
Network Engineer (Mortgage Industry)
CMG Financial · United States
- Hybrid
- Full-time
- $130,000 / year
- United States
Tailored resume — keyword-matched to this role.
Hiring manager — we find who's hiring.
Intro email — drafted to reach them directly.
Job highlights
- Design, implement, and manage enterprise network infrastructure.
- Work with Palo Alto firewalls and Azure cloud networking.
- Ensure secure, high-availability connectivity.
- Troubleshoot network incidents and perform root cause analysis.
- Automate tasks using scripting and IaC tools.
About the role
Network Engineer
CMG Financial is looking for an experienced Network Engineer to design, implement, and manage enterprise network infrastructure across on-premises, hybrid, and Azure cloud environments. You will work with cutting-edge technologies including Palo Alto next-generation firewalls, Azure networking services, and modern SASE architectures to ensure secure, high-availability connectivity for our organization.
Essential Duties and Responsibilities
Responsibilities include, but are not limited to:
- Firewall & Security Operations: Review and update Palo Alto security policies, NAT rules, and App-ID/User-ID configurations. Monitor threat prevention alerts, URL filtering hits, and WildFire submissions. Manage VPN tunnels (site-to-site and remote access), addressing status, drops, or mismatches.
- Azure Networking: Monitor NSG flow logs, Azure Network Watcher, and Connection Monitor for anomalies. Review hub-and-spoke topology health, including VNet peering, private endpoints, and DNS resolution. Check Azure Firewall policy hits and deny logs.
- Change & Configuration Management: Implement and document approved network changes such as firewall rules, VLAN changes, and routing updates. Utilize Panorama/Strata Cloud Manager for pushing policy updates across managed firewalls. Maintain and update network documentation, including topology diagrams, runbooks, and IP addressing.
- Ticket & Problem Resolution: Respond to and triage network incidents, performing Layer 1–7 troubleshooting and root cause analysis. Triage and prioritize incoming tickets from the service desk, assigning severity and ownership. Investigate and resolve network-related incidents like connectivity failures, latency, and application access issues. Perform root cause analysis on recurring issues and document findings for problem records. Update ticket status, add work notes, and communicate resolution steps to stakeholders. Escalate complex issues to senior engineers or vendors with full diagnostic context. Close resolved tickets with detailed notes for knowledge base reuse.
- Automation & IaC: Write or maintain PowerShell/Python/Bash scripts for operational tasks. Update Terraform configurations for infrastructure changes, validating and planning before applying.
- Collaboration: Communicate with application, security, and helpdesk teams regarding connectivity issues. Participate in an on-call rotation, handing off or escalating as needed. Attend change advisory or ops standup meetings.
Qualifications and Experience
- Education and Experience: Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent hands-on experience. 3–7+ years of network engineering experience in enterprise, multi-site, or hybrid cloud environments.
- Core Networking Skills: Deep understanding of TCP/IP, subnetting, routing, switching, VLANs, DNS, and DHCP. Experience with Cisco Catalyst, Nexus, and Meraki switches. Experience with BGP in enterprise or hybrid cloud environments. Hands-on experience with firewalls, including rule creation, NAT, and VPNs. Experience with load balancing technologies (NetScaler ADC Preferred) and network segmentation, including Zero Trust design principles. Strong troubleshooting capability across Layer 1–7, including incident response, root cause analysis, and performance optimization. Strong understanding of network security concepts like Zero Trust architecture, IDS/IPS, and DDoS mitigation. Experience implementing secure segmentation across on-premises and cloud environments.
- Palo Alto Networks: Hands-on experience with Palo Alto NGFW: security policy management, NAT, App-ID, User-ID, and Content-ID. Experience configuring site-to-site and remote access VPNs using Palo Alto firewalls. Experience with threat prevention, URL filtering, and WildFire services. Experience using Panorama / Strata Cloud Manager for centralized firewall management. Experience with Prisma Access (SASE), including remote user access, service connections, and identity integration. Experience with Strata Cloud Manager for policy management, visibility, logging, and analytics. Understanding of Zero Trust Network Access (ZTNA) and modern SASE architectures.
- Monitoring & Tooling: Experience with network monitoring and troubleshooting tools such as SolarWinds and Wireshark. Familiarity with SD-WAN and enterprise wireless networking.
- Collaboration & Communication: Strong communication skills with the ability to work across technical and non-technical teams. Ability to document network architecture, standards, and operational procedures. Strong analytical and problem-solving skills with attention to detail. Ability to participate in on-call rotation as needed.
Preferred Certifications
- Azure Network Engineer Associate
- Palo Alto PCNSE
- Cisco CCNA / CCNP
Nice to Have
- Strong experience with Azure networking (VNets, subnet design, IP addressing).
- Experience configuring and managing NSGs, ASGs, and Azure Firewall policies.
- Experience with Azure Load Balancer, Application Gateway, and Azure Front Door.
- Experience designing hybrid connectivity (Site-to-Site VPN, Point-to-Site VPN, ExpressRoute with BGP).
- Experience with Private Endpoints, Private Link, VNet peering, hub-and-spoke architectures, and Azure Private DNS Zones.
- Experience integrating PaaS resources with virtual networks.
- Experience using Azure Network Watcher, Connection Monitor, NSG flow logs, and packet capture.
- Scripting experience in Python, PowerShell, or Bash for automation.
- Experience with IaC tools like Terraform, ARM templates, and Bicep.
- Familiarity with YAML for configuration, pipelines, and automation workflows.
- Experience with Azure landing zones and large-scale hub-and-spoke architectures.
- Experience with enterprise SASE deployments.
- Experience in DevOps / NetDevOps environments.
- Familiarity with compliance frameworks like NIST or ISO 27001.
Key skills/competency
- Network Engineering
- Palo Alto Firewalls
- Azure Networking
- SASE Architecture
- Network Security
- TCP/IP
- BGP Routing
- VPN Management
- Network Monitoring
- Infrastructure as Code (IaC)
Skills & topics
- Network Engineer
- Palo Alto Networks
- Azure Networking
- SASE
- Network Security
- TCP/IP
- BGP
- VPN
- Network Troubleshooting
- Infrastructure as Code
- Firewall Management
- Cloud Networking
- Network Automation
- Enterprise Network
- Hybrid Cloud
How to get hired
- Tailor your resume: Highlight experience with Palo Alto, Azure, SASE, and IaC.
- Showcase relevant skills: Emphasize troubleshooting, security policy management, and scripting.
- Prepare for technical questions: Review core networking concepts and Palo Alto-specific features.
- Demonstrate collaboration: Be ready to discuss teamwork and communication with other teams.
- Express interest in CMG's mission: Connect your skills to the mortgage industry's needs.
Technical preparation
Master Palo Alto firewall configurations.,Understand Azure networking services deeply.,Practice scripting for network automation.,Review SASE and Zero Trust concepts.
Behavioral questions
Describe a complex network issue you resolved.,How do you handle urgent network incidents?,Explain your documentation process.,How do you collaborate with other teams?
Frequently asked questions
- What specific Palo Alto Networks experience is most valued for the Network Engineer role at CMG Financial?
- CMG Financial highly values hands-on experience with Palo Alto NGFW, including security policy management, NAT, App-ID, User-ID, and Content-ID. Experience configuring site-to-site and remote access VPNs, threat prevention, URL filtering, and using Panorama/Strata Cloud Manager are also key.
- Does CMG Financial prefer specific certifications for their Network Engineer position?
- While not strictly required, CMG Financial prefers candidates with certifications such as Azure Network Engineer Associate, Palo Alto PCNSE, or Cisco CCNA/CCNP. These demonstrate a commitment to professional development and validated expertise.
- What is the expected salary range for the Network Engineer role at CMG Financial?
- For residents in CA, CO, and NY, the total annual compensation for the Network Engineer role at CMG Financial ranges from $110,000.00 to $130,000.00. Salary is determined by factors including education, years of experience, and relevant industry work history.
- How important is experience with Azure networking for this Network Engineer position?
- Experience with Azure networking is very important. This includes VNets, subnet design, IP addressing strategies, NSGs, ASGs, Azure Firewall policies, and designing hybrid connectivity solutions. Familiarity with Azure Network Watcher and related tools is also beneficial.
- What kind of automation and Infrastructure as Code (IaC) experience is CMG Financial looking for in a Network Engineer?
- CMG Financial seeks Network Engineers who can write or maintain scripts in PowerShell, Python, or Bash for operational tasks. Experience updating Terraform configurations for infrastructure changes and validating/planning deployments is also desired.
- What are the core networking skills required for this Network Engineer role?
- Core networking skills include a deep understanding of TCP/IP, subnetting, routing, switching, VLANs, DNS, and DHCP. Experience with Cisco switches, BGP, firewalls (rules, NAT, VPNs), load balancing, and network segmentation are also essential.
- Can you describe the work arrangement for the Network Engineer position at CMG Financial?
- The Network Engineer position operates in an ADA-compliant office environment. While the description doesn't explicitly state 'remote' or 'hybrid', it implies an on-site presence with the mention of office equipment and typical office tasks. Flexibility for overtime is also noted.