Network Architect

ValidaTek, Inc.

$120K — $145K *
Aerospace & Defense
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant STEM field or equivalent experience
  • 12+ years of network engineering experience in defense environments
  • Active TS/SCI Clearance required
  • DoD 8570.01-M / DoD 8140 IAT Level II or III certification
  • Active Computing Environment certification (e.g., CCNA, CCNP, ACSA)
  • Experience configuring Cisco IOS-XE and Aruba appliances for VPNs
  • Proven skills with Palo Alto firewalls and security policies

Responsibilities

  • Architect and operate secure dual-layer cryptographic networks using Cisco and Aruba technologies
  • Implement and tune Palo Alto NGFW security policies and IDS/IPS signatures
  • Design multi-layered CSfC architectures compliant with NSA standards
  • Integrate enterprise PKI services and manage certificate lifecycles
  • Deploy VPN protocols with Cisco and Aruba appliances ensuring traffic separation
  • Manage Cisco ISE and Aruba ClearPass for network access control
  • Prepare compliance documentation for NSA CSfC PMO registration

Benefits

  • Opportunity to work on high-impact government projects
  • Engagement with cutting-edge network technologies
  • Professional development and certification support
  • Work in a collaborative team environment
  • Potential for career advancement within a growing organization
Full Job Description
Summary:

ValidaTek is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio.

Responsibilities:
  • The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing.
  • Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks.
  • Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
  • Understanding of NIAP approved list and monitors for changes
  • Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
  • Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation.
  • Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection.
  • Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling.
  • Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure.
  • Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission.

Qualifications:
  • Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree.
  • 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments
  • Active TS/SCI Clearance
  • Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP).
  • Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP
  • Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF).
  • Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles.
  • Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies.
  • Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization.
  • Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN).
  • Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs).
  • Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations.
  • Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).

Salary Disclosure:

Actual salary will be based on a variety of factors including but not limited to experience, geographic location, contract affordability, internal equity, education, and certifications. The upper end of the salary range may be reserved for individuals who have demonstrated tenure with the company, seniority, and proven excellent performance. This includes factors such as education, certifications, and extensive/unique experience beyond what is required.

Similar Jobs

More Jobs at ValidaTek, Inc.

  • Network Architect
    $120K — $145K *
    Fort Belvoir, VA 22060 (Fairfax County)
    Aerospace & Defense
    In-Person
  • IT Project Manager
    $110K — $130K *
    Quantico, VA 22134 (Prince William County)
    Information Technology
    In-Person
  • Program Manager
    $110K — $130K *
    Mclean, VA 22101 (Fairfax County)
    Information Technology
    In-Person
  • Senior Program Manager - PKI
    $112K — $135K *
    Fort George G Meade, MD 20755 (Anne Arundel County)
    Aerospace & Defense
    In-Person
  • Senior Network Engineer
    $100K — $130K *
    Arlington, VA 22204 (Arlington County)
    Aerospace & Defense
    In-Person

More Aerospace & Defense Jobs

Find similar Network Architect jobs: