{"id":1488551,"url":"https://alion.io/job/celestica-technical-lead-it-infrastructure","title":"Technical Lead, IT Infrastructure","company":{"id":58064,"name":"Celestica","domain":"celestica.com","url":"https://alion.io/company/celestica","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"DevOps","role_family":"DevOps","seniority":"lead","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["George Town, Malaysia"],"countries":["MY"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":19000,"max_usd":46000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":602},"experience_years_min":14,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CentOS Stream","optional":false},{"name":"Crowdstrike","optional":false},{"name":"CyberArk","optional":false},{"name":"Hyper-V","optional":false},{"name":"Linux","optional":false},{"name":"ServiceNow","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"Tcpdump","optional":false},{"name":"Ubuntu","optional":false},{"name":"VLAN","optional":false},{"name":"VMWare","optional":false},{"name":"Wireshark","optional":false},{"name":"Zero Trust","optional":false},{"name":"Zscaler","optional":false}],"status":"live","first_seen_at":"2026-09-30T00:05:22Z","employer_posted_date":null,"last_verified_at":"2026-09-30T00:05:22Z","board_verified":false,"closed_at":null,"days_open":2,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":2},"description":"Req ID: 137478\n\nRemote Position: Hybrid\n\nHiring Manager: Paul Stanners\n\nBand: 10\n\nRegion: Asia\n\nCountry: Malaysia\n\nState/Province: Bayan Lepas\n\nCity: Penang\n\nGeneral Overview\n\nFunctional Area: Information Technology (ITM)\n\nCareer Stream: IT Infrastructure (INFR)\n\nRole: Technical Lead (TEL)\n\nJob Title: Technical Lead, IT Infrastructure\n\nJob Code: TEL-ITM-INFR\n\nJob Level: Level 10\n\nDirect/Indirect Indicator: Indirect\n\nSummary\n\nWe are seeking a proactive and detail-oriented RDL Network Administrator to manage the day-to-day operations and administration of our global Research and Development Lab (RDL) networks. Reporting directly to the Lead Network Architect, you will be responsible for the run-and-maintain aspects of our isolated, air-gapped networks across multiple HPS Design Center locations (including San Jose, Richardson, Thailand, Shanghai, SongShan Lake, Penang, Chennai, and future sites).\n\nThis role uniquely focuses on cutting-edge open networking. The majority of our RDL network infrastructure runs on SONiC (Software for Open Networking in the Cloud) deployed on Celestica's own high-performance network switches. Furthermore, security inside the air-gap relies heavily on Zscaler technology acting as internal firewalls integrated with local VLANs for precise, policy-driven access control.\n\nSince this environment operates under strict security isolation without typical enterprise automated management tools, this role requires a hands-on, highly disciplined administrator who excels at executing manual and semi-automated workflows securely and consistently. Traditional Cisco-based networking skills are considered secondary to expertise in SONiC, Linux networking, and Zscaler-driven zero-trust security.\n\nThis role requires regular on-site presence within the RDL environment and participation in a 24x7 on-call rotation supporting global RDL infrastructure, including after-hours incident response and scheduled maintenance activities.\n\nCore Responsibilities\n\n SONiC & Open Network Operations\nSONiC Infrastructure Management: Monitor, configure, and maintain the health, performance, and uptime of Celestica's proprietary open network switches running the SONiC operating system.\nConfiguration & Segmentation: Implement localized VLAN adjustments, IP address allocations, and switch port provisioning within the SONiC environment to isolate multi-tenant engineering projects.\nRoutine Maintenance: Execute hardware diagnostics, physical cabling checks, and SONiC OS/firmware updates following strict maintenance window guidelines.\nSecondary Infrastructure Support: Perform operational support, troubleshooting, and maintenance of legacy secondary network components, including Check Point 3980 firewalls, Silver Peak SD-WAN appliances, and Cisco Catalyst 9400/9200 switches as required.\n Zscaler & Internal Security Policy Administration\nZero-Trust Internal Firewalling: Administer and configure Zscaler ZTNA / App Connectors to serve as internal firewalls, establishing secure boundaries and controlling data flow across isolated local VLANs.\nAccess Control & Identity: Provision local user accounts, configure role-based permissions, and manage decentralized credentials on Linux-based jump hosts.\nRemote Session Security: Manage secure engineer connections using CyberArk vPAM (Virtual Privileged Access Management).\nSecurity Auditing: Conduct weekly audits of active user sessions, ACL configurations, and local accounts to maintain an uncompromising security posture.\n Data Transfer & Repository Sync Operations\nMulti-Tier Sync Execution: Execute and monitor the secure transfer of transfer bundles containing OS packages (Rocky Linux, Ubuntu, CentOS, etc.), drivers, and software libraries across the physical air gap.\nRepository Services Administration: Ensure repository services remain operational, synchronized, and accessible to authorized systems within segmented and isolated RDL environments.\nIntegrity Validation: Verify cryptographic hashes (SHA-256 checksums) of all data packages moving from the Global Repository Server to the RDL Local Repository Server.\n Support Ticket Resolution & SLA Adherence\nEnd-User Support: Act as the primary technical point of contact for HPS design engineers needing open network troubleshooting, VLAN routing resolution, or new package requests.\nTicketing Operations: Process, update, and resolve secure lab support tickets in accordance with established Service Level Agreements (SLAs).\nEscalation Point: Identify complex open-networking bugs, design deviations, or routing limitations and escalate them directly to the Lead Network Architect.\n Compliance & Environment Enforcement\nSoftware Auditing: Conduct regular logical audits of systems within the RDL to ensure strictly banned corporate agents (e.g., CrowdStrike, Threat Locker, Big Fix, ServiceNow Agents, ClearPass NAC) are not installed.\nAsset Tracking: Maintain a flawless inventory of all HPS-owned assets inside the RDL physical rooms, including servers, switches, wireless access points (Aruba 755), and connected lab machines.\n\nKnowledge/Skills/Competencies\n\nRequired Technical Skills\n\nNetwork & Security Hardware: Practical experience configuring and troubleshooting Layer 2 and Layer 3 network environments including VLANs, routing, ACLs, packet capture analysis, and protocol troubleshooting using tools such as Wireshark and tcpdump.\nMonitoring & Visibility: Experience with SNMP-based monitoring and alerting platforms such as SolarWinds, including device health monitoring, performance analysis, fault identification, and capacity trending.\nLinux System Administration: Mid-to-senior level Linux administration experience including user management, shell scripting, package management, service administration, repository hosting, and network troubleshooting.\nAccess Tools: Experience working with remote access tools such as Zscaler ZTNA / App Connectors and Privilege Access Management solutions (specifically CyberArk).\nVirtualization Administration: Experience provisioning, maintaining, and troubleshooting virtual machines, clustered hosts, storage resources, and virtual networking within VMware vSphere, Nutanix AHV, and/or Microsoft Hyper-V environments.\nAir-Gap Protocols: Working knowledge of secure file transfer protocols (SFTP, SCP, rsync) and security scanning methodologies.\n\nPreferred Certifications\n\nCCNA (Cisco Certified Network Associate)\nCheck Point Certified Security Administrator (CCSA)\nCompTIA Security+ or Linux+\nCyberArk Certified Trustee or Defender\n\nSoft Skills & Working Style\n\nHigh Operational Discipline: Ability to strictly adhere to Standard Operating Procedures (SOPs) without cutting corners, even during urgent troubleshooting.\nExcellent Communicator: Strong written and verbal communication skills, necessary for translating technical issues to designers and coordinating with corporate security teams.\nMulti-Tasker: Capable of balancing ticket requests from multiple global labs concurrently while maintaining accurate records.\n\nPhysical Demands\n\nDuties of this position are performed in a normal office environment.\nDuties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.\n\nEducation & Experience\n\nBachelor's degree in Network Administration, Information Technology, Computer Science, or equivalent hands-on experience.\n4+ years of experience in network administration or system administration, preferably managing secure, segmented, or laboratory networks.\nOverall 14+years of work experience is required.\n\nNotes\n\nThis job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.\n\nCelestica is an equal opportunity employer. All qualified applicants will receive consideration for employment and will not be discriminated against on any protected status (including race, religion, national origin, gender, sexual orientation, age, marital status, veteran or disability status or other characteristics protected by law).\n\nAt Celestica we are committed to fostering an inclusive, accessible environment, where all employees and customers feel valued, respected and supported. Special arrangements can be made for candidates who need it throughout the hiring process. Please indicate your needs and we will work with you to meet them.","description_format":"text","description_chars":8628,"description_truncated":false,"requirements":{"experience_years_min":14,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Supply Chain"],"lifecycle":[{"event":"open","at":"2026-09-30T00:05:22Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":24,"reasons":["seen:1","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/celestica-technical-lead-it-infrastructure","json_url":"https://alion.io/job/celestica-technical-lead-it-infrastructure.json","meta":{"generated_at":"2026-10-02T02:49:40Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3821,"day_limit":5000,"remaining_today":1179,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}