Expertise

Cisco Networking

. Design/implement Layer 2/3 networks; advanced routing/switching and troubleshooting; BGP, OSPF and EIGRP where applicable; VLANs, trunking, STP, link aggregation, segmentation, routing domains, QoS, high availability, redundancy, and inter data centre connectivity.

. Hands on experience with Cisco Nexus, enterprise switching and routing platforms; Cisco ACI strongly preferred; understanding of SDN/controller based networking; capacity/performance engineering, lifecycle upgrades, and troubleshooting of latency, packet loss, asymmetric routing, and connectivity issues.

. Perform configuration/design reviews, identify deficiencies, and recommend corrective actions.

F5 Application Delivery & Load Balancing

. Design, implement, troubleshoot, upgrade, and migrate enterprise F5 BIG IP/LTM solutions, including Virtual Servers, Pools/Pool Members, Health Monitors, Profiles, SSL/TLS profiles, SNAT, Persistence, and Traffic Policies; design highly available architectures.

. Understand HTTP/HTTPS, TCP, TLS, DNS, application traffic flows, SSL termination/offload, and certificate management considerations; F5 DNS/GTM and iRules are highly desirable; F5 APIs/automation strongly preferred.

. Partner with application teams to translate availability and traffic management requirements into F5 configurations.

Palo Alto Networks Security

. Design and implement secure Palo Alto NGFW architectures, including security rules/policies, NAT, zones/interfaces, routing integration, application/service policies, segmentation, HA, and centralized management with Panorama.

. Use App ID/User ID where applicable; understand threat prevention/security profiles; perform troubleshooting, policy optimization/rule base hygiene, software upgrades, lifecycle activities, and integration with automated provisioning/configuration workflows.

. Work with Cybersecurity to meet security standards and controls; Prisma Access/cloud based Palo Alto capabilities are an asset.

Network Automation & Infrastructure as Code

Network Automation is a key requirement. Demonstrated ability to move network engineering from manual configuration to repeatable, version controlled workflows is expected.

. Develop automation for provisioning, configuration, validation, compliance, backups, drift detection, and pre/post change checks across Cisco, F5, and Palo Alto platforms where supported; use APIs for programmatic interaction.

. Build reusable scripts/modules/workflows; integrate automation with CI/CD; maintain code in source control; apply code review, testing, approval, and deployment controls; reduce manual effort, configuration errors, and implementation risk.

. Core tools: Python, Ansible/Ansible Automation Platform, REST APIs, JSON/YAML, Git, CI/CD, IaC. Beneficial: Terraform, NetBox, vendor APIs/SDKs, Jenkins/GitLab/GitHub Actions/Azure DevOps, network validation/testing frameworks, Netmiko/NAPALM/Paramiko or equivalents.

. Automation must be supportable, reusable, secure, controlled, and suitable for enterprise operations.

Security, Resiliency & Financial Services Controls

. Apply secure by design, least privilege, segmentation, defense in depth, controlled administrative access, privileged access, logging/monitoring, configuration traceability, and approved change management practices; coordinate with Cybersecurity, Risk, Compliance, Architecture, and Audit.

. Complete required security assessments/approvals, maintain audit evidence, support vulnerability remediation and audit findings, and meet financial services technology/security requirements.

. Design for redundancy, fault tolerance, active/active or active/standby as appropriate; minimize single points of failure; validate failover/recovery; support DR planning/testing and resiliency exercises; align to application RTO/RPO where applicable and document service dependencies.

Troubleshooting, Change & Documentation

. Provide senior troubleshooting across routers, switches, firewalls, load balancers, and applications; analyze end to end traffic; troubleshoot routing, DNS, TCP, SSL/TLS, latency, packet loss, firewall, and load balancing issues; perform packet captures/traffic analysis; lead RCA and permanent corrective actions; use automation to prevent recurring issues.

. Prepare change records, implementation/validation/communication/rollback plans; participate in technical/CAB reviews; coordinate dependent teams; execute within approved windows; perform post change validation and recovery; maintain strong change hygiene.

. Maintain HLDs, LLDs, diagrams, traffic/security flows, implementation/migration plans, MOPs, test/validation and rollback plans, SOPs, configuration standards, automation runbooks, operational support documentation, and knowledge transfer materials.

Required qualifications to be successful in this role

Mandatory Qualifications & Experience

. 10+ years of enterprise network engineering experience with significant hands on design and implementation responsibility in large, complex environments.

. Strong hands on expertise with Cisco networking, F5 BIG IP/LTM, and Palo Alto Networks firewalls/Panorama; advanced TCP/IP, routing/switching, BGP/OSPF, and Layer 2/3 troubleshooting skills.

. Demonstrated experience with resilient/high availability architectures and business critical production environments.

. Demonstrated Network Automation experience using Python, Ansible, APIs and/or IaC, plus Git/source control.

. Experience producing HLDs/LLDs, implementation plans, network diagrams, production changes, and complex multi tier application connectivity troubleshooting.

. Strong network security/segmentation knowledge; strong written/verbal communication; able to work across infrastructure, security, application, cloud, operations, vendors, and business teams.

Preferred Qualifications & Certifications

. Financial services experience (banking, payments, capital markets, insurance) and highly regulated/security sensitive environments; Cisco ACI; F5 DNS/GTM and iRules; Prisma Access; AWS/Azure/GCP and hybrid/multi cloud networking; SDN; Terraform; network CI/CD; automated testing/validation; ServiceNow/ITSM integration; monitoring/observability/telemetry; DNS/DHCP/IPAM; data centre migration/network transformation; distributed teams/managed service providers.

. Certifications: CCNP Enterprise/Data Center, CCIE, F5 Certified Technology Specialist, Palo Alto PCNSE, AWS/Azure/GCP networking, Red Hat Ansible Automation, HashiCorp Terraform, and/or ITIL. Equivalent hands on experience accepted.

Working Conditions

. Location: Anywhere in Canada.

. Work model: Hybrid – minimum three days per week in office.

. Schedule: Standard eight hour workday; occasional after hours, evening, or weekend work may be required based on project or operational needs.

. Travel: No travel required.

Security & Compliance Requirements

. Must be eligible to obtain and maintain Government of Canada Protected B Security Clearance.

. Must adhere to all client security, operational and compliance policies.

MANDATORY QUALIFICATIONS & EXPERIENCE

. 10+ years of enterprise network engineering experience with significant hands on design and implementation responsibility in large, complex environments.

. Strong hands on expertise with Cisco networking, F5 BIG IP/LTM, and Palo Alto Networks firewalls/Panorama; advanced TCP/IP, routing/switching, BGP/OSPF, and Layer 2/3 troubleshooting skills.

. Demonstrated experience with resilient/high availability architectures and business critical production environments.

. Demonstrated Network Automation experience using Python, Ansible, APIs and/or IaC, plus Git/source control.

. Experience producing HLDs/LLDs, implementation plans, network diagrams, production changes, and complex multi tier application connectivity troubleshooting.

. Strong network security/segmentation knowledge; strong written/verbal communication; able to work across infrastructure, security, application, cloud, operations, vendors, and business teams.

PREFERRED QUALIFICATIONS & CERTIFICATIONS

. Financial services experience (banking, payments, capital markets, insurance) and highly regulated/security sensitive environments; Cisco ACI; F5 DNS/GTM and iRules; Prisma Access; AWS/Azure/GCP and hybrid/multi cloud networking; SDN; Terraform; network CI/CD; automated testing/validation; ServiceNow/ITSM integration; monitoring/observability/telemetry; DNS/DHCP/IPAM; data centre migration/network transformation; distributed teams/managed service providers.

. Certifications: CCNP Enterprise/Data Center, CCIE, F5 Certified Technology Specialist, Palo Alto PCNSE, AWS/Azure/GCP networking, Red Hat Ansible Automation, HashiCorp Terraform, and/or ITIL. Equivalent hands on experience accepted.

WORKING CONDITIONS

. Location: Anywhere in Canada.

. Work model: Hybrid – minimum three days per week in office.

. Schedule: Standard eight hour workday; occasional after hours, evening, or weekend work may be required based on project or operational needs.

. Travel: No travel required.

SECURITY & COMPLIANCE REQUIREMENTS

. Must be eligible to obtain and maintain Government of Canada Protected B Security Clearance.

. Must adhere to all client security, operational and compliance policies.

CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $75,000–$125,000. This role is an existing vacancy

#LI-AB19

Together, as owners, let’s turn meaningful insights into action.

Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you’ll reach your full potential because…

You are invited to be an owner from day 1 as we work together to bring our Dream to life. That’s why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company’s strategy and direction.

Your work creates value. You’ll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise.

You’ll shape your career by joining a company built to grow and last. You’ll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.

At CGI, we value the strength that diversity brings and are committed to fostering a workplace where everyone belongs. We collaborate with our clients to build more inclusive communities and empower all CGI partners to thrive. As an equal-opportunity employer, being able to perform your best during the recruitment process is important to us. If you require an accommodation, please inform your recruiter.

That same commitment to fairness extends to how we use technology. To support our recruitment team, AI tools may be used to help assess applications though they never replace human judgement. All hiring decisions remain entirely in the hands of our recruitment professionals.

To learn more about accessibility at CGI, contact us via email. Please note that this email is strictly for accessibility requests and cannot be used for application status inquiries.

Come join our team - one of the largest IT and business consulting services firms in the world.

Compensation

This Other role pays $75k-$125k/yr. Within typical range for other roles in Canada.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on CGI's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Other roles in Canada varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Other hub for Canada medians across recent openings.

You never touch the form - the application is filled and submitted for you on CGI's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.