Principal Network Architect / Subject Matter Expert (SME)

Valiant Solutions, LLC

$135K — $160K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in network architecture, including enterprise LAN, WAN, and data center design.
  • Bachelor's degree in Computer Science, Information Systems, Mathematics, Engineering, or related field (or equivalent experience).
  • Track record of serving as the senior technical authority for a multi-site enterprise network.
  • Experience consolidating operations from multiple vendors into a unified network model.
  • Deep expertise in routing and switching protocols like OSPF, BGP, and carrier-grade WAN design.

Responsibilities

  • Lead assessment and validation of network devices across diverse hardware solutions.
  • Direct initial enterprise network assessment focusing on design, security, and performance.
  • Drive knowledge transfer from current staff while documenting operational procedures.
  • Define an ITIL-aligned service management model to unify operations.
  • Plan and review network designs to identify and mitigate single points of failure.

Benefits

  • Valiant covers 99% of health coverage for full-time staff, including medical, dental, and vision.
  • 100% paid short-term disability and life insurance for full-time employees.
  • Paid certifications to support professional development.
  • 401K matching up to 4% to help employees save for retirement.
  • Access to wellness programs and an online training portal for continued learning.
Full Job Description
Position Description

Valiant Solutions is seeking a Principal Network Architect / Subject Matter Expert (SME) to serve as the senior technical authority for a nationwide enterprise network operations consolidation supporting our government customer. Today the customer's network is managed in silos by separate vendors and internal teams across cloud, WAN, LAN, and security, which slows incident resolution and stalls modernization. This role owns the end-to-end design that replaces that model: a single operating picture spanning campus LAN, a carrier MPLS WAN reaching roughly 50 sites, two enterprise data centers, and two public cloud platforms.

The architect sets technical direction for the agency's Zero Trust and IPv6 programs, grounded in NIST SP 800-207, TIC 3.0 reference architectures, and the federal IPv6 mandate in OMB M-21-07. This is a hands-on senior engineering role rather than a management position, and it serves as the final escalation point for Tier 3 architectural root cause analysis.

This position is based in Silver Spring, MD, and allows for partial remote work. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.
Responsibilities
Transition, Consolidation, and Assessment
  • Lead the assessment and validation of the device inventory across Cisco Catalyst and Nexus switches, Cisco Firepower Threat Defense firewalls, Cisco ISE appliances, and Ubiquiti UniFi and Meraki switches.
  • Direct the initial enterprise network assessment covering design, security, redundancy, and performance posture, and identify the gaps that block the target Zero Trust architecture.
  • Drive knowledge transfer from incumbent staff and government engineers, capturing undocumented operational procedures and reconciling them against existing network standard operating procedures.
  • Define the ITIL v4 aligned service management model that replaces tool-by-tool operation, and set the architecture for a consolidated monitoring dashboard aggregating MPLS WAN, data center fabric, and cloud telemetry.
  • Assess the existing ServiceNow ITSM workflow used for network service requests and deliver written recommendations through the customer's review process.
Network Design, Redundancy, and Tier 3 Engineering
  • Conduct the network design review within the first 90 days of performance and annually thereafter, identifying single points of failure in internet, DMZ, and cloud egress paths.
  • Verify that the hot-hot aggregation design across the Seattle and Ashburn data centers survives the loss of any single circuit or backbone device without dropping internet or cloud connectivity.
  • Plan and evaluate failover testing with the security team to confirm that backup paths activate automatically.
  • Serve as the Tier 3 escalation authority for architectural root cause analysis, complex code upgrades, and disaster recovery execution.
  • Review and approve Methods of Procedure before Change Control Board submission, including rollback plans and risk assessments, to protect the change success rate standard.
Multi-Cloud and Carrier Architecture
  • Own BGP traffic engineering across the carrier MPLS backbone, transport circuits, and cloud interconnects to prevent suboptimal routing between on-premise and cloud workloads.
  • Confirm that all cloud connectivity conforms to TIC 3.0 reference architectures so that cloud traffic is inspected and logged as required.
  • Set Quality of Service policy on customer edge routers so that mission data and VoIP traffic receive priority across the wide area network.
  • Act as the senior technical escalation point in carrier disputes, directing intrusive testing windows and vendor management escalation during circuit outages.
Modernization and IPv6 Transition
  • Own the enterprise IPv6 transition plan and drive the enterprise from a roughly 5 percent dual-stacked endpoint baseline toward the 80 percent target, including cloud environments that are currently IPv4-only.
  • Manage the interim dual-stack environment, keeping OSPFv3 and MP-BGP routing tables synchronized and stable.
  • Maintain the enterprise IPv6 addressing plan and prefix allocation across sites, data centers, and cloud tenancies.
  • Design NAT64 and DNS64 translation services if legacy IPv4-only applications are identified during migration.
  • Identify End-of-Life and End-of-Support hardware and propose replacement paths that support TrustSec and native IPv6.
  • Lead quarterly architecture reviews that adapt the design to changing traffic patterns such as increased cloud egress.
Qualifications
Experience and Education
  • 8 years of progressive network architecture experience, including enterprise LAN, WAN, and data center design.
  • Bachelor's degree in Computer Science, Information Systems, Mathematics, Engineering, or a related field. Four additional years of relevant experience may substitute for the degree.
  • Demonstrated experience acting as the senior technical authority for a nationwide or multi-site enterprise network.
  • Experience consolidating fragmented, multi-vendor network operations into a single operating model.
Technical Skills
  • Deep routing and switching expertise across OSPF, OSPFv3, BGP, MP-BGP, and EIGRP redistribution in carrier-managed environments.
  • Carrier-grade WAN design, including MPLS service management, Quality of Service policy, and circuit performance analysis using latency, jitter, packet loss, and availability metrics.
  • Data center fabric design with Cisco Catalyst and Nexus platforms, including Data Center Interconnect tuning for storage replication.
  • Multi-cloud network architecture across Oracle Cloud Infrastructure and Google Cloud Platform, including dedicated interconnect and hybrid routing design.
  • Zero Trust network design incorporating Cisco Identity Services Engine, TrustSec Security Group Tags, and identity-based firewall policy.
  • IPv6 transition planning at enterprise scale, including dual-stack operations, addressing plans, and translation gateways.
  • Familiarity with Infrastructure as Code practice using Terraform, sufficient to set standards for the engineering team.
Communication and Stakeholder Engagement
  • Written and verbal communication skills sufficient to explain network and security concepts to both engineers and non-technical government stakeholders.
  • Ability to brief senior government leadership, including the Contracting Officer's Representative and Technical Lead, on incident root cause, risk, and remediation.
  • Clear technical writing for Methods of Procedure, topology diagrams, standard operating procedures, and monthly status report inputs.
  • Ability to work as a contractor employee in a non-personal services environment, identifying as contractor staff in all meetings, correspondence, and system records.
Federal Knowledge
  • Working knowledge of federal network security direction, including Zero Trust Architecture (NIST SP 800-207), Trusted Internet Connection (TIC) 3.0 reference architectures, and the IPv6 mandate under OMB M-21-07.
  • Familiarity with NIST SP 800-53 Rev. 5 security and privacy controls as they apply to network and boundary protection.
  • Understanding of HSPD-12 identity credentialing and its enforcement in network access decisions.
  • Awareness of Section 508 accessibility requirements (WCAG 2.0 AA) as they apply to contract deliverables.
  • Experience operating inside a federal change control process, with government-approved documentation and deliverable acceptance criteria.


The following certifications are preferred:
  • CCIE Enterprise Infrastructure or CCNP Enterprise.
  • CCNP Security or Cisco Certified Specialist - Security Identity Management Implementation (300-715 SISE).
  • A cloud networking certification relevant to the environment, such as (GCP) Google Professional Cloud Network Engineer or (OCI) Oracle Cloud Infrastructure Architect.
  • ITIL v4 Foundation certification is preferred, given the requirement to unify operations under an ITSM framework.


Benefits Snapshot (includes, but not limited to)
Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
Valiant contributes 25% towards Health Coverage for Family and Dependents
100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
100% Paid Certifications
401K Matching up to 4%
Paid Time Off
Paid Federal Holidays
Wellness & Fitness Program
Valiant University - Online Education and Training Portal
FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
Referral Bonuses

The salary range for this position is a general guideline and not a guarantee of compensation or salary. It has been benchmarked in relation to the scope of the role, market rate, and internal equity. The salary for this role is expected to be in the xxx- xxx range. Where a candidate falls within the band can be determined based on one or more of the following: skillset, experience level, achievements, education, geographic location, security clearance, involvement in corporate tasks, and other non-discriminatory factors. In addition to the base salary, this role will include benefits as described above. Valiant reserves the right to adjust the salary range, experience requirements, and position responsibilities at any time without prior notice.

Remote Work Policy

Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General's effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.

Physical Demands

Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.

Similar Jobs

More Jobs at Valiant Solutions, LLC

More Information Technology Jobs

Find similar Principal Network Architect / Subject Matter Expert (SME) jobs: