This is the section where round two of the screen actually happens, the closing gate before an
interview hits your inbox. A recruiter takes their time here, and even at that, the current
role still drives around 95% of the result.
That tracks: nothing proves what you can run in production today like the seat you sit in
right now. To earn a "yes", the section has to hit every entry on the
Network Engineer role profile, one bullet per domain you named in Domain
Expertise above. Every bullet has to come off something you genuinely held in production,
never a ticket that landed on your queue.
1
Network Architecture & Topology Design
The flagship work of the role. Show the network you designed end to end (campus, data
center, WAN, hybrid cloud), the redundancy posture, and the workloads riding on top of it.
Name the design and what it now carries, not "designed networks".
Techniques
Spine-leaf fabric
Hub-and-spoke WAN
Redundancy & failover
IPAM & subnetting
Tools
Cisco NX-OS, Arista EOS
Juniper Junos
NetBox, Infoblox
Metrics
Sites brought online
Devices designed
Network availability
2
Routing & Switching
The protocol-level work that keeps traffic flowing. Show the routing fabric you turned up
(BGP, OSPF, EIGRP), the VLAN / VXLAN segmentation, and the cutover or upgrade you led
through change windows. Name the protocol and what it now carries, not "worked on
routing".
Techniques
BGP / OSPF / EIGRP
VLAN / VXLAN / STP
MPLS / MP-BGP
QoS policy
Tools
Cisco Catalyst, Nexus
Arista 7000 series
Juniper EX, MX
Metrics
Routes & prefixes
Convergence time cut
Cutovers led
3
Network Security & Firewalls
What keeps the perimeter and the segmentation enforced. Show the firewall platform you run,
the policy you authored, and the VPN or zero-trust posture behind it. Name the platform
and the policy you set, not "managed firewalls".
Techniques
Zone-based policy
Site-to-site & remote VPN
NAC / 802.1X
Zero-trust segmentation
Tools
Palo Alto PAN-OS
Fortinet FortiGate
Check Point, Cisco ASA/FTD
Metrics
Firewalls under management
Rules consolidated
Audit findings closed
4
Load Balancing & Application Delivery
How the network keeps services available under load. Show the load-balancer platform you
run, the SSL/TLS posture, and the pool or virtual-server configuration behind a specific
application. Name the application and what it now carries, not "managed load
balancers".
Techniques
L4 / L7 load balancing
SSL / TLS offload
GSLB / DNS-based
iRules / VCL
Tools
F5 LTM / GTM
NGINX, HAProxy
A10, AWS ALB/NLB
Metrics
Apps fronted
Latency cut
Availability lifted
5
Wireless & SD-WAN
How the network reaches the edge. Show the wireless platform you operate (controllers, APs,
survey work) and the SD-WAN program you ran (cutover from MPLS, branch consolidation,
cost savings). Name the platform and the scope, not "wireless and SD-WAN".
Techniques
Wireless site surveys
Controller / cloud-managed APs
SD-WAN cutovers
Branch consolidation
Tools
Cisco Meraki, Aruba
Ekahau, AirMagnet
Cisco Viptela, Versa, Silver Peak
Metrics
Sites migrated
WAN cost cut
Wireless coverage uplifted
6
Network Automation & IaC
What takes the network estate out of manual CLI and into versioned code. Show the
automation tooling you built (Ansible playbooks, Netmiko scripts, NAPALM workflows), the
CI process you put on every config change, and the devices now managed from code. Name
the workflow and what it replaced, not "wrote scripts".
Techniques
Config templating (Jinja)
Network CI / pre-checks
Source-of-truth (NetBox)
Drift detection
Tools
Ansible / Nornir
Netmiko, NAPALM
Batfish, Suzieq
Metrics
Devices under code
Manual config cuts
Change-window time reduced
7
Monitoring, Telemetry & Performance
What turns a bad network day into a closed ticket. Show the monitoring stack you stood up,
the streaming telemetry feed you wired in, and the performance regression you found and
fixed. Name the system and the regression you closed, not "monitored the
network".
Techniques
SNMP / NetFlow / sFlow
Streaming telemetry (gNMI)
Packet capture & analysis
Path tracing
Tools
SolarWinds, LibreNMS
Prometheus / Grafana
Wireshark, ThousandEyes
Metrics
MTTR cut
Alert noise reduced
Latency & jitter held
8
Tooling & Workflow
The setup that lets a small network team run a multi-site estate. Show the change workflow
you defend, the source-of-truth system you maintain, and the docs that cut on-call ramp.
Name the workflow, not "a modern stack".
Techniques
Change advisory boards
Source-of-truth / NetBox
Runbook libraries
On-call rotation
Tools
Git, GitLab
ServiceNow, Jira
Confluence, Notion
Metrics
Change requests fulfilled
PR cycle time
On-call ramp cut