
Network Security Engineer Principal
Children’s Hospital of Philadelphia
- Philadelphia, PA
- $126,560-167,690 per year
- Permanent
- Full-time
The Principal Network Engineer is a senior technical authority responsible for leading the design, deployment, and optimization of enterprise network infrastructure. This role drives strategic initiatives across traditional and cloud environments, with a focus on data center fabric architectures, hybrid connectivity, and secure, scalable solutions. The engineer serves as a mentor, advisor, and hands-on expert in technologies such as cloud networking (Azure, AWS), dynamic routing protocols (BGP, OSPF), and advanced security platforms. Ideal candidates bring deep architectural insight, operational excellence, and a forward-looking approach to network evolution.This department works approximately 80% remotely, 20% on site in our Philadelphia offices on an as needed basis.What you will do
- A Principal Network Engineer also:
- Leads the planning and implementation of advanced network technologies, including cloud-native and hybrid architectures.
- Designs scalable, resilient data center fabric architectures and integrates dynamic routing protocols such as BGP and OSPF.
- Evaluates emerging technologies and develops enterprise-wide standards for network infrastructure.
- Oversees complex troubleshooting and automation efforts across multi-vendor environments.
- Leads enterprise-wide network initiatives requiring deep cross-domain expertise.
- Maintains expert-level knowledge of internal systems and external industry trends.
- Mentors engineers across all levels and contributes to strategic planning and governance.
- Participates in enterprise-wide incident response.
- Supports continuous improvement in project execution, workflow, and performance management.
- Serves as expert for management task forces and committees.
- Participates and provides feedback to improve CHOP corporate and DTS processes including, but not limited to, work flow, project management, time accounts, and employee reviews.
- Bachelor's Degree Computer Science or related field Required
- At least seven (7) years experience in Data Networking and TCP/IP Protocols. Required
- At least seven (7) years experience in networks, LAN/WAN or management information systems. Required
- Expert design experience pertaining to IP data solutions in the healthcare industry Preferred
- At least three (3) years Hands-on experience with cloud networking in Azure and AWS environments Required
- At least five (5) years Experience designing and deploying data center fabric architectures and integrating BGP/OSPF routing Required
- At least three (3) years Familiarity with load-balancer technologies (F5, Netscaler, Cloud Native Load Balancing solutions) and enterprise firewalls (Checkpoint, ASA, Palo Alto) (Preferred) Preferred
- Strong communication and interpersonal skills to interact with team members, management, customers and support personnel. (Required proficiency)
- Strong ability to analyze and solve complex problems using analytical and creative problem solving skills for design, creation and testing of networks. (Required proficiency)
- Extensive knowledge and experience understanding industry best practices on network architecture and engineering and experience in robust network, product/service and system design and implementation strategies. (Required proficiency)
- Extensive knowledge and experience in wide range of technologies including routing and switching design and architecture. (Required proficiency)
- Expert level knowledge of switching, including but not limited to: CGMP, IGMP, 802.xx, Gigabit Ethernet, Fast Ethernet, Vlan/Trunking (802.1q), Etherchannel, Spanning Tree (STP), HSRP, VRRP. (Required proficiency)
- Solid knowledge of IPv4 routing protocols (OSPF, BGP), along with their control plane dynamics, QoS and rate limiting, IP addressing and subnetting, Ethernet standards and 10GigE Ethernet technology. (Required proficiency)
- Expert knowledge of network security systems and protocols including firewalls, Radius and TACACS+, IPSEC and IKE, SSH, etc.. (Required proficiency)
- Knowledge in ancillary technologies used to support enterprise network monitoring and management such as fault/performance management and metric gathering tools/technology (SNMP, Netflow), packet capturing tools, and automation tools. (Required proficiency)
- Information Security Requirements: (Required proficiency)
- Understand and comply with all enterprise and IS departmental information security policies, procedures and standards. (Required proficiency)
- Support the integration of information security in the development, design, and implementation of Hospital Technology Resources that process, transmit, or store CHOP information. (Required proficiency)
- Support all compliance activities related to state, federal regulatory requirements, healthcare accreditation standards, and all other applicable regulations that govern the use and disclosure of patient, financial, or other confidential information. (Preferred proficiency)