Source description
About the role
Job Title: Network Engineer
Location: Washington, D.C. MD, VA, NY candidates only (hybrid 2 days/week)
VISA: USC ONLY
Client: Federal gov.
MOI: Skype
Pay Rate: $60/hr. on C2C
Clearance: Active DoD Security Clearance (Required)
Job Description:
· DISA Secure Cloud Computing Architecture (SCCA) reference design implementation experience.
· AWS networking depth (TGW, VPC peering, Direct Connect, DC Gateway, NAT/PAT design).
· Palo Alto VM-Series NGFW. Prisma Access / SASE Awareness.
· NIPRNet ingress / BCAP familiarity.
· DISA STIGs for network devices.
· VDSS/VDMS boundary, RFC 1918, Direct Connect / DC Gateway, transit gateway architecture, boundary public-IP exposure controls, Network scan.
Position Overview
We are seeking an experienced Network Engineer to support a long-term federal program focused on secure cloud networking and enterprise network infrastructure. The ideal candidate will have strong expertise in AWS networking, DISA Secure Cloud Computing Architecture (SCCA), Palo Alto security technologies, and DoD network security standards. This role requires hands-on experience designing, implementing, and securing cloud-based network architectures while ensuring compliance with DoD cybersecurity requirements.
Key Responsibilities
· Design, implement, and maintain secure network infrastructure in accordance with DISA Secure Cloud Computing Architecture (SCCA) reference designs.
· Architect and support AWS networking environments, including:
· Virtual Private Clouds (VPCs)
· Transit Gateway (TGW)
· VPC Peering
· AWS Direct Connect
· Direct Connect Gateway
· NAT/PAT design and implementation
· Configure, deploy, and manage Palo Alto VM-Series Next-Generation Firewalls (NGFW).
· Support and maintain secure connectivity using Prisma Access/SASE technologies.
· Design and support secure NIPRNet ingress solutions and demonstrate familiarity with BCAP requirements.
· Ensure compliance with DISA Security Technical Implementation Guides (STIGs) for network devices.
· Design and maintain secure network boundaries, including VDSS/VDMS environments.
· Implement secure routing and segmentation using RFC 1918 addressing standards.
· Manage AWS Transit Gateway and Direct Connect architectures to ensure secure hybrid cloud connectivity.
· Implement boundary security controls, including public IP exposure management and ingress/egress security.
· Support network vulnerability assessments, security scans, remediation activities, and compliance initiatives.
· Troubleshoot complex network connectivity and performance issues across cloud and hybrid environments.
· Collaborate with cybersecurity, cloud, infrastructure, and engineering teams to deliver secure and scalable network solutions.
· Maintain network documentation, diagrams, configurations, and operational procedures.
Required Qualifications
· Active DoD Security Clearance (Required).
· Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field (or equivalent experience).
· 8+ years of experience in enterprise network engineering, preferably within DoD or Federal environments.
· Hands-on experience implementing DISA Secure Cloud Computing Architecture (SCCA).
· Strong expertise with AWS networking services, including:
· Transit Gateway (TGW)
· VPC
· VPC Peering
· AWS Direct Connect
· Direct Connect Gateway
· NAT/PAT
· Experience deploying and administering Palo Alto VM-Series NGFW.
· Working knowledge of Prisma Access and Secure Access Service Edge (SASE) architectures.
· Familiarity with NIPRNet, BCAP, and DoD networking environments.
· Experience implementing DISA STIGs and security hardening for network devices.
Strong understanding of:
· Hybrid cloud networking
· Network segmentation
· Routing and switching
· TCP/IP
· VPN technologies
· RFC 1918 private addressing
· Experience supporting vulnerability scanning and remediation activities.
· Excellent troubleshooting, analytical, and documentation skills.
Preferred Qualifications
-
· AWS Certified Advanced Networking – Specialty.
-
· AWS Solutions Architect – Associate or Professional.
-
· Palo Alto Networks Certified Network Security Engineer (PCNSE).
-
· Cisco CCNP or CCIE certification.
-
· Experience supporting federal agencies such as DISA or DoD cloud environments.
-
· Familiarity with Zero Trust Architecture (ZTA) principles.
More at Alpha Net Consulting
Related open roles
Onshore Senior Unix Linux SME -CGEMJP00349841
United States · Hybrid
Adobe Experience Platform (AEP) Architect
Remote · United States
Mid Network Engineer | CGEMJP00349325
Salt Lake City · Onsite
Network Architect Run | CGEMJP00348820
Los Angeles · Hybrid
SQL DBA-CGEMJP00348806
(Fort Mill, SC, 29715)
Network Engineer - Ship Board | CGEMJP00348804
United States · Hybrid