Concept Solutions is seeking a
Senior Network Engineer to join a dedicated team of Information Technology (IT) professionals supporting the Federal Aviation Administration's (FAA) Command, Control, and Communications (C3) office. The C3 office carries a critical strategic mandate: ensuring FAA managers maintain daily situational awareness and uninterrupted continuity of communications during severe national emergencies, natural disasters, or critical equipment malfunctions. Should disruptions occur, the C3 office is chartered with executing rapid disaster recovery and restoring essential communication services expeditiously. This high-stakes, mission-critical position is based on-site in Washington, DC, with some telework eligibility available once the candidate is fully trained and integrated.
In this role, the selected engineer serves as the primary technical advisor and bridge between traditional enterprise network environments and modern, scalable AWS cloud systems. The role is responsible for the design interpretation, modernization, security, and continuous operation of the hybrid infrastructure that underpins the FAA's emergency communications posture, aligning complex physical architectures with cutting-edge public sector cloud solutions.
Core Duties & Hybrid Architecture Responsibilities
The Senior Network and Hybrid Cloud Engineer will lead complex, time-sensitive projects and serve as a senior technical authority. The core responsibilities span across traditional hardware environments and AWS public sector cloud infrastructure:
Traditional Enterprise Network Engineering• Serve as the senior technical authority for the end-to-end design, development, and implementation of robust enterprise network architectures, including Local Area Networks (LAN), Wide Area Networks (WAN), and Metropolitan Area Networks (MAN).
• Lead multi-vendor physical engineering efforts for the expansion, performance optimization, and modernization of enterprise network infrastructures, with specific focus on high-scale routers, switches, and firewalls.
• Evaluate emerging physical networking technologies and develop strategic investment recommendations to continuously improve the scalability, resiliency, and path diversity of the C3 office's mission-critical networks.
• Perform system administrator duties on an as-needed basis to verify server-network integration, maintaining high availability for local and remote operations.
Hybrid Connectivity & AWS Cloud Architecture• Design, build, and maintain highly secure hybrid connectivity architectures bridging traditional civilian FAA data centers with AWS cloud environments, utilizing AWS Direct Connect, Site-to-Site VPN, Transit Gateway, and Route 53.
• Formulate and execute structured cloud migration strategies to transition legacy, on-premises civilian systems, applications, and network appliances into secure, scalable AWS environments.
• Develop and operate robust multi-account AWS landing zones using AWS Control Tower, establishing logical subnets, route tables, security groups, custom VPC configurations, and strict network segmentation boundaries.
• Establish highly available cloud architectures and robust disaster recovery configurations designed to meet stringent Recovery Time Objective (RTO) and Recovery Point Objective (RPO) requirements.
• Optimize cloud resource costs and efficiency (FinOps) through proactive resource right-sizing, AWS Savings Plans, Reserved Instances, and tier-appropriate storage optimization strategies.
Cybersecurity, Compliance & Zero Trust HardeningTo ensure the high integrity of critical communications, the candidate will be responsible for integrating a holistic security posture across physical and virtual environments, conforming to strict federal guidelines:
• Verify the posture of the LAN, WAN, and AWS environments to ensure complete compliance with civilian configuration management and federal security requirements, in strict accordance with OMB Circular A-130, FISMA, and the NIST SP 800 series (specifically NIST SP 800-53 and FedRAMP security controls).
• Implement and enforce advanced network security controls and Zero Trust Network Architecture (ZTNA) principles, utilizing Cisco secure firewalls, segmentation rules, and secure remote access tunnels (IPsec, 802.1x, and client-to-site VPNs).
• Deploy and monitor unified cloud-based security tools including IAM, AWS Organizations, AWS Security Hub, Amazon GuardDuty, AWS Config, Key Management Service (KMS), and AWS WAF.
• Lead the buildout and strict enforcement of civilian and federal Security Technical Implementation Guides (STIGs) across all routing, switching, and cloud-native network components.
• Support civilian Security Assessments, vulnerability remediation cycles, continuous monitoring, and Authorization to Operate (ATO) activities to preserve the network's authorized operations status.
Diagnostics, Automation & Operational SupportOperational readiness demands rapid troubleshooting, automated infrastructure management, and rigorous environment isolation:
• Provide tier-3 diagnostic expertise to resolve complex enterprise network failures affecting critical systems, utilizing deep-packet analysis (such as Wireshark) and performance tracking to isolate packet loss, latency, or routing loops.
• Proactively monitor physical and virtual infrastructure performance using enterprise-grade monitoring suites including Riverbed, NetFlow, SolarWinds, AWS Network Manager, and Cisco Catalyst Center.
• Automate the deployment and configuration of physical network components and AWS resources utilizing modern Infrastructure-as-Code (IaC) and configuration management tools including Terraform, AWS CloudFormation, Ansible, Python scripting, and structured CI/CD pipelines.
• Build, maintain, and support a segregated, realistic test lab environment to validate software patches, firewall rules, and cloud infrastructure modifications prior to production release.
• Coordinate closely with external telecommunications vendors and ISP engineering teams to troubleshoot high-capacity circuits and resolve external carrier network disruptions.
• Deliver professional technical mentorship, direction, and coaching to junior network engineering and operations staff.
• Serve in an on-call capacity after standard business hours, with the critical operational requirement to respond rapidly to emergency network outages or degradation.
Requirements
- Bachelor's degree in a technical discipline (Computer Science, Electrical Engineering, Information Technology, or a related field).
- Alternative Experience Substitution**: A minimum of eight (8) additional years of direct network engineering experience can substitute for a relevant technical degree.
- Relevant Experience**: Minimum of fifteen (15) years of progressive, relevant experience in enterprise-scale network design, implementation, and operations.
- Technical Leadership**: Proven management and leadership capabilities, with a history of guiding multi-stakeholder technical projects, contractors, and agency partners to successful outcomes.
- Federal Security Clearance**: Eligible for a Secret Security Clearance (Active Secret Clearance is highly preferred).
- Operational Availability**: Willingness and ability to work primarily on-site in Washington, DC, and support occasional local travel (MD, VA area) and emergency after-hours on-call rotations.
A highly qualified candidate will possess a modern blend of traditional routing/switching skills, advanced cloud credentials, and federal compliance experience:
- Traditional Networking Protocols: TCP/IP, BGP, OSPF, EIGRP, VLANs, STP/RSTP, MPLS, ISIS, L2VPN, SD-WAN, and high-availability design.
- Physical & Virtual Platforms: Cisco Catalyst and Nexus switches, Juniper routing platforms, F5 Big-IP Local Traffic Managers (LTM), Palo Alto Next-Generation Firewalls, and Cisco Secure Firewalls.
- AWS Cloud Engineering: Amazon EC2, S3, VPC (subnets, route tables, security groups), AWS Direct Connect, Transit Gateway, Route 53, RDS, Lambda, AWS IAM, KMS, Security Hub, Control Tower, GuardDuty, and FinOps cost-governance structures.
- Automation, IaC & DevOps: Terraform, Ansible, Python scripting, AWS CloudFormation, YAML, JSON, Git version control, and CI/CD pipelines.
- Federal & Compliance Frameworks: OMB Circular A-130, FISMA, FedRAMP, NIST SP 800-53, DoD STIGs, CIS Benchmarks, Zero Trust Architecture guidelines, and CyberArk privileged access controls.
Preferred & Recommended Professional CertificationsTo validate the necessary hybrid expertise, candidates are expected to maintain or pursue industry certifications across networking, cloud, and security domains:
- Core Enterprise Networking (One or more): Cisco CCNP (Enterprise/Routing & Switching), Cisco CCIE, Juniper JNCIP (JNCIP-ENT/JNCIP-SEC), or Juniper JNCIE.
- AWS Cloud Engineering (Highly recommended): AWS Certified Advanced Networking - Specialty, AWS Certified Solutions Architect - Professional, or AWS Certified Security - Specialty.
- Federal Cybersecurity Compliance (Highly recommended): DoD Approved 8570 Information Assurance Technician Level II (IAT-II) certifications, such as CompTIA Security+ CE, CySA+, GSEC, or higher (e.g., CISSP).
Location and Schedule- Location: Washington, DC
- Schedule: 40 hours per week, Monday through Friday, with core working hours from 9:00 a.m. to 3:00 p.m. local time.
- Security Requirement: Secret Clearance
- Travel: 10-15%
Salary: $ 150K to $170K
Benefits: Concept Solutions offers a competitive benefits and salary package you would receive from a large company. We offer health, dental, vision and life insurance, as well as a comprehensive 401(k) plan with matching and immediate vesting.