Overview
We are seeking a Senior Network Engineer to design, implement, secure, and support enterprise network infrastructure across LAN/WAN/WiFi, datacenters, and cloud connectivity within a CMMC-regulated environment. This role requires deep technical expertise in enterprise networking plus hands-on experience supporting NIST 800-171 controls and CUI (Controlled Unclassified Information) boundary protection.
Key Responsibilities
- Design, implement, and maintain enterprise network infrastructure (LAN/WAN/WLAN) in alignment with CMMC/NIST 800-171 requirements.
- Lead the design and implementation of Cisco SD-Access (SDA) across the environment, including DNA Center-managed fabric (wired and wireless), SGT/TrustSec-based segmentation, and fabric-based CUI boundary enforcement.
- Manage and optimize routing and switching environments (SD-WAN, BGP, OSPF, EIGRP, VLANs, STP, HSRP/VRRP).
- Configure and support firewalls, VPNs, and network security controls enforcing CUI boundary segmentation.
- Design and maintain network architecture supporting CUI enclaves, including access control, encryption in transit, and audit logging per NIST 800-171 / DFARS .
- Lead network upgrades, migrations, and infrastructure projects with attention to compliance boundary impact.
- Support and troubleshoot network performance issues and outages (root cause analysis).
- Monitor network health using tools like SolarWinds / ThousandEyes (or similar), including compliance-relevant traffic visibility and alerting.
- Maintain network documentation: diagrams, IP schema, standards, runbooks, and System Security Plan (SSP) network artifacts.
- Support CMMC self-assessment or C3PAO assessment activities by providing network evidence, diagrams, and control narratives.
- Work with service providers for circuit turn-ups, troubleshooting, and escalations.
- Ensure high availability, redundancy, and disaster recovery readiness.
- Mentor junior engineers and provide technical guidance.
- Participate in on-call rotation and after-hours maintenance.
Cloud Networking (AWS / Azure)
- Design and support cloud network architecture: AWS VPC / Transit Gateway / Route Tables / NACLs / Security Groups; Azure VNet / VNet Peering / UDR / NSGs / Cloud Firewall.
- Implement secure hybrid connectivity: IPsec site-to-site VPN, AWS Direct Connect / Azure ExpressRoute.
- Implement cloud segmentation and secure routing patterns specifically for CUI-handling workloads.
- Support cloud security integrations: centralized logging/monitoring, network traffic visibility and alerting mapped to NIST 800-171 controls.
- Partner with cloud engineering and compliance/GRC teams to ensure compliant connectivity for CUI workloads.
Required Qualifications
- Bachelor's degree in IT/Computer Science or equivalent experience.
- 7+ years of hands-on enterprise network engineering experience.
- Demonstrated experience supporting a network environment under CMMC / NIST 800-171 / DFARS requirements — implementation or assessment support, not just familiarity.
- Strong knowledge of routing and switching (Cisco); TCP/IP, subnetting, DNS, DHCP, InfoBlox; WAN technologies (DMVPN, SD-WAN, DIA, broadband); wireless networking (Cisco/Meraki).
- Experience with firewalls (Palo Alto / Cisco ASA/FTD), VPN (site-to-site, remote access), and network segmentation for regulated/CUI environments.
- Strong troubleshooting skills using packet capture tools (Wireshark/tcpdump).
- Experience contributing to or supporting SSP, POA&M, or CMMC assessment documentation.
- Excellent communication and stakeholder management skills.
Preferred Qualifications
- CMMC RP, CCP, or CCA credential (or actively pursuing).
- CCNP / CCIE (Enterprise or Security).
- PCNSE / NSE.
- SD-WAN experience (Viptela, etc.).
- Automation experience (Python, Ansible, Terraform, API-based networking).
- NAC experience (Cisco ISE, ClearPass).
- Prior experience on a DoD/federal contractor network supporting an active CMMC assessment cycle.