Senior F5 Consultant / Network & Security Engineer

About Sparx Solutions

Sparx Solutions is a leading Australian provider of cybersecurity and IT infrastructure solutions, delivering to enterprise and government clients.

We’ve been recognised in AFR Fast Starters, CRN Fast 50, and as a Juniper Emerging Partner of the Year, and we continue to grow through delivering complex, high-quality outcomes for our customers.


Location: Melbourne
Start Date: Immediate
Engagement: Contract


About the Role

We are seeking an experienced Senior F5 Consultant to take technical ownership of a turn-key migration of a critical Victorian transport infrastructure client's F5 BIG-IP platform from end-of-life physical appliances to F5 BIG-IP Virtual Edition (VE).

This is a full-lifecycle engagement, not just a build. You will run discovery, produce the target-state design, plan and execute the migration, integrate the platform into the enterprise environment, uplift application security with APM and ASM/Advanced WAF, and hand a fully documented, operationally supportable platform to the client's Network and Security team.


What you'll be doing

  • Discovery and assessment of the existing physical BIG-IP estate, including the three logically isolated vCMP guests (DMZ, Corporate and Engineering), and documenting the current-state architecture.
  • Developing the High-Level Design (HLD) and Low-Level Design (LLD) for the target BIG-IP VE platform.
  • Designing and building three isolated BIG-IP VE high-availability pairs (one per security zone) on VMware ESXi with a vSphere Distributed Switch, including anti-affinity, failover and connection mirroring.
  • Migrating LTM configuration on a like-for-like basis: virtual servers, pools, monitors, iRules and traffic policies, SSL profiles and certificates, VLANs and self-IPs, and HA/device trust relationships.
  • Network and security integration: VLANs and trunking, routing and path validation, northbound/southbound connectivity, and firewall and security policy alignment across zones.
  • Integrating the platform with the enterprise backup solution (Commvault), configuring scheduled configuration backups, and performing and documenting a backup and restoration test.
  • Developing the migration strategy, rollback and contingency procedures, type testing, and the transition and cutover plan.
  • Executing after-hours production cutovers on an application-by-application and domain-by-domain basis using a DNS-based cutover approach, with rollback readiness at every stage.
  • Supporting User Acceptance Testing and target-state validation through to operational acceptance.
  • Implementing BIG-IP APM and ASM/Advanced WAF to uplift a legacy application: identity-aware pre-authentication, integration with the enterprise identity platform, MFA and SSO, plus WAF policy covering OWASP Top 10, bot defense and L7 DoS, using phased transparent-to-blocking enforcement.
  • Decommissioning the legacy platform, producing as-built documentation and operational runbooks, and delivering knowledge transfer to the client's operations team.

What you'll bring

  • Deep, hands-on F5 BIG-IP engineering experience, with LTM essential and APM and ASM/Advanced WAF highly regarded.
  • Demonstrated experience migrating physical BIG-IP appliances (ideally vCMP-based) to BIG-IP Virtual Edition.
  • Strong VMware vSphere/ESXi skills, including distributed switching, port groups and the networking requirements of virtual appliances.
  • Solid core networking: L2/L3, VLANs, routing, NAT, DNS, and SSL/TLS with certificate lifecycle management.
  • Intermediate to expert level firewall engineering skills across Cisco and Palo Alto platforms, including security policy design, rule implementation, NAT and troubleshooting across segmented zones, to support the network and firewall integration activities.
  • Practical experience with iRules, traffic policies, profiles, health monitors and persistence.
  • Sound understanding of F5 high availability: device service clustering, traffic groups, floating self-IPs and VIPs, and failover behaviour.
  • Experience working within formal change control, including planning and executing after-hours change windows in production environments.
  • Strong documentation ability across HLD, LLD, runbooks and as-built material, and the consulting skills to lead workshops and engage senior stakeholders.
  • Availability to work scheduled after-hours cutover windows.

Desirable

  • F5 certifications (F5 Certified Technology Specialist LTM, and/or Security Solution Expert).
  • APM integration with enterprise identity platforms such as Microsoft Entra ID, Okta or Duo, and delivering MFA/SSO for legacy applications that cannot support modern authentication.
  • Experience integrating network infrastructure with enterprise backup platforms such as Commvault.
  • Background in rail, transport, utilities, government or other critical infrastructure environments.
  • Experience collaborating alongside vendor professional services teams.

The engagement

  • Contract length: approximately 8 months (circa 159 working days end to end), aligned to a defined work-package schedule with stage gates and go/no-go decision points.
  • Location: Melbourne based, hybrid, with on-site attendance for workshops, build and cutover activities.
  • Hours: business hours, with scheduled after-hours windows for production migration and cutover activity.
  • Day rate: negotiable, commensurate with experience.


Why this role

This is a high-visibility program on a platform that underpins critical services. You will own the technical outcome end to end, work across the full delivery lifecycle from discovery through to operational handover, and deliver a genuine security uplift rather than a lift-and-shift.

Professional Services​

Docklands, Australia

Deel met:

Algemene voorwaardenPrivacyCookiesPowered by Rippling