UK Health Security Agency
Senior Specialist Engineer - Networks

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Birmingham, Leeds, Liverpool or London (Canary Wharf)
Job Summary
The Senior Specialist Engineer – Networks is a senior technical role responsible for delivering and maintaining excellence across the network infrastructure estate. The post holder acts as a subject matter expert and network architect, driving the design and evolution of the network environment, providing expert-level technical leadership during major incidents, and working across multi-disciplinary teams to ensure network services underpin the organisation's operational and scientific mission.
Working alongside the Network Manager, the post holder ensures all systems are optimally configured, resilient, secure, and performant. Beyond day-to-day operational responsibilities, the role carries explicit accountability for network architecture, strategic design, and cross-functional incident response.
This role also attracts a market pay supplement of £6650 per annum (to be reviewed in February 2027).
Working for your organisation
We pride ourselves as being an employer of choice, where Everyone Matters promoting equality of opportunity to actively encourage applications from everyone, including groups currently underrepresented in our workforce.
UKHSA ethos is to be an inclusive organisation for all our staff and stakeholders. To create, nurture and sustain an inclusive culture, where differences drive innovative solutions to meet the needs of our workforce and wider communities. We do this through celebrating and protecting differences by removing barriers and promoting equity and equality of opportunity for all.
Please visit our careers site for more information https://gov.uk/ukhsa/careers
Job Description
- Own and maintain a comprehensive and current understanding of the network architecture, acting as an authoritative technical reference for network design decisions.
- Maintain consistent availability and performance across specialist network systems, collaborating with other specialist engineers and ICT colleagues as required.
- Act as a primary network technical authority during major incidents, coordinating resolution activity across multi-disciplinary teams including infrastructure, security, application, and service management functions.
- Act as a technical point of expertise, providing advice, guidance, and training to improve and enhance services for end users.
- Support the Network Team in ensuring hardware, software, and associated technologies are designed, procured, and delivered efficiently and cost-effectively.
- Contribute to and lead the production of network architecture documentation, including High Level Designs (HLD), Low Level Designs (LLD), and As-Built records.
Network Architecture, Design & Delivery
- Act as the senior technical lead for UKHSA network architecture, owning and maintaining High Level Designs (HLD), Low Level Designs (LLD), topology diagrams and As-Built documentation.
- Lead the design, implementation and lifecycle management of resilient, scalable and secure LAN, WAN, WLAN and cloud-connected infrastructure, ensuring alignment with NCSC Secure by Design principles.
- Provide technical assurance across estate modernisation, science campus, data centre and hybrid cloud programmes, while collaborating with infrastructure, security, application and cloud teams.
- Manage routing, switching, wireless, WAN, load balancing, IPAM, DNS and DHCP services, alongside Extreme Networks Fabric Engine, Site Engine and wireless platforms.
Network Security, Resilience & Incident Management
- Provide technical leadership for network security and operational resilience across the UKHSA estate.
- Administer Palo Alto NGFW, Panorama, VPN, micro-segmentation, DMZ and Zero Trust architectures, ensuring compliance with security standards and evolving threat landscapes.
- Act as the senior network authority during Major Incident Response Team (MIRT) activities, leading diagnosis, resolution, communication, Root Cause Analysis (RCA) and Post Incident Reviews (PIR).
- Develop incident runbooks, continuity plans and mitigation strategies to reduce risk, improve service resilience and support secure cloud and on-premises environments.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Service Management, Automation & Technical Leadership
- Lead the monitoring, observability, performance and capacity management of network services, integrating operational and security monitoring with ITSM and SIEM platforms.
- Drive network automation and Infrastructure as Code using tools such as Ansible and Python to improve consistency and efficiency.
- Manage vendor relationships, technology lifecycles, procurement planning and proof-of-concept evaluations.
- Produce technical documentation, support ITIL Incident, Problem, Change and Request Management processes, contribute to CAB activities, mentor engineers, provide expert stakeholder advice, maintain compliance with ICT standards and deliver high-quality customer support, including participation in on-call and out-of-hours services.
This is not an exhaustive list.
Own and maintain a comprehensive and current understanding of the network architecture, acting as an authoritative technical reference for network design decisions. Maintain consistent availability and performance across specialist network systems, collaborating with other specialist engineers and ICT colleagues as required. Act as a primary network technical authority during major incidents, coordinating resolution activity across multi-disciplinary teams including infrastructure, security, application, and service management functions. Act as a technical point of expertise, providing advice, guidance, and training to improve and enhance services for end users. Support the Network Team in ensuring hardware, software, and associated technologies are designed, procured, and delivered efficiently and cost-effectively. Contribute to and lead the production of network architecture documentation, including High Level Designs (HLD), Low Level Designs (LLD), and As-Built records.
Network Architecture, Design & Delivery
Act as the senior technical lead for UKHSA network architecture, owning and maintaining High Level Designs (HLD), Low Level Designs (LLD), topology diagrams and As-Built documentation. Lead the design, implementation and lifecycle management of resilient, scalable and secure LAN, WAN, WLAN and cloud-connected infrastructure, ensuring alignment with NCSC Secure by Design principles. Provide technical assurance across estate modernisation, science campus, data centre and hybrid cloud programmes, while collaborating with infrastructure, security, application and cloud teams. Manage routing, switching, wireless, WAN, load balancing, IPAM, DNS and DHCP services, alongside Extreme Networks Fabric Engine, Site Engine and wireless platforms.
Network Security, Resilience & Incident Management
Provide technical leadership for network security and operational resilience across the UKHSA estate. Administer Palo Alto NGFW, Panorama, VPN, micro-segmentation, DMZ and Zero Trust architectures, ensuring compliance with security standards and evolving threat landscapes. Act as the senior network authority during Major Incident Response Team (MIRT) activities, leading diagnosis, resolution, communication, Root Cause Analysis (RCA) and Post Incident Reviews (PIR). Develop incident runbooks, continuity plans and mitigation strategies to reduce risk, improve service resilience and support secure cloud and on-premises environments.
Service Management, Automation & Technical Leadership


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Lead the monitoring, observability, performance and capacity management of network services, integrating operational and security monitoring with ITSM and SIEM platforms. Drive network automation and Infrastructure as Code using tools such as Ansible and Python to improve consistency and efficiency. Manage vendor relationships, technology lifecycles, procurement planning and proof-of-concept evaluations. Produce technical documentation, support ITIL Incident, Problem, Change and Request Management processes, contribute to CAB activities, mentor engineers, provide expert stakeholder advice, maintain compliance with ICT standards and deliver high-quality customer support, including participation in on-call and out-of-hours services.
This is not an exhaustive list.
Person specification
Essential Criteria
- Formal technical qualification equivalent to CCNP level or above, or substantial experience in a senior network engineering role, with advanced knowledge of enterprise routing and switching, network security, wireless technologies, and large-scale network infrastructure management.
- Proven experience producing and maintaining network architecture artefacts, including High Level Designs (HLDs), Low Level Designs (LLDs), topology diagrams, reference architectures, and As-Built documentation across enterprise LAN, WAN, WLAN, and security environments.
- Demonstrable ability to lead or contribute to network architecture initiatives, provide technical assurance and design reviews, and ensure solutions align with organisational standards, security-by-design principles, and best practice methodologies.
- Significant experience acting as a senior technical authority during major incidents, leading network diagnosis and resolution activities, collaborating within multi-disciplinary Major Incident Response Teams, and managing complex, high-pressure situations.
- Experience producing Root Cause Analysis (RCA) reports, Post-Incident Reviews (PIRs), and maintaining incident runbooks, playbooks, and escalation procedures while driving continuous service improvement and reducing recurrence of critical incidents.
- Skilled in monitoring network infrastructure to optimise performance, support capacity planning, identify risks, and proactively address technical issues to maintain service availability and resilience for large user populations.
- Excellent written, verbal, reporting, and presentation skills, with the ability to communicate complex technical concepts to both technical and non-technical audiences, work effectively across multidisciplinary teams, deliver outstanding customer service, and manage competing priorities under changing timescales.
Desirable criteria
- Experience with network Function Virtualisation (NFV) and Software Defined Networking (SDN) architectures, including overlay/underlay design models and virtual network appliance deployment.
- Experience with advanced network automation toolchains including Terraform, Ansible, or Python-based frameworks applied to infrastructure provisioning and compliance enforcement.
- Hands-on experience with SIEM platforms (e.g. Splunk, Microsoft Sentinel) in the context of network security monitoring, alert triage, and threat hunting.
- Experience with Zero Trust technologies such as Zscaler ZIA/ZPA, Illumio, or equivalent ZTNA platforms in an enterprise deployment context.
- Familiarity with network observability tools such as ThousandEyes, NetBrain, or Datadog Network Performance Monitoring for advanced path analysis and synthetic monitoring.
- Experience with ITSM platforms (e.g. ServiceNow or equivalent) including use of the platform for major incident management, problem records, and change advisory workflows
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location