Required Qualifications- Security Clearance: Active Top Secret clearance with SCI eligibility required.
- Experience: Minimum of 10+ years of progressive, hands-on experience in enterprise network engineering and network security infrastructure within Department of Defense (DoD), intelligence community, or federal enterprise environments.
- Education: Bachelor's degree in Network Engineering, Computer Science, Cybersecurity, Information Technology, or an equivalent technical discipline (or 12+ years of relevant experience in lieu of degree).
- Routing & Switching Mastery: Demonstrated expertise with enterprise routing protocols (BGP, OSPF, ISIS), VLAN/VXLAN design, spine-leaf topologies, and hardware platforms (Cisco Nexus/Catalyst, Juniper Junos, or Arista EOS).
- Cybersecurity & Perimeter Defense: At least 4+ years of dedicated hands-on experience configuring and administering Next-Generation Firewalls (Palo Alto PAN-OS, Fortinet FortiGate, or Cisco Secure Firewall), VPN concentrators, and zero-trust segmentation policies.
- Network Visibility & Sensor Deployment: Proven experience deploying and managing network traffic monitoring solutions, such as network TAPs, SPAN/RSPAN sessions, packet brokers (Gigamon, Ixia), or network intrusion sensors (Zeek, Suricata, Snort).
- DoD Compliance Standards: Strong working knowledge of DISA Network Infrastructure STIGs, SCAP compliance tools, and secure boundary enforcement standards.
- Certifications: Active DoD 8570/8140 IAT Level II (e.g., CompTIA Security+, CySA+) required; plus professional-level networking/security certification (e.g., Cisco CCNP Enterprise / Security, Palo Alto PCNSE, or Juniper JNCIP).
Preferred Experience- Network Automation: Proficiency in automating network workflows and configuration auditing using Python (Netmiko, Scrapli, Nornir), Ansible, and RESTCONF/NETCONF APIs.
- Data & SIEM Pipeline Integration: Experience forwarding and optimizing high-volume network telemetry to Elastic Stack (ELK), Splunk, or Kafka architectures.
- Advanced Cryptography: Familiarity with DoD Type-1 encryptors (KG-175 TACLANE) and NSA CSfC (Commercial Solutions for Classified) architectures.
- Threat Frameworks: Understanding of the MITRE ATT&CK framework for Enterprise, specifically network attack vectors, C2 infrastructure detection, and lateral movement tactics.
Want to learn more about Government Services? Check us out on our platform:https://www.wwt.com/public-sectorhttps://www.wwt.com/government-servicesPreferred locations: San Antonio, TXCertain states and localities require employers to post a reasonable estimate of salary range. A reasonable estimate of the current base pay range for this position is $150,000.00 to $194,000.00 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base pay.
The well-being of WWT employees is essential. So, when it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:
- Health and Wellbeing: Health, Dental, and Vision Care, Onsite Health Centers, Employee Assistance Program, Wellness program
- Financial Benefits: Competitive pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Tuition Reimbursement
- Paid Time Off: PTO and Sick Leave (starting at 20 days per year) & Holidays (10 per year), Parental Leave, Military Leave, Bereavement
- Additional Perks: Nursing Mothers Benefits, Voluntary Legal, Pet Insurance, Employee Discount Program
We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for All!
What is the Government Services Team and why join? Our Government Services team provides cleared resources with a global reach to federal civilian, Department of Defense (DoD), and intelligence community markets. We excel at delivering innovative, operationally ready, and cost-effective IT solutions that accelerate the interoperability and resiliency of mission-critical systems.
What will you be doing?World Wide Technology (WWT) is seeking a Network Architect Cybersecurity with at least 8 years of enterprise networking and cybersecurity infrastructure experience to support mission-critical Department of Defense (DoD) environments. In this role, you will serve as the primary network architect and security systems integrator, engineering resilient, high-speed, and highly secure network fabrics designed to transport, inspect, and analyze sensitive operational telemetry.
You will design and administer multi-site routed and switched backbones, implement Zero Trust network segmentation, configure Next-Generation Firewalls (NGFWs), and architect high-capacity network visibility architectures-integrating hardware taps, packet brokers, and network sensors (such as Zeek and Suricata) directly into enterprise security operations platforms.
Key Responsibilities: - Enterprise Network Architecture & Operations: Design, deploy, configure, and maintain mission-critical enterprise routing, switching, and transport backbones (BGP, OSPF, EVPN-VXLAN, MPLS) across multi-site DoD and secure enclave environments.
- Network Security & Boundary Defense: Architect, deploy, and manage Next-Generation Firewalls (NGFW - Palo Alto Networks, Fortinet, or Cisco Firepower), implementing strict zero-trust boundary controls, micro-segmentation, deep packet inspection, and IPS/IDS policies.
- Sensor Infrastructure & Telemetry Ingestion: Architect and sustain passive/active network visibility infrastructure, including physical/virtual TAPs, network packet brokers (e.g., Gigamon, Ixia), and high-throughput network forensics engines (Zeek, Suricata) to ensure complete packet capture and telemetry ingestion.
- DoD Compliance & Network Hardening: Harden all network routing, switching, and security appliances in strict adherence to DISA Security Technical Implementation Guides (STIGs), DoD boundary protection requirements, and NIST SP 800-53/Zero Trust Architecture (SP 800-207) controls.
- Cyber Operations & SIEM Pipeline Alignment: Collaborate closely with SOC analysts and cyber platform teams to route, filter, and stream NetFlow, IPFIX, Syslog, and Zeek/Suricata logs into analytic data pipelines (Elastic Stack/ELK, Splunk, Kafka) for real-time threat detection.
- Encrypted Transport & Secure Interconnects: Engineer, maintain, and audit secure site-to-site IPsec VPNs, MACsec links, and HAIPE/Type-1 cryptographic overlay tunnels ensuring data-in-transit confidentiality and regulatory compliance across enclaves.
- Network Automation & Programmability: Develop automation playbooks and custom scripts using Python, Ansible, and REST APIs to streamline switch/router configurations, firmware lifecycle updates, ACL compliance audits, and telemetry routing.
- Performance Tuning & High Availability: Analyze network telemetry, packet latency, jitter, and link utilization; optimize Quality of Service (QoS), jumbo frame support, and redundant fabric architectures (MLAG, vPC, BFD) to prevent packet loss under high sensor traffic loads.
- Incident Response & Network Forensics Collaboration: Support cyber incident response and threat hunting investigations by performing advanced packet captures (PCAP analysis), tracing unauthorized lateral movement, and isolating compromised network segments.
- Technical Documentation & ATO Artifacts: Produce authoritative network topologies, IP addressing schemas, data-flow diagrams, and technical risk documentation required for DoD Risk Management Framework (RMF) and Authority to Operate (ATO) packages.