Senior Network Engineer
We usually respond within three days
Who we are
Ilkari is a privately-held start-up based in Dublin, Ireland. We deliver hyper-private scale innovation and technology to safeguard and secure data, enabling true data sovereignty even as the pace of change accelerates. Our best-in-breed sovereign technology delivers privacy and control over where companies’ data resides, where it flows, and how it’s accessed.
We’re here to rewrite the story of data sovereignty – empowering innovators, pioneers and visionaries to make their mark. We believe the sky is not the limit. We strive for the perfect balance of simplicity and excellence in everything we do, and we’re looking for people who are ready to join our journey and rewrite the story of data sovereignty.
Role overview
We are seeking a Senior Network Engineer (L3) to design, implement, and operate resilient, high-performance, and cost-efficient network infrastructure that supports both internal platforms and customer-facing services.
Operating at Layer 3 escalation and engineering depth, this role is part of a collaborative engineering team responsible for delivering robust, scalable, and secure network solutions. The successful candidate will contribute to and influence network designs through governance forums (TDA / peer review), produce and implement High-Level and Low-Level Design (HLD/LLD) documentation, and adhere to structured Service Design and Service Transition principles.
The role includes the delivery of modern spine-leaf and perimeter network architectures, with a strong focus on operational readiness, scalability, and long-term maintainability.
This is a hands-on senior engineering position focused on technical depth, implementation, and operational excellence. It is not an architecture-only role, nor is it a ticket-based NOC position.
What you'll do
• Contribute to peer-reviewed network designs and implement approved HLD/LLD artefacts to ensure scalable, resilient, and standards-aligned infrastructure is delivered correctly the first time.
• Deploy and validate spine-leaf and enterprise routing architectures to support high-performance data centre and customer environments without introducing instability or technical debt.
• Adhere to governance frameworks (TDA, peer reviews, change control) to prevent uncontrolled configuration drift and ensure long-term maintainability.
• Engineer and optimise complex routing environments (BGP, OSPF, EIGRP, MPLS, advanced L2/L3 protocols) to guarantee deterministic failover, predictable convergence, and sustained network stability at scale.
• Diagnose and resolve deep routing and switching issues at Layer 3 to minimise downtime, eliminate recurring faults, and protect service availability.
•Engineer and administer enterprise firewall platforms (Palo Alto, Fortinet, Cisco) to enforce structured, secure, and auditable perimeter controls that protect customer and internal services.
• Design and maintain clean, segmented network zones and rule bases to reduce attack surface, prevent rule sprawl, and support evolving security strategy.
• Lead technical investigations during high-severity outages to protect platform resilience and restore service with confidence and precision.
• Produce and maintain accurate HLD/LLD documentation, topology diagrams, and configuration standards to eliminate tribal knowledge and enable operational readiness from Day 1.
• Ensure all network changes transition through Service Design, Service Transition and Change Management principles to avoid undocumented risk and operational fragility.
• Identify and implement automation opportunities to reduce manual configuration risk, improve deployment consistency, and increase engineering efficiency at scale.
• Continuously review network performance, resilience, and cost posture to improve reliability while optimising infrastructure spend.
What are we looking for
Technical Skills
• 7+ years hands-on network engineering experience in enterprise, service provider, or data centre environments.
• Demonstrated ownership of production routing and switching environments, not limited to support or monitoring roles.
• Proven experience implementing and supporting BGP, OSPF, MPLS, and advanced Layer 2/3 architectures in live environments.
• Experience deploying or operating spine-leaf data centre fabrics.
• Hands-on experience administering and engineering enterprise firewall platforms (Palo Alto, Fortinet, Cisco ASA or equivalent).
• Experience operating as a Tier 3 escalation point, leading deep technical diagnostics and contributing to root cause analysis.
• Experience working within structured engineering frameworks involving HLD, LLD, peer review, and controlled service transition.• Strong documentation, runbook and process design skills.
• Exposure to automation or configuration standardisation practices in network environments.
Experience & education
Strongly preferred
• Cisco CCNP Enterprise (or equivalent advanced routing certification)
• PCNSE (Palo Alto Networks Certified Network Security Engineer) or equivalent Fortinet certification (e.g., NSE4/NSE7)
Highly regarded
• Cisco CCIE (any track)
• Fortinet NSE7 or above
• Relevant MPLS or Service Provider certifications
Soft Skills
• Very good problem-solving skills, open mind towards feedback, and can-do attitude.
• Self-motivated and self-managing, with excellent organisational skills.
• Clear communication, documentation, and cross-team collaboration skills.
What's in it for you
• Private life and health insurance for you and your family.
• Four weeks per year to work from anywhere for eligible employees.
• Gym reimbursement.
• Company bus applicable for employees based in Málaga city.
• Learning Pocket for personal development.
• A hybrid working model with flexible hours.
• 3 volunteering paid days each year.
• Generous referral bonus programme.
- Department
- Product Development
- Locations
- Málaga (Spain)
- Remote status
- Hybrid
- Employment type
- Full-time