Network engineering services
Network engineering services for offices, data centres, clouds and provider networks: routing and switching on Cisco, Juniper and Arista, firewalls from Fortinet, Palo Alto Networks and Check Point, network design, cloud networking, SD-WAN and zero-trust access, Wi-Fi and network automation, with dedicated network engineers for your team or network projects delivered end to end.
Network engineering we take on
Routing and switching
Campus, branch and core networks on Cisco, Juniper, Arista, HPE Aruba Networking or MikroTik, with OSPF and BGP routing, redundant uplinks, and configurations backed up and compared after every change.
Firewall administration
FortiGate, Palo Alto Networks, Check Point and Cisco firewalls with rule sets reviewed and cleaned up, segments between users, servers, guests and devices, site-to-site VPNs, and firmware kept on releases the vendor still supports.
Network design and documentation
Topology, addressing, VLANs and routing designed for your sites and traffic, with NetBox as the record of every device, prefix and cable, and diagrams that match what is installed.
Cloud networking
VPCs and VNets with address ranges that do not clash, hub-and-spoke networks through AWS Transit Gateway, Azure Virtual WAN or Google Cloud Network Connectivity Center, private endpoints, and Direct Connect, ExpressRoute or Cloud Interconnect links to your data centres.
SD-WAN and zero-trust access
Branches moved from MPLS to SD-WAN on Fortinet, Cisco Catalyst SD-WAN or Palo Alto Networks, and remote access moved from VPNs to zero-trust access through Zscaler, Cloudflare One, Netskope or Prisma Access.
Wireless networks
Wi-Fi designed from a site survey for coverage and capacity, WPA3 and 802.1X sign-in against your identity provider, and separate networks for staff, guests and devices.
Data centre and provider networks
Leaf-spine fabrics with EVPN-VXLAN on Arista, Cisco Nexus or Juniper, F5 BIG-IP and HAProxy load balancers, and BGP peering, MPLS and IPv6 for hosting companies, internet providers and telecom operators.
Network automation
Configurations generated and pushed by Ansible, Python or Terraform providers from NetBox as the source of truth, changes tried first on a Containerlab copy of the network, and compliance reports produced from the devices rather than written by hand.
Access control and traffic analysis
802.1X network access control with Cisco ISE or ClearPass, NetFlow and SNMP monitoring in LibreNMS, Zabbix or PRTG, and packet captures that settle whether the network or the application is at fault.
Hire network engineers
Dedicated network engineers
Network engineers who join your team full time, work in your tools and process, and report to your lead. You interview them; we carry the Ukrainian contract, payroll, invoicing and leave.
Network engineering projects
A defined piece of network engineering with a scope, a fixed plan and a named lead on our side who owns the result and reports progress in your channels.
Ongoing network engineering
Network engineering as a continuing service: the same people every month, a backlog you prioritise, and hours you can see in our portal and on the invoice.
The dedicated team page explains how specialists join your team, and the outsourcing page covers project delivery, take-overs and how we charge.
Who works on your network engineering
Network engineers
Routing, switching and network design
Network security engineers
Firewalls, VPNs and zero-trust access
Cloud network engineers
VPCs, VNets and hybrid links
Network automation engineers
Ansible, Python and NetBox
Wireless engineers
Site surveys, design and tuning
How we run networks
The network is recorded before it is changed: NetBox or your own records as the source of truth, configurations backed up and versioned, and every change planned with a rollback, approved and made in an agreed window. Where the equipment allows it, changes are pushed by automation from Git rather than typed into a console.
Access is denied by default, with segments between users, servers, guests and devices, and administrators sign in through named accounts with multi-factor authentication. On a network another team built, we start with a read-only review of configurations, firmware, rules and diagrams, and a written list of risks in order of impact. Our own cloud estate runs behind deny-by-default firewalls under the same rule.
Other cloud, DevOps and security services
AWS development
AWS development services: EKS and ECS containers, serverless, landing zones, migrations, databases, data platforms, Bedrock generative AI, security and cost optimisation, with dedicated AWS engineers or project delivery.
Google Cloud development
Google Cloud development services: Cloud Run and GKE, BigQuery, Firebase backends, Cloud SQL and AlloyDB, Gemini on Agent Platform, security and migrations, with dedicated Google Cloud engineers or project delivery.
Kubernetes consulting
Kubernetes consulting and development: clusters on EKS, AKS, GKE and on premises, Helm, GitOps with Argo CD or Flux, cluster security, upgrades and GPU workloads, with dedicated Kubernetes engineers or project delivery.
DevOps and CI/CD
DevOps and CI/CD services: pipelines, Terraform infrastructure as code, observability, SRE and on-call, DevSecOps, platform engineering and FinOps, with dedicated DevOps and SRE engineers or ongoing DevOps work.
Cybersecurity and pentesting
Cybersecurity and penetration testing services: web, mobile, API, network and cloud pentests, secure code review, SOC and incident response, ISO 27001 and SOC 2, with dedicated security engineers or defined projects.
IT infrastructure
IT infrastructure and system administration services: Windows and Linux servers, networks, Microsoft 365 and Entra ID, virtualisation, backups and telecom, with dedicated system administrators or ongoing support.
Site reliability engineering
Site reliability engineering services: SLOs, OpenTelemetry observability, on-call and incident management, load testing, disaster recovery and chaos engineering, with dedicated SRE engineers or project delivery.
Platform engineering
Platform engineering services: internal developer platforms, Backstage portals, golden paths and templates, self-service infrastructure and Kubernetes platforms, with dedicated platform engineers or project delivery.
Cloud architecture
Cloud architecture and consulting services: designs for AWS, Azure and Google Cloud, migration plans, landing zones, Well-Architected reviews, resilience and cost, with dedicated cloud architects or project delivery.
FinOps
FinOps and cloud cost optimisation services: cost allocation, rightsizing, savings plans and reservations, Kubernetes, data and AI costs, budgets and anomaly alerts, with dedicated FinOps engineers or project delivery.
Terraform and IaC
Terraform and infrastructure as code services: Terraform and OpenTofu modules, imports, plan and apply pipelines, drift control, policy as code and Ansible, with dedicated Terraform engineers or project delivery.
Linux administration
Linux administration services: Ubuntu, Debian, RHEL, Rocky Linux and AlmaLinux servers set up, patched, hardened, monitored and backed up, and end-of-life upgrades, with dedicated Linux administrators or ongoing support.
Cloud security
Cloud security services: CSPM and CNAPP, IAM reviews, Kubernetes security, network and data protection and cloud compliance on AWS, Azure and Google Cloud, with dedicated cloud security engineers or project delivery.
SOC and security monitoring
SOC as a service and security monitoring: managed SOC, SIEM deployment, log onboarding, detection engineering, EDR, threat hunting and incident response retainers, with dedicated SOC analysts or ongoing monitoring.
Security compliance
Security compliance and audit readiness: ISO 27001, SOC 2, GDPR, PCI DSS, HIPAA, NIS2 and DORA controls, gap assessments and audit evidence, with dedicated compliance engineers or a readiness project.
Questions about network engineering
Which industries do your network engineers work in?
Mostly cloud, hosting and telecom companies running provider networks, data centres and customer connectivity; fintech and banking, with segmented and audited networks; industrial, manufacturing and energy companies keeping plant networks apart from office IT; security companies; retail and e-commerce businesses with many stores and warehouses; healthcare clinics; and public-sector offices.
Which vendors do you work with?
Cisco, Juniper, Arista, HPE Aruba Networking, MikroTik and Ubiquiti for routing, switching and Wi-Fi; Fortinet, Palo Alto Networks, Check Point and Cisco for firewalls; Zscaler, Cloudflare and Netskope for zero-trust access; and the networking services of AWS, Azure and Google Cloud. We work with the equipment you already have.
Can you move our sites from MPLS to SD-WAN?
Yes, one site at a time. The design and policies are proved at a pilot site, MPLS and SD-WAN run side by side while traffic moves across, and each site keeps a way back until its old circuit is cancelled.
How quickly can network engineers start?
When the right network engineer is available, the start is gated only by your interview and the NDA and IP assignment. Otherwise we run a search, which typically produces candidate profiles within two to three weeks, and nobody starts until you have said yes.
How do we hire network engineers through BigTree108?
Tell us the work, the seniority and the hours you need. We propose one or two people with their profiles, you interview them the way you would interview your own hire, and you sign one agreement with BIG TREE 108 LLC and receive one invoice a month.
Who owns the work they produce?
You do. Every specialist has a signed contract with BigTree108 that assigns all work product to the company, and our agreement with you assigns it onward. Code, designs and documents are delivered into your own repositories and tools, not kept where only we can change them.
Need network engineers?
Tell us how many sites you have, what equipment runs them and what needs to change. You get an answer within one business day: a plan for the work, a scope for a review, or candidate profiles.