user avatar
Posted today

Job Requirements

Colorado Springs, CO
Top Secret/SCI Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

We are seeking a highly experienced and technically exceptional Network Engineering Subject Matter Expert (Engineer 4) to serve as a trusted technical advisor in a Systems Engineering and Technical Assistance (SETA) capacity directly supporting the Government Chief Technology Officer (CTO) and Next Generation Environment (NGE) leadership in the Missile Defense Agency.

About the Program

Join a mission-critical, high-visibility program to architect, build, and secure the Agency's Next Generation Environment (NGE). This initiative establishes a secure, resilient, and flexible hybrid, multi-cloud ecosystem designed to support national security objectives for years to come.

Within the NGE, the transport network and core enterprise network services, including DNS, DHCP, and IP Address Management (DDI)-serve as the foundational backbone and enforcement fabric of the Agency's Zero Trust Architecture (ZTA). As the Network Engineering SME, you will guide technical decisions, shape transport and core network services roadmaps, and oversee multi-vendor integration efforts across commercial cloud providers (AWS, Azure), on-premises VMware Cloud Foundation (VCF) environments, and DISA/DODNET boundaries.

Position Summary

In this role, you will provide critical oversight and technical direction for the NGE Network and Transport Design Area. You will ensure that all hybrid networking components-spanning software-defined wide area networks (SD-WAN), software-defined data centers (SDDC), enterprise DDI architectures, multi-cloud transit networks, application delivery controllers, and next-generation firewalls-are designed, integrated, and accredited to form a cohesive, secure, and interoperable system.

Lead the architecture and governance of the enterprise DDI solution using Infoblox as the Authoritative Source of Truth (ASOT) to automate IP address management and name resolution across hybrid enclaves. Simultaneously, oversee the technical integration of NGE enclaves with DODNET boundaries, ensuring strict compliance with DISA Connection Approval Processes (CAP) and Versa-based SD-WAN gateways. Throughout these efforts, serve as the principal technical liaison translating senior Government leadership requirements into actionable engineering solutions delivered by contractors and vendors

Key Responsibilities
  • Serve as a senior technical authority in architectural review boards (ARBs), evaluating and validating vendor-proposed network, boundary, and DDI designs against the NGE Master Architecture and DoD Zero Trust reference mandates.
  • Design and document holistic, end-to-end transport solutions across AWS, Azure, and on-premises VMware Cloud Foundation (VCF), defining routing topologies, traffic engineering, and resilient transit patterns.
  • Architect and govern the enterprise Infoblox DDI infrastructure as the centralized Authoritative Source of Truth (ASOT). Design split-horizon DNS, DNSSEC, Anycast routing, and dynamic IPAM synchronizations across multi-cloud and on-prem segments.
  • Architect and integrate micro-segmentation, software-defined perimeters, and secure access service edge (SASE) capabilities aligned with DISA Thunderdome standards.
  • Oversee the technical integration of NGE enclaves with DODNET boundaries, ensuring compliance with DISA connection approval processes (CAP) and Versa-based SD-WAN gateways.
  • Guide the deployment and policy harmonization of F5 BIG-IP (ASG/AWAF) and Palo Alto Networks NGFWs across on-premises and cloud boundaries to enforce Layer 7 inspection and zero-trust controls.
  • Facilitate technical exchange meetings (TEMs) with integration contractors and software vendors (Cisco, Versa, VMware, Infoblox, F5, Palo Alto). Act as the final escalation authority for complex, cross-domain routing and name resolution issues.


The position requires deep technical knowledge, practical engineering skills, and system-level architectural design experience across the following functional areas and vendor platforms:

  • Design and operation of Infoblox as the Authoritative Source of Truth (ASOT). Integration with AWS Route 53 Resolvers/Private Hosted Zones, Azure Private DNS Resolver, and VMware NSX IP pools. Automation of DDI via REST APIs and Infrastructure as Code.
  • Transport-independent fabric engineering, overlay routing policies, application-aware routing, and integration with DODNET SD-WAN boundaries utilizing Versa gateways.
  • Multi-tenant micro-segmentation, distributed firewalling (DFW), logical routing (T0/T1 gateways), and automated segment IP provisioning tied to Infoblox IPAM
  • Scalable hub-and-spoke transit networks, routing domain segmentation, and automated routing propagation between cloud enclaves and on-premises cores.
  • Implementation of F5 as an Application Security Gateway (ASG), SSL/TLS offloading and inspection, dynamic access control, and Layer 7 protection for enterprise services.
  • Deployment of physical and virtual (VM-Series) next-generation firewalls at perimeter inspection points, establishing automated threat prevention and zero-trust micro-perimeters.
  • Alignment with DISA Thunderdome reference standards, implementing identity-aware network segmentation, secure remote access proxies, and continuous endpoint posture verification


Experience & Education

Education & Years of Experience: Bachelor of Science degree in Network Engineering, Computer Science, Computer Engineering, Systems Engineering, or a related technical discipline with 12 years of progressive engineering and architectural experience (or Master's degree with 10 years of experience).
  • Enterprise DDI & DNS Experience: Demonstrated track record architecting enterprise-grade DNS, DHCP, and IPAM solutions, specifically utilizing Infoblox as an Authoritative Source of Truth (ASOT) in hybrid cloud environments.
  • Hybrid Cloud Track Record: Demonstrated experience designing, deploying, and securing enterprise networks across AWS, Azure, and on-premises VMware VCF / NSX environments.
  • Classified Environment Experience: Proven track record designing, integrating, and accrediting network transport and boundary security solutions within classified DoD (TS//SCI) enclaves.


Security Clearance & Compliance
  • Clearance: Must possess an active Top Secret security clearance with current SCI eligibility (TS/SCI).
  • DoD Compliance: Must meet DoD 8140/8570 requirements for an IAT Level III or IASAE Level II position. An active (ISC)² CISSP certification is required.


Desired Qualifications (Highly Valued)
  • Infoblox Core Administrator / Engineer (CDCA / CICA)
  • Cisco Certified Internetwork Expert (CCIE Enterprise Infrastructure)
  • Palo Alto Networks Certified Network Security Engineer (PCNSE)
  • F5 Certified Technology Specialist (F5-CTS)
  • VMware Certified Advanced Professional (VCAP) - Network Virtualization
  • AWS Certified Advanced Networking - Specialty
  • Microsoft Certified: Azure Network Engineer Associate (AZ-700)
  • Demonstrated experience managing Infoblox, firewalls, and cloud routing through Infrastructure as Code (Terraform providers, Ansible collections, Python automation using REST/WAPI).
  • Deep operational understanding of DISA STIGs, DODNET connection requirements, NIST SP 800-207, and practical engineering experience implementing DISA Thunderdome zero-trust capabilities
  • Prior experience in a SETA, A&AS, or direct engineering advisory role supporting Government Program Managers, Directors, or CTOs.


The pay range for this position in Colorado is $130,000/year to $190,000/year; however, base pay offered may vary depending on established government contract ranges, job-related knowledge, skills, and experience, and other factors. MTSI also offers a full range of medical, financial, and other benefits, dependent on the position offered. Base pay information is based on market location. Applications will be accepted on an ongoing basis. This posting will be renewed periodically until the position is filled.

#LI-AT1
group id: RTL041421
Find Modern Technology Solutions, Inc. on Social Media
Recruiters
user avatar
About Us
Modern Technology Solutions, Inc. (MTSI) is a 100% employee-owned technology firm specializing in Digital Engineering, Space Systems, Unmanned Systems, Flight Test Engineering, Modeling and Simulation, Cybersecurity, and DevOps for vital defense and intelligence programs. MTSI excels in delivering premier solutions to address global challenges. Founded in 1993, MTSI now operates across 20+ global offices and field sites. Perks of being part of MTSI's employee-ownership culture include: • 6% 401k matching with immediate vesting • Semi-annual performance bonuses • Company-funded Employee Stock Ownership Plan (ESOP) • 20 days of paid time off (PTO), 10 paid holidays, and flexible work schedules • Optional zero-deductible BC/BS insurance with FSA • Certified as a top workplace Join us in a company with a long-term strategy and a commitment to our employee-owners, free from external shareholders' demands.

Modern Technology Solutions, Inc. Jobs


Clearance Level
Top Secret/SCI