^E01 Network Engineer IV
Remote
Job Summary
Design, implement, and sustain the hybrid Azure Government network architecture connecting cloud-hosted services, on-premises resources, and remote users for the Digital Engineering Ecosystem. Engineer resilient private connectivity using Azure ExpressRoute, site-to-site VPN, and redundant gateways while configuring Border Gateway Protocol routing, route filtering, and failover mechanisms. Develop and maintain IP address-management plans, network segmentation policies, and least-privilege security controls including Network Security Groups, Application Security Groups, and Azure Firewall rules. Lead the engineering of resilient Azure virtual networks, private DNS zones, and remote-access capabilities integrated with identity and multifactor authentication. Automate network infrastructure as code using Bicep, Terraform, and PowerShell to integrate with DevSecOps processes, ensuring compliance with NIST SP 800-171, RMF, and DISA STIG requirements. Produce and maintain RMF evidence, network diagrams, and rule registers while coordinating with cybersecurity engineers, cloud architects, and Risk Management Framework personnel. Support technical reviews, change-control boards, and incident response activities to ensure operational excellence and contractual deliverables.
Required Qualifications
- Active Secret clearance
- Bachelor's degree in computer science, information systems, engineering, cybersecurity, or a related field (or equivalent)
- 8-10 years of relevant experience (or a Master's degree with 6-8 years of relevant experience)
- Extensive experience designing, implementing, securing, and sustaining enterprise hybrid-cloud networks
- Hands-on experience with Azure virtual networks, subnets, peering, route tables, Network Security Groups, Application Security Groups, Azure Firewall Policy, VPN Gateway, ExpressRoute, private endpoints, private DNS, and network monitoring
- Strong knowledge of TCP/IP, BGP, IPsec, DNS, routing, switching, firewalls, NAT, network segmentation, load balancing, high-availability design, and hybrid name resolution
- Experience developing and maintaining network diagrams, traffic-flow documentation, firewall and security-group rule matrices, IP-address plans, implementation plans, rollback plans, and test procedures
- Experience analyzing effective security rules and troubleshooting interactions among NSGs, Azure Firewall, routing, NAT, private endpoints, DNS, and hybrid connectivity
- Experience implementing network and security-rule configurations through infrastructure as code, source control, peer review, and controlled deployment pipelines
- Experience with enterprise and Azure-native monitoring, logging, performance analysis, and incident troubleshooting
- Working knowledge of NIST SP 800-171, NIST SP 800-53, RMF, CMMC, DoD Cloud SRG, and applicable
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.