ROLE SUMMARY
The Network Patching Tower Lead (Onshore) is the primary network interface to client NetOps/L2/L3 during Canada hours. This role owns IOS/IOS-XE/NX-OS firmware patching and security upgrades across a 147,000+ device estate — spanning Cisco core routers, campus and data center switches, Juniper devices, and F5 load balancers. Zero-tolerance for unplanned outages during change windows drives the need for expert-level Cisco expertise and deep understanding of network redundancy patterns.
ROLE IN THE OPERATING MODEL
▸ Tower/pod lead and SME for Network patching — primary network interface to client NetOps/L2/L3 during Canada hours and weekend windows
▸ Coordinates change windows with the NOC and client NetOps; owns Network tower compliance reporting
▸ Operates as network execution layer under client direction; network architecture/design changes remain client L2/L3 owned
▸ Directs offshore network SMEs during onshore hours; manages escalation within agreed SLTs
KEY RESPONSIBILITIES
▸ Plan and execute IOS/IOS-XE/NX-OS firmware upgrades and security patches for Cisco, plus Juniper Junos and F5 TMOS devices
▸ Design patching sequences leveraging redundancy — HSRP/VRRP failovers, VSS/StackWise rolling upgrades, NSF/SSO capabilities
▸ Take pre-change configuration backups (TFTP/SCP), perform staged upgrades (core → distribution → access), and validate redundancy/failover post-change
▸ Coordinate maintenance windows with the NOC and client NetOps; align to golden-config standards
▸ Maintain device EOL/EOS tracking and compliance posture; update CMDB and asset records
▸ Perform RCA for failed upgrades; execute rollback; escalate to L2/L3 NetEng and vendor (via client) as needed
▸ Track Cisco PSIRT security advisories and Field Notices; prioritise CVE-driven firmware upgrades within wave cycles
▸ Own Network tower compliance reporting; present KPIs to the Patch Service Lead for governance reviews
TECHNICAL ACTIVITIES FOR THE SCOPE
▸ Execute IOS/IOS-XE/NX-OS firmware upgrades and Cisco security patches; Juniper Junos and F5 TMOS upgrades
▸ Design redundancy-aware patching sequences — HSRP/VRRP failover, VSS/StackWise rolling, NSF/SSO validation
▸ Take config backups (TFTP/SCP); perform staged upgrades (core → distribution → access)
▸ Validate redundancy, routing protocol convergence, and spanning tree stability post-change
▸ Maintain EOL/EOS tracking; update CMDB device firmware levels; close vulnerability tickets
▸ Author RFC/CAB documentation; coordinate maintenance window scheduling with NOC and NetOps
▸ Track Cisco PSIRT and Field Notices; plan CVE-driven upgrade waves
SKILLS, TOOLS & COMPETENCIES
Primary Skills
Network Platforms | Cisco IOS/IOS-XE · Cisco NX-OS (Nexus) · Cisco ASA/FTD · Juniper Junos · F5 TMOS |
Protocols | BGP · OSPF · EIGRP · STP/RSTP/MSTP · HSRP/VRRP · VSS/StackWise · MPLS/VPN |
Patching Tools | Cisco DNA Center · Cisco Prime · TFTP/SCP image transfer · Kron/EEM scheduler · Ansible (network modules) |
Automation | Ansible (ios_command/nxos_command) · Python (Netmiko/Napalm) · NETCONF/RESTCONF · RANCID/Oxidized |
ITSM & Vuln | ServiceNow (Change/CMDB) · BMC Network Discovery · Tenable/Qualys · RFC/CAB · KEDB |
Secondary Skills
▸ Firewall and load-balancer patching — Cisco ASA/FTD upgrade, F5 TMOS upgrade procedures
▸ SD-WAN awareness and Cisco DevNet automation
▸ Splunk/Dynatrace for network event correlation
CERTIFICATIONS
Mandatory
▸ CCNP Enterprise or CCNP Data Centre (mandatory)
▸ ITIL 4 Foundation
Preferred (one or more)
▸ CCIE Enterprise or CCIE Data Centre — strong plus
▸ Juniper JNCIP/JNCIA-Junos
▸ F5 Certified Administrator (F5-CA / 201) for load-balancer estate
▸ Cisco DevNet Associate (network automation) — advantageous
NICE TO HAVE
▸ Experience patching large Cisco estates (50,000+ devices)
▸ Cisco DNA Centre and SD-Access operational familiarity
▸ Firewall policy-aware patching — ASA/FTD upgrade experience with rule-set validation
WORK MODEL & COMMITMENT
Hours | Canada business hours + weekend change window coverage |
Shift Model | Hybrid onshore; scheduled network maintenance windows |
On-Call | Yes — emergency network firmware events and routing outage escalations |
Language | English (mandatory) |
Compensation: We are offering between $60,000 – $85,000. Applications will be accepted until Aug 21, 2026.Cognizant will only consider applicants for this position who are legally authorized to work in Canada without requiring employer sponsorship, now or at any time in the future.
Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.
*Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
Über Cognizant
Cognizant (NASDAQ: CTSH) i ist ein Technologiedienstleister und Entwickler von KI-Lösungen. Wir schlagen die Brücke zwischen KI-Investitionen und echtem unternehmerischem Mehrwert, indem wir ganzheitliche Full-Stack-KI-Lösungen für unsere Kunden entwickeln. Mit unserer fundierten Branchen-, Prozess- und Engineering-Expertise integrieren wir die spezifischen Anforderungen von Unternehmen passgenau in Technologiesysteme. So entfalten wir das menschliche Potenzial, erzielen greifbare Ergebnisse und sichern globalen Unternehmen in einer sich rasant wandelnden Welt den entscheidenden Vorsprung. Erfahren Sie mehr unter cognizant.ai oder @cognizant.
Zusätzliche Informationen zur Beschäftigung
Die Vergütungsinformationen sind zum Zeitpunkt der Veröffentlichung dieser Stellenausschreibung korrekt. Cognizant behält sich das Recht vor, diese Informationen jederzeit unter Beachtung der geltenden gesetzlichen Bestimmungen zu ändern.
Bewerberinnen und Bewerber können verpflichtet sein, an Vorstellungsgesprächen persönlich oder per Videokonferenz teilzunehmen. Darüber hinaus kann es erforderlich sein, bei jedem Gespräch einen gültigen staatlichen Lichtbildausweis vorzulegen.
Cognizant ist ein Arbeitgeber mit Chancengleichheit. Ihre Bewerbung und Kandidatur werden nicht aufgrund von Rasse, Hautfarbe, Geschlecht, Religion, Glaubensbekenntnis, sexueller Orientierung, Geschlechtsidentität, nationaler Herkunft, Behinderung, genetischen Informationen, Schwangerschaft, Veteranenstatus oder sonstiger durch bundes‑, landes‑ oder kommunalrechtliche Vorschriften geschützter Merkmale berücksichtigt oder abgelehnt.







