Network Engineer - CBO
INNOVIM United States · $92K–$110K/yr
Defense & Space · 51-200 employees
About the role
The Network Engineer will design, implement, and maintain secure Cisco-based network architectures while enforcing Zero Trust principles and federal cybersecurity standards. They will also perform continuous monitoring, vulnerability assessments, and provide technical support for network incidents and infrastructure optimization.
What they look for
Requirements
Candidates must have at least 8 years of hands-on enterprise network engineering experience in Cisco environments and a bachelor's degree in a relevant field. Proficiency in NIST security controls, Zero Trust architecture, and active Cisco certification (CCNP or CCNA) are required.
Benefits
Full description
Location Washington, DC — hybrid; on-site as required by task assignment Employment Type Full-time — contingent upon contract award Salary Range $92,000 – $110,000 Clearance / Suitability Public Trust (Tier 2); U.S. citizenship or permanent residence required
Position Summary
The Network Engineer provides secure engineering and operational support for a U.S. legislative branch agency's Cisco-based enterprise network. The role designs, implements, and sustains secure network architectures that enforce Zero Trust principles — segmentation, micro-segmentation, and least-privilege access — while hardening and continuously monitoring switches, routers, and perimeter systems in accordance with federal cybersecurity standards (NIST SP 800-53 and NIST SP 800-207) and Cisco best practices.
Key Responsibilities
- Operate, optimize, and troubleshoot the Cisco core, distribution, access, and edge network infrastructure to ensure reliability, performance, and availability.
- Configure and manage routing, switching, VLANs, DNS, DHCP, and VPN services with secure, standards-aligned configurations.
- Implement and maintain network security controls aligned with NIST SP 800-53 (AC, CM, SC, AU control families).
- Enforce Zero Trust architecture per NIST SP 800-207, including network segmentation, micro-segmentation, and continuous verification of users and devices.
- Deploy and manage 802.1X port-based network access control (NAC) and least-privilege, identity-aware access across all network layers.
- Harden network devices to secure configuration baselines (e.g., Cisco Secure Configuration Guides); secure perimeter and public-facing assets through ingress/egress filtering, firewall rule optimization, and MFA for administrative access.
- Configure centralized logging and forward logs to the enterprise SIEM; support continuous, real-time (24/7) monitoring and alerting.
- Conduct continuous monitoring and vulnerability assessments aligned with the NIST Risk Management Framework (RMF); coordinate patching, firmware updates, and remediation.
- Support incident response with network-level analysis, containment actions, and forensic data collection.
- Perform root cause analysis (RCA) for network incidents; develop and maintain network diagrams, configuration baselines, and Standard Operating Procedures (SOPs).
- Serve as technical adviser on complex service-desk tickets, collaborating with cloud, Microsoft engineering, and cybersecurity teams.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field (equivalent experience considered).
- Minimum 8 years of hands-on enterprise network engineering experience in Cisco environments.
- Demonstrated expertise in routing and switching, VLANs, DNS/DHCP, VPNs, and 802.1X network access control.
- Working knowledge of NIST SP 800-53 controls and NIST SP 800-207 Zero Trust Architecture.
- Active Cisco certification (CCNP or CCNA) or equivalent demonstrable expertise.
- S. citizenship or permanent residence status; ability to obtain a Public Trust (Tier 2) determination.
Preferred Qualifications
- CCNP Enterprise or CCNP Security; CompTIA Security+ (DoD 8140/8570 IAT Level II).
- Experience with Cisco ISE, TrustSec/MACsec, and Catalyst 9300 StackWise environments.
- Experience with next-generation firewalls (Check Point or Palo Alto) and secure web gateways (e.g., iBoss).
- Familiarity with SIEM (Microsoft Sentinel or Splunk) and network monitoring tools (SolarWinds, ThousandEyes).
- Prior experience supporting federal or Congressional / legislative branch environments.
Clearance, Suitability & Security
U.S. citizenship or permanent residence status is required. The selected candidate must be able to obtain and maintain a Public Trust (Tier 2) suitability determination and will undergo an FBI criminal background check and U.S. Capitol Police fingerprinting prior to starting work, in accordance with the contract's security requirements. Remote work is authorized; however, on-site presence at the customer's facilities in Washington, DC (and, as needed, data-center/computing facilities in Ashburn, VA and Manassas, VA) may be required based on task assignment. Local travel to these sites is non-reimbursable. Core hours are 9:00 AM–6:00 PM ET, Monday–Friday; occasional after-hours or weekend maintenance activity may be required.
Compensation
Salary Range: $92,000 – $110,000, commensurate with experience, education, and certifications. INNOVIM offers a comprehensive benefits package including health, dental, and vision coverage, retirement savings, paid time off, and professional development support.
ime off, and professional development support.
Similar roles
-
Senior Network Engineer (Hybrid Working)
Resultant Indianapolis, Indiana, United States
-
Senior Azure Network Engineer (m/f/d)
Redcare Pharmacy Cologne, North Rhine-Westphalia, Germany
-
Senior Network Engineer
IP Secure, LLC San Antonio, Texas, United States
-
Network Engineer - Enterprise Infrastructure
Quast Ltd Corsham, England, United Kingdom · £143K/yr
-
Sr. Network Engineer -Information Technology - Shift 1
NEW CARROT FARMS LLC Bakersfield, California, United States · $100K–$125K/yr
-
IP Network Engineer (NOC)
Tieto Rio de Janeiro, Rio de Janeiro, Brazil