Principal Network Engineer (Must be eligible for clearance)

Position Summary:

As a Principal Network Engineer, you will support the design, implementation, and audit-readiness of a secure network infrastructure for high-priority government and corporate programs. This role will include technical execution (building secure cloud/on-prem environments, resilient network design including mesh) and security governance (CMMC compliance and corporate IT posture). This role requires you to maintain a CISSP certification.

Core Responsibilities (includes but not limited to):

  • Lead the progressive development and maintenance of all ATO/ATO-C artifacts, ensuring continuous alignment with CMMC (Level 2/3) and NIST 800-171 standards.

  • Architect and manage resilient, high-availability network topologies, including Mesh Networks, Software-Defined Networking (SDN), and secure VPN tunnels.

  • Perform comprehensive Systems Maintenance and technical support for hosting environments, including proactive troubleshooting, routine patching, and firmware updates across Windows and Linux server ecosystems.

  • Drive Vulnerability Management programs by conducting regular system scans (ACAS/Nessus), performing rapid remediation, and managing the POA&M (Plan of Action and Milestones) process.

  • Design and deploy secure, cloud-agnostic environments in AWS GovCloud or Azure Government, ensuring all infrastructure meets DISA STIG requirements.

  • Support DevSecOps initiatives by integrating security monitoring, automated gatekeeping, and container security into CI/CD pipelines.

  • Oversee corporate and program-specific security postures, including Identity and Access Management (IAM), secure MFA/CAC user provisioning, and SIEM transparency for user behavior analytics.

  • Implement "Zero Trust" principles and secure file-upload pipelines, incorporating integrated virus scanning and sandbox isolation.

  • Engineer and maintain cross-platform integration between legacy systems and modern data-driven operations, ensuring robust audit logging and data retention meeting NARA standards.

  • Serve as the primary technical liaison for government auditors, defending security controls and providing full transparency into the system's risk posture.

‍    ‍Education

  • Minimum: Bachelor’s degree in Computer Science, Information Technology, or Network Engineering.

  • Mandatory Certification: CISSP (Certified Information Systems Security Professional) is required for this role.

  • Preferred Certifications: CCNP/CCIE (Enterprise or Security), AWS Certified Solutions Architect – Professional (SAP), or Microsoft Certified: Azure Solutions Architect Expert.

‍    ‍Experience

  • Total Experience: 10–15+ years in network engineering and systems administration.

  • Role-Specific: 4+ years in a Principal, Lead Architect, or Senior Systems Engineer role focusing on secure government infrastructure.

  • Compliance Leadership: Proven track record of leading at least 2 full ATO (Authority to Operate) processes or CMMC Level 2/3 certifications from gap analysis through successful audit.

  • Technical Depth: Extensive experience designing Zero Trust Architecture (ZTA) and managing hybrid-cloud environments (AWS GovCloud/Azure Government) within DISA STIG requirements.

  • Security Operations: Demonstrated expertise in vulnerability management using ACAS/Nessus and managing complex POA&Ms for federal programs.

  • Infrastructure Strategy: Experience mentoring mid-level network engineers and advising executive leadership on long-term infrastructure roadmaps, including "Cloud vs. On-Prem" cost-benefit and risk analysis.