Senior COMSEC & Network Engineer (Cloud/Classified)

General Dynamics Information Technology, Inc.

• $107K — $143K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in Network Engineering, with 4 years focused on COMSEC and Cryptographic systems
  • Deep understanding of OSI Model, TCP/IP, BGP, and IPsec
  • Proficiency with HAIPE devices and Key Management Infrastructure (KMI)
  • Experience with CSfC Multi-Site and Mobile Access Capability Packages
  • Familiarity with Zero Trust Architecture principles in tactical or enterprise environments

Responsibilities

  • Design and implement COMSEC solutions in classified Azure environments
  • Manage and optimize Azure virtual networks and VPN Gateways
  • Install and maintain Type-1 encryption devices and keying materials
  • Develop SOPs for key management and incident response
  • Collaborate with cross-functional teams to troubleshoot connectivity issues
  • Maintain records of COMSEC material and perform physical inventories
  • Conduct audits to ensure compliance with NSA policies

Benefits

  • Comprehensive medical, dental, and vision plans
  • 401(k) plan with company match
  • Flexible work weeks and various paid time off options
  • Short and long-term disability benefits
  • Life and critical illness insurance
  • Identity verification process to enhance security
Full Job Description
Type of Requisition:
Regular

Clearance Level Must Currently Possess:
Secret

Clearance Level Must Be Able to Obtain:
Top Secret/SCI

Public Trust/Other Required:
None

Job Family:
IT Infrastructure and Operations

Job Qualifications:

Skills:
Communications Security (COMSEC), Infrastructure, Network Engineering
Certifications:
None
Experience:
8 + years of related experience
US Citizenship Required:
Yes

Job Description:

We are seeking a highly skilled COMSEC and Network Engineer to lead the integration and management of secure communications within a classified Azure Cloud environment. This role is critical in bridging the gap between traditional cryptographic hardware and modern software-defined networking in a high-stakes, multi-domain mission space. You will be responsible for the end-to-end security of data in transit, ensuring that our classified cloud infrastructure meets all regulatory requirements while maintaining peak operational performance.

Key Responsibilities
  • Cryptographic Architecture: Design and implement Secure Communications (COMSEC) solutions across classified Azure environments (IL5/IL6), ensuring compliance with NSA Commercial Solutions for Classified (CSfC) requirements.
  • Cloud Networking: Manage and optimize Azure virtual networks, ExpressRoute, and VPN Gateways to maintain low-latency, high-security connectivity.
  • Hardware Integration: Install, configure, and maintain Type-1 encryption devices (e.g., TACLANE) and cryptographic keying materials using specialized management systems.
  • Policy & Compliance: Develop and maintain Standard Operating Procedures (SOPs) for key management, device auditing, and incident response in accordance with government security mandates.
  • Cross-Functional Collaboration: Partner with Cloud Architects, Network Engineers and Security Engineers to troubleshoot complex connectivity issues and mitigate vulnerabilities within the transport layer.
  • Accountability & Inventory: Maintains records of all COMSEC material, performing physical inventories (often semi-annually) and securing Controlled Cryptographic Items (CCI).
  • Keying Material Management: Orders, receives, secures, loads, and destroys COMSEC keying material using systems like the Key Management Infrastructure (KMI) or Simple Key Loader (SKL).
  • Compliance & Audits: Conducts regular audits and inspections to identify vulnerabilities, ensuring compliance with National Security Agency (NSA) and agency policies.
  • Incident Reporting: Reports known or suspected COMSEC incidents immediately to the program office, ensuring proper procedures are followed.
  • Training & Briefing: Conducts initial briefings and debriefings for authorized users, managing access lists to restricted areas/material.
  • Destruction and Disposal: Oversees the authorized destruction of keying material and coordinates the disposal of obsolete cryptographic equipment.


Required Qualifications
  • BA/BS or equivalent experience
  • Experience: 8+ years of experience in Network Engineering with at least 4 years focused on COMSEC and Cryptographic systems.
  • Clearance: Secret with ability to obtain and maintain TS/SCI
  • Cloud Expertise: Proven experience configuring networking components within Azure Government or Classified Cloud environments.


Technical Knowledge
  • Deep understanding of OSI Model, TCP/IP, BGP, and IPsec.
  • Proficiency with HAIPE (High Assurance IP Encryptor) devices and Key Management Infrastructure (KMI).
  • Experience with CSfC Multi-Site and Mobile Access Capability Packages.
  • Experience with Infrastructure as Code (Terraform, Bicep, or ARM templates) to automate secure network deployments.
  • Familiarity with Zero Trust Architecture (ZTA) principles in a tactical or enterprise edge environment.
  • Previous experience as a COMSEC Custodian or Alternate.


Certifications
  • DoD 8570 IAT Level II or III (e.g., Security+, CISSP, or CASP+).
  • Azure Solutions Architect or Azure Network Engineer Associate preferred.
  • Clearance: Active Secret with ability to obtain and maintain TS/SCI


The likely salary range for this position is $107,744 - $143,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:
40

Travel Required:
10-25%

Telecommuting Options:
Onsite

Work Location:
USA CA El Segundo

Additional Work Locations:

Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

Similar Jobs

More Jobs at General Dynamics Information Technology, Inc.

More Aerospace & Defense Jobs

Find similar Senior COMSEC & Network Engineer (Cloud/Classified) jobs: