About Us:
At apexanalytix, we’re lifelong innovators! Since the date of our founding nearly four decades ago we’ve been consistently growing, profitable, and delivering the best procure-to-pay solutions to the world. We’re the perfect balance of established company and start-up. You will find a unique home here.
And you’ll recognize the names of our clients. Most of them are on The Global 2000. They trust us to give them the latest in controls, audit and analytics software every day. Industry analysts consistently rank us as a top supplier management solution, and you’ll be helping build that reputation.
Read more about apexanalytix - https://www.apexanalytix.com/about/
Most network engineering jobs today are configuring someone else's cloud. This one is not. We build, own and operate our own private cloud across our own datacenters, from the fabric up, and you would own the network underneath it. That means Anycast and BGP you design rather than raise a ticket for, and Kubernetes networking at the CNI layer rather than at the console.
What you would own
Kubernetes networking at the CNI layer. Cilium and the eBPF datapath, network policy, and how pod networking meets the physical fabric. This is the part most network engineers never get near, and it is central to this role rather than adjacent to it.-
The routed core. BGP design and Anycast deployment across our datacenters, including how traffic is steered between sites and how it fails over when one goes away.
-
The perimeter. Firewalls, IDS and IPS, site-to-site connectivity, ISP relationships and WAN resilience.
-
The switching estate. Multi-vendor across Cisco Nexus and Catalyst, Aruba and Ruckus, in both enterprise and datacenter contexts.
-
Hybrid connectivity into Azure, and the design decisions about what stays on our own hardware and what does not.
-
The standard the network is run to. Documentation, topology, change discipline, and the resiliency and security hardening roadmap. You set it, rather than following it.
What the first year looks like
-
Bring the Kubernetes network layer under the same operational standard as the physical fabric.
-
Take ownership of the Anycast and BGP design and make its failover behaviour provable rather than assumed.
-
Lead at least one DR exercise end to end, and fix what it exposes.
-
Remove the single points of knowledge, so no part of the network depends on one person being reachable.
What we need you to have done
Kubernetes networking is a hard requirement for this role. You need hands-on production experience with a CNI, Cilium or Calico, and you should be able to walk us through how a packet reaches a pod and how you debugged it when it did not. Certification without production experience does not meet this bar. If you have not worked at the CNI layer, this is not the right role for you, and we would rather say so here than at interview.
Hands-on Kubernetes networking with Cilium or Calico in production. Network policy, the datapath, and the boundary between pod networking and the physical fabric.-
8+ years in network engineering, with real depth in routing and switching across both enterprise and datacenter environments.
-
BGP in production, and Anycast you have designed or operated. Not familiarity. Design decisions you made and can defend.
-
Firewalls, IDS and IPS, and perimeter design. Barracuda and ASA or FTD are what we run.
-
Multi-vendor switching. Cisco Nexus and Catalyst, Aruba, Ruckus.
-
Azure networking: VNets, VPN gateways, hybrid connectivity. AWS or GCP a plus.
-
Monitoring and root cause analysis in complex environments, with tools such as SolarWinds or Grafana, including the ability to prove where a fault is rather than where it is not.
-
CCNP or equivalent depth. The certificate matters less than being able to walk us through a failure you diagnosed.
-
Two or more DR implementations you took part in, including the testing.
-
Bachelor's degree in a technical field, or equivalent practical experience.
How the team works
-
You would join the IT Infrastructure team and work directly with platform engineering, security and the OEM vendors.
-
On-call is a shared rotation, not a permanent state. Major incidents are escalated to the whole team, and we would rather fix the cause than staff the symptom.
-
We expect ownership rather than ticket-taking. If you find something broken outside your area, we would rather you said so.
-
This role is a step toward network architecture ownership across the estate as the Noida centre grows.
Over the years, we’ve discovered that the most effective and successful associates at apexanalytix are people who have a specific combination of values, skills, and behaviors that we call “The apex Way”. Read more about The apex Way - https://www.apexanalytix.com/careers/
Benefits
At apexanalytix we know that our associates are the reason behind our successes. We truly value you as an associate and part of our professional family. Our goal is to offer the very best benefits possible to you and your loved ones. When it comes to benefits, whether for yourself or your family the most important aspect is choice. And we get that. apexanalytix offers competitive benefits for the countries that we serve, in addition to our BeWell@apex initiative that encourages employees’ growth in six key wellness areas: Emotional, Physical, Community, Financial, Social, and Intelligence.
With resources such as a strong Mentor Program, Internal Training Portal, plus Education, Tuition, and Certification Assistance, we provide tools for our associates to grow and develop.