Subject Matter Expert (Support&Ops)
About this role
Job Summary
HCLTech is seeking two experienced professionals under one integrated critical role covering hybrid cloud and enterprise networking, multi-vendor firewall and VPN engineering, and controlled change execution. The team will provide senior technical ownership across on-premises, data-center and public-cloud environments, resolve complex incidents, lead root-cause analysis, deliver high-risk changes, strengthen security and operational resilience, and mentor L1/L2 engineers.
Key Responsibilities
- Act as a senior escalation point for complex and high-severity network, cloud, firewall and VPN incidents and drive service restoration within agreed operational targets.
- Own technical assessment, design validation, implementation planning, test evidence, rollback planning and post-change validation for high-risk changes.
- Perform deep root-cause analysis and produce permanent corrective actions, technical reports, standards, SOPs, runbooks, HLDs and LLDs.
- Collaborate with cloud, security, systems, application, service-management, carrier and vendor teams on cross-domain initiatives and incidents.
- Drive automation, configuration compliance, operational standardisation, capacity planning, technology lifecycle and continuous service improvement.
- Mentor L1/L2 engineers, review technical changes and participate in critical escalation or on-call support as required.
Skill Requirements
Experienced Change Management and Cloud Level 3 (L3) Network Engineer to serve as the highest technical escalation point for our enterprise and data center network estate, spanning on-premises infrastructure and public cloud (Azure, AWS, and/or GCP). The successful candidate will own complex incident resolution, network architecture and design input, change implementation, and root-cause analysis across routing, switching, WAN/MPLS, data center fabric, and cloud networking domains. This is a senior, hands-on role that combines deep protocol-level troubleshooting with design ownership and mentoring of L1/L2 engineers. Primary Skills (Must-Have) Cloud Networking (Azure / AWS / GCP) • Design and operate cloud network architectures on at least one major provider, with working knowledge of at least two: ▪ Azure — VNets, VNet peering, ExpressRoute, Azure Firewall, NSGs/UDRs, Virtual WAN, Private Link/Private Endpoints, Load Balancer/Application Gateway. ▪ AWS — VPCs, Transit Gateway, Direct Connect, VPC peering, Route 53, Security Groups/NACLs, PrivateLink, NAT/Internet Gateways, ELB/NLB. ▪ GCP — VPCs, Cloud Router, Cloud Interconnect, VPC peering, Cloud NAT, Cloud Load Balancing, firewall rules. • Hybrid connectivity design and troubleshooting (site-to-cloud VPN, dedicated interconnect, SD-WAN to cloud on-ramps). • Cloud routing integration with on-prem BGP peering and route propagation. WAN & Service Provider Routing • MPLS: L3VPN/L2VPN, VRFs, MP-BGP, route distinguishers/route targets, PE-CE routing, QoS across the WAN, and troubleshooting provider MPLS services. • BGP: eBGP/iBGP design and operation, route reflectors, communities, AS-path and prefix-list policy, route filtering, path selection/manipulation, dampening, and large-scale BGP troubleshooting. Interior Routing (IGP) • OSPF: multi-area design, area types (stub/NSSA), LSA types, DR/BDR behavior, route summarization, redistribution, and convergence tuning. • Working knowledge of additional IGPs (e.g., IS-IS, EIGRP) is an advantage. • Route redistribution and mutual redistribution between IGP/BGP/MPLS with loop prevention. Enterprise LAN & Switching • Campus/enterprise LAN design and operations: VLANs, STP/RSTP/MSTP, VTP, EtherChannel/LAG, inter-VLAN routing. • First-hop redundancy protocols (HSRP/VRRP/GLBP). • Access-layer security: 802.1X, port security, DHCP snooping, dynamic ARP inspection. • Wireless LAN fundamentals (controller-based and cloud-managed) an advantage. Data Center (DC) Networking • Data center fabric design and operations: spine-leaf architectures, VXLAN/EVPN, overlay/underlay networking. • DC technologies such as Cisco ACI, Nexus (NX-OS), vPC, and fabric troubleshooting. • Understanding of DC interconnect (DCI), workload mobility, and east-west/north-south traffic patterns. Secondary / Supporting Skills • Network Security: Firewalls (Palo Alto, Cisco ASA/Firepower, Fortinet, Check Point), IPsec/GRE VPNs, ACLs, zone-based policy, NAT. • SD-WAN: Meraki, Versa, or equivalent. • Network Services: DNS, DHCP, NTP, IPAM. • Automation & Tooling: Python and/or Ansible for network automation; familiarity with REST APIs, Terraform (for cloud networking), Git. • Monitoring & Observability: SolarWinds, PRTG, ThousandEyes, NetFlow/sFlow, syslog/SNMP, packet capture and analysis (Wireshark, tcpdump). • QoS: design and troubleshooting across LAN/WAN. • IPv4/IPv6: addressing, subnetting, and dual-stack operations. Key Responsibilities • Act as the final internal escalation point (L3) for complex, high-severity network incidents across LAN, WAN/MPLS, data center, and cloud. • Perform deep root-cause analysis (RCA) and produce post-incident reports with permanent corrective actions. • Design, review, and validate network changes; own high-risk change implementation during maintenance windows. • Contribute to network architecture
Other Requirements
Supporting Skills
- Network security with Palo Alto, Cisco ASA/Firepower, Fortinet or Check Point; IPsec/GRE VPN, ACL, zone-based policy and NAT.
- SD-WAN technologies such as Meraki or Versa; DNS, DHCP, NTP and IPAM services.
- Python, Ansible, REST APIs, Terraform and Git for network and cloud automation.
- SolarWinds, PRTG, ThousandEyes, NetFlow/sFlow, syslog/SNMP, Wireshark and tcpdump for monitoring and analysis.
- QoS, IPv4/IPv6 addressing, subnetting and dual-stack operations.
Position 1 Deliverables
- Configure, optimise and troubleshoot BGP, OSPF, MPLS and cloud-routing integrations across LAN, WAN/MPLS, data center and cloud.
- Lead high-risk network changes, architecture and design reviews, backbone readiness, technical discussions and service-improvement projects.
- Contribute to capacity planning, technology roadmaps, network standards, configuration compliance and automation.
Frequently Asked Questions
Is the salary disclosed for the Subject Matter Expert (Support&Ops) position at HCLTech?
Where is the Subject Matter Expert (Support&Ops) position at HCLTech located?
How do I apply for the Subject Matter Expert (Support&Ops) position at HCLTech?
When was the Subject Matter Expert (Support&Ops) job at HCLTech posted?
You'll be redirected to HCLTech's official application page on successfactors.