user avatar

Network Engineer (SME)

TEKsystems c/o Allegis Group

Posted today

Job Requirements

Fort Belvoir, VA
Top Secret/SCI Polygraph not specified
Senior Level Career (10+ yrs experience)
$150,000 - $180,000

Job Description

TEKsystems is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio.

Clearance: Must have an active TS/SCI clearance at time of consideration. U.S. Citizen is a must.

Primary Responsibilities:

The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing.

Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks.
Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
Understanding of NIAP approved list and monitors for changes
Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation.
Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection.
Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling.
Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure.
Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission.

Qualifications:
Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree.

12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments

Active TS/SCI Clearance

Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP).

Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP

Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF).

Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles.

Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies.

Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization.

Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN).

Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs).

Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations.

Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).

1.1. MISSION
DTRA is a combat support agency enabling the United States (U.S.) Government and its international partners to counter and deter Weapons of Mass Destruction (WMD). The DTRA mission is to safeguard the United States and its allies from global weapons of mass destruction and improvised threats by integrating, synchronizing and providing expertise, technologies and capabilities.
The ITD provides enabling and secure technologies, applications, and services anywhere, to our workforce, mission partners, and external customers to effectively deliver relevant data, information, and situational awareness to successfully perform the Countering Weapons of Mass Destruction and Emerging Threats mission.

This TO supports the ITD’s Mission Information Technology (IT-MT) Department. IT-MT enables innovation through an agile approach by providing reliable, resilient, secure, and adaptable mission information technology through implementation of technology solutions that directly support the Agency's mission and enhances communications and information sharing with our partners across the Countering Weapons of Mass Destruction and emerging threats mission space. IT-MT also manages DTRA ABQ regional IT Division responsible for delivering fixed and rapidly deployable IT network environments and engineering solutions providing mission enabling capabilities across all security enclaves in support of RD test events throughout DTRA test ranges.

1.2. BACKGROUND
DTRA’s ITD is responsible for providing Agency-wide information technology services, supporting in excess of 5,200 world-wide Agency customers utilizing Unclassified (NIPRNet), Secret (SIPRNet), and Top Secret/Sensitive Compartmented Information (JWICS) networks. DTRA personnel supporting the Agency’s mission require enterprise, common-use and custom-developed mission solutions across the technology lifecycle from design to delivery, sustainment, and customer support in on-premises, hybrid and cloud hosting environments. The ITD continually innovates and optimizes technology solutions to support the needs of Agency customers, including internal and external mission partners, first responders, Combatant Commands (COCOMS), and other U.S. Government entities. The ITD’s intent is to provide seamless and efficient delivery of IT services and advanced methods of deploying, operating and sustaining CWMD and improvised-threat solutions.

Eligibility requirements apply to some benefits and may depend on your job
classification and length of employment. Benefits are subject to change and may be
subject to specific elections, plan, or program terms. If eligible, the benefits
available for this temporary role may include the following:

• Medical, dental & vision
• Critical Illness, Accident, and Hospital
• 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
• Life Insurance (Voluntary Life & AD&D for the employee and dependents)
• Short and long-term disability
• Health Spending Account (HSA)
• Transportation benefits
• Employee Assistance Program
• Time Off/Leave (PTO, Vacation or Sick Leave)
group id: 10105424
Find TEKsystems c/o Allegis Group on Social Media
Recruiters
user avatar
About Us
We’re partners in transformation. We help customers activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services and real-world application, we work with progressive leaders to drive change. That’s the power of true partnership. TEKsystems is an Allegis Group company.

TEKsystems c/o Allegis Group Jobs


Job Category
IT - Networking
Clearance Level
Top Secret/SCI