OverviewDecisionPoint seeks a Cloud Network Architect to design, secure, and optimize cloud network architectures within IL5 AWS GovCloud environments supporting a large federal and DoD-aligned mission environment. This role focuses on network segmentation, routing, DNS architecture, VPC/VNet design, east-west traffic control, firewall policies, and secure boundary design aligned with Zero Trust principles.
The Cloud Network Architect works closely with cloud platform engineers, cybersecurity teams, system administrators, and application architects to ensure resilient, compliant, and high-performing network infrastructure across enterprise cloud systems.
This position is fully remote.
Duties & Responsibilities
The Cloud Network Architect will:
- Design IL5-compliant cloud network architectures including VPCs, subnets, routing, and segmentation.
- Implement network security controls aligned with Zero Trust, including east-west traffic filtering and micro-segmentation.
- Develop and maintain DNS architecture, API routing flows, and secure naming conventions.
- Architect secure cloud boundary protections including WAF, firewalls, and network access controls.
- Lead configuration of VPN, Direct Connect, and cross-account networking for hybrid-cloud or multi-VPC connectivity.
- Support traffic flow analysis, latency optimization, and performance tuning across cloud network layers.
- Ensure network designs comply with RMF, STIGs, IL5 cloud security standards, and boundary defense requirements.
- Troubleshoot complex network issues involving connectivity, DNS failures, load balancing, or segmentation errors.
- Develop network diagrams, architecture documentation, and network policy standards.
- Support monitoring and alerting implementations across network and connectivity components.
- Participate in Change Control Board (CCB) processes for network modifications.
- Provide guidance to engineering teams on cloud network patterns and operational impacts.
Qualifications
Clearance Requirement
Must hold an active Top Secret clearance, supported by a Tier 5 background investigation.
Education (Required)
Bachelors degree in Networking, Computer Science, Engineering, or a related technical field.
Experience (Required)
- Minimum 7 years of experience in cloud or enterprise network engineering.
- Experience designing secure cloud network architectures including VPC/VNet segmentation.
- Experience with DNS, routing, firewalls, and secure boundary design.
- Experience supporting IL5, federal, or DoD network environments.
Technical Knowledge (Required)
- Strong knowledge of AWS GovCloud networking services (VPC, NACLs, SGs, Transit Gateway, Route 53).
- Experience with VPN, Direct Connect, and hybrid-cloud connectivity patterns.
- Knowledge of Zero Trust network principles and east-west segmentation.
- Familiarity with load balancers, WAF, and boundary defense tools.
Technical Knowledge (Preferred)
- Experience with network automation or IaC network configuration.
- Experience with container networking, service mesh, or microservices connectivity.
- Familiarity with cloud-native monitoring and packet analysis tools.
Certifications
Required:
Preferred:
- Additional cloud network certifications
Skills
- Strong problem-solving and diagnostic abilities for complex network issues.
- Excellent communication and collaboration skills across technical teams.
- High attention to detail and documentation accuracy.
- Ability to architect secure, scalable network solutions at enterprise scale.
- Ability to manage change in a fast-paced mission environment.