About You: You are a senior to principal-level enterprise network engineering subject matter expert with deep, hands-on experience designing, implementing, integrating, and modernizing data center networks and enterprise firewalls in mission-critical environments. You combine strong routing and switching fundamentals with practical expertise in firewall policy, secure segmentation, high availability, and network troubleshooting.
You have experience across data center, WAN, and LAN environments, including internet-connected enterprise networks, classified enclaves, multi-site mission networks, and fully air-gapped environments. You understand how to integrate firewalls, load balancers, and physical and virtual infrastructure into resilient, secure network architectures that support mission operations, performance, and long-term modernization.
You are comfortable leading complex architecture and integration efforts while remaining hands-on with design, implementation, troubleshooting, documentation, and deployment. You thrive in high-assurance environments where reliability, security, interoperability, and disciplined execution are essential. You provide technical leadership and work closely with network engineering, cybersecurity, infrastructure, unified communications, and performance engineering teams.
Position Overview: VT-ARC is seeking a Senior to Principal Enterprise Network Engineer with a focus on data center networking and firewall engineering to serve as a senior technical authority for enterprise network architecture, implementation, sustainment, and modernization supporting mission-critical programs within TS/SCI environments.
This role spans the full network lifecycle, from requirements interpretation and architecture input through detailed design, implementation, validation, documentation, and operational transition. The primary emphasis is data center network design and buildout, enterprise firewall implementation, secure segmentation, high availability, and integration with the broader enterprise network. The position remains multi-vendor and includes connectivity across WAN, LAN, classified, air-gapped, and multi-enclave environments.
This is a hands-on, principal-level network engineering role responsible for translating mission and architecture objectives into executable network designs, implementation plans, and operationally supportable solutions. The Principal Enterprise Network Engineer will provide technical guidance to network, cybersecurity, and infrastructure teams while actively contributing to system stand-up, modernization, architecture validation, and mission integration.
Active Top Secret/SCI clearance is required. Duties/Responsibilities: - Lead enterprise network engineering for data centers and firewalls, from architecture input and detailed design through implementation planning, integration, validation, and operational transition.
- Design, implement, and modernize data center routing and switching infrastructure, including connectivity for physical and virtual server environments, storage systems, and enterprise services.
- Design, configure, integrate, and troubleshoot enterprise firewalls, including security policies, access controls, NAT, VPNs, DMZs, segmentation, and high-availability configurations.
- Develop and validate resilient network designs that account for redundancy, routing convergence, firewall failover, load balancing, performance, interoperability, and sustainment.
- Provide SME-level technical leadership across multi-vendor network environments, including Cisco, Juniper, Aruba, and related data center, firewall, and network infrastructure platforms.
- Translate enterprise architecture objectives and mission requirements into executable network designs, implementation plans, configuration standards, and deployment roadmaps.
- Design and deploy enterprise routing and transport technologies, including BGP, OSPF, MPLS, QoS, VPN, and overlay/underlay architectures supporting data center and multi-site connectivity.
- Develop cross-domain, multi-enclave, and secure network integration approaches for classified and high-assurance mission environments in coordination with the appropriate security and architecture teams.
- Collaborate with program architecture, cybersecurity, UC, systems engineering, infrastructure, and network performance teams to ensure end-to-end mission integration.
- Lead proof-of-concept demonstrations, lab validation, technical pilots, and integration events; validate firewall policies, application connectivity, performance, and failover behavior before deployment.
- Troubleshoot complex routing, switching, firewall, VPN, and load-balancing issues using packet captures, logs, and network monitoring tools.
- Develop technical documentation, Layer 2/Layer 3 network diagrams, firewall rule sets, configuration baselines, implementation guides, test plans, and operational transition materials.
- Mentor network engineering staff, establish network engineering standards, and promote best practices across the program.
Required Education, Certification, Skills, Capabilities: - Professional certifications such as CCNP, CCIE, JNCIP, JNCIE, PCNSE, Aruba Certified Professional/Expert, Security+, CISSP, or equivalent technical credentials.
- Experience with Cisco Nexus data center switching, Juniper SRX, Cisco ASA/Firepower, or comparable data center networking and enterprise firewall platforms.
- Experience with F5 BIG-IP LTM/GTM or equivalent load-balancing and application-delivery platforms.
- Experience integrating VMware networking, physical and virtual server infrastructure, and storage network connectivity in high-availability environments.
- Experience with SD-WAN technologies, including Cisco Viptela, Juniper, Aruba, VMware/VeloCloud, or equivalent platforms.
- Experience with cloud or hybrid networking architectures in AWS GovCloud, Azure Government, or similar government cloud environments.
- Experience with network automation, scripting, and infrastructure-as-code tools such as Python, Ansible, REST APIs, Git, or related toolsets.
- Experience with network modeling, simulation, lab validation, or digital engineering environments.
- Familiarity with systems engineering lifecycle reviews, including SRR, PDR, CDR, TRR, and related technical review processes.
- Experience producing architecture artifacts aligned with DoDAF, mission engineering, model-based systems engineering, or enterprise architecture frameworks.
- Experience mentoring engineers, establishing technical standards, and serving as a trusted technical advisor to program leadership and mission stakeholders.
Desired Education, Certification, Skills, Capabilities: - Professional certifications such as CCNP, CCIE, JNCIP, JNCIE, PCNSE, Aruba Certified Professional/Expert, Security+, CISSP, or equivalent technical credentials.
- Experience with Cisco Nexus data center switching, Juniper SRX, Cisco ASA/Firepower, or comparable data center networking and enterprise firewall platforms.
- Experience with F5 BIG-IP LTM/GTM or equivalent load-balancing and application-delivery platforms.
- Experience integrating VMware networking, physical and virtual server infrastructure, and storage network connectivity in high-availability environments.
- Experience with SD-WAN technologies, including Cisco Viptela, Juniper, Aruba, VMware/VeloCloud, or equivalent platforms.
- Experience with cloud or hybrid networking architectures in AWS GovCloud, Azure Government, or similar government cloud environments.
- Experience with network automation, scripting, and infrastructure-as-code tools such as Python, Ansible, REST APIs, Git, or related toolsets.
- Experience with network modeling, simulation, lab validation, or digital engineering environments.
- Familiarity with systems engineering lifecycle reviews, including SRR, PDR, CDR, TRR, and related technical review processes.
- Experience producing architecture artifacts aligned with DoDAF, mission engineering, model-based systems engineering, or enterprise architecture frameworks.
- Experience mentoring engineers, establishing technical standards, and serving as a trusted technical advisor to program leadership and mission stakeholders.
Primary Work Location: Work is expected to be fully onsite in Arlington, VA.
Special Work Conditions: Travel may be required, up to 10%.
Security: - Must be a U.S. Citizen
- Active Top Secret/SCI clearance is required
Competitive Salary: VT-ARC offers competitive pay based on a number of factors, including but not limited to conducting comparable salary market research, education, years of experience, and benefits.
Salary Range: $220,000• $250,000 annually
To learn more about VT-ARC's Benefits, Perks, Culture & more visit our Careers page: https://vt-arc.org/careers/