Principal Network Engineer (Must be eligible for clearance)
Position Summary:
As a Principal Network Engineer, you will support the design, implementation, and audit-readiness of a secure network infrastructure for high-priority government and corporate programs. This role will include technical execution (building secure cloud/on-prem environments, resilient network design including mesh) and security governance (CMMC compliance and corporate IT posture). This role requires you to maintain a CISSP certification.
Core Responsibilities (includes but not limited to):
Lead the progressive development and maintenance of all ATO/ATO-C artifacts, ensuring continuous alignment with CMMC (Level 2/3) and NIST 800-171 standards.
Architect and manage resilient, high-availability network topologies, including Mesh Networks, Software-Defined Networking (SDN), and secure VPN tunnels.
Perform comprehensive Systems Maintenance and technical support for hosting environments, including proactive troubleshooting, routine patching, and firmware updates across Windows and Linux server ecosystems.
Drive Vulnerability Management programs by conducting regular system scans (ACAS/Nessus), performing rapid remediation, and managing the POA&M (Plan of Action and Milestones) process.
Design and deploy secure, cloud-agnostic environments in AWS GovCloud or Azure Government, ensuring all infrastructure meets DISA STIG requirements.
Support DevSecOps initiatives by integrating security monitoring, automated gatekeeping, and container security into CI/CD pipelines.
Oversee corporate and program-specific security postures, including Identity and Access Management (IAM), secure MFA/CAC user provisioning, and SIEM transparency for user behavior analytics.
Implement "Zero Trust" principles and secure file-upload pipelines, incorporating integrated virus scanning and sandbox isolation.
Engineer and maintain cross-platform integration between legacy systems and modern data-driven operations, ensuring robust audit logging and data retention meeting NARA standards.
Serve as the primary technical liaison for government auditors, defending security controls and providing full transparency into the system's risk posture.
Education
Minimum: Bachelor’s degree in Computer Science, Information Technology, or Network Engineering.
Mandatory Certification: CISSP (Certified Information Systems Security Professional) is required for this role.
Preferred Certifications: CCNP/CCIE (Enterprise or Security), AWS Certified Solutions Architect – Professional (SAP), or Microsoft Certified: Azure Solutions Architect Expert.
Experience
Total Experience: 10–15+ years in network engineering and systems administration.
Role-Specific: 4+ years in a Principal, Lead Architect, or Senior Systems Engineer role focusing on secure government infrastructure.
Compliance Leadership: Proven track record of leading at least 2 full ATO (Authority to Operate) processes or CMMC Level 2/3 certifications from gap analysis through successful audit.
Technical Depth: Extensive experience designing Zero Trust Architecture (ZTA) and managing hybrid-cloud environments (AWS GovCloud/Azure Government) within DISA STIG requirements.
Security Operations: Demonstrated expertise in vulnerability management using ACAS/Nessus and managing complex POA&Ms for federal programs.
Infrastructure Strategy: Experience mentoring mid-level network engineers and advising executive leadership on long-term infrastructure roadmaps, including "Cloud vs. On-Prem" cost-benefit and risk analysis.