R

Principal Network Engineer

RocketForce Technologies LLC $150K–$220K/yr

3 h ago
network-engineer Principal (10+ yrs) Full-time
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Principal Network Engineer will design and oversee the network architecture across five sites, including LAN, WAN, and security infrastructure. They are responsible for directing outsourced partners and ensuring compliance with CMMC, ITAR, and DFARS standards.

What they look for

Network Architecture SD-WAN LAN Switching Enterprise Wireless Zero Trust Network Access Micro-segmentation CMMC Compliance ITAR DFARS Packet Shaping QoS Vendor Management Network Security Infrastructure Migration UCaaS

Requirements

Candidates must have over 8 years of experience in enterprise network design and hands-on expertise in SD-WAN, wireless, and network security. U.S. Person status is required due to ITAR data access requirements.

Full description

The Principal Network Engineer is Rocketdyne's subject matter expert, architect, and owner for network architecture across all five sites — LAN, wireless, WAN/SD-WAN, and network-layer security capabilities (packet shaping/QoS, local internet breakout, zero trust network enforcement) that a modern, multi-site aerospace/defense manufacturer needs. This role sets network architecture and standards and directs the outsourced delivery partners who perform day-to-day network operations, break/fix, and moves/adds/changes. It carries no direct-report headcount, but it does carry real management authority: this person directs and is accountable for the output, quality, and schedule of outsourced network delivery partners. Zero trust strategy itself is owned by the Principal Cybersecurity Engineer & Architect; this role is the network-side technical counterpart that implements and operates that strategy at the network layer. The role is central to the TSA exit — replacing L3Harris-inherited network infrastructure and connectivity with a right-sized, Rocketdyne-owned network — and to the ongoing CMMC Level 2 / ITAR / DFARS compliance posture, since network segmentation and access control are core controls in that framework.

Key Responsibilities

Network Architecture & Standards

  • Own end-to-end network architecture across all five sites — LAN switching, wireless, and WAN/SD-WAN design
  • Design and maintain the SD-WAN architecture, including transport diversity, application-aware routing, and local internet breakout strategy to reduce backhaul dependency and improve site-level resiliency
  • Define packet shaping and QoS standards to prioritize latency-sensitive traffic (voice, video, real-time engineering/manufacturing systems) across the WAN
  • Set enterprise wireless standards (coverage, security, guest/BYOD segmentation) consistent across all sites
  • Maintain network architecture documentation, standards, and reference designs so the environment doesn't drift back into ad hoc, inherited configuration
  • Design and implement Teams Phone (or equivalent UCaaS), SBC and SIP trunking design, and PSTN connectivity strategy across all sites, ensuring voice traffic is correctly prioritized within the broader QoS design

Zero Trust & Network Security

  • Implement and operate the network-layer components of the zero trust architecture — identity-aware network access enforcement and micro-segmentation — to the strategy and standards owned by the Principal Cybersecurity Engineer & Architect
  • Design network segmentation to support CMMC Level 2 / ITAR / DFARS boundary and CUI data-flow requirements, working from the control framework and segmentation strategy set by cyber architecture/GRC
  • Partner with the Principal Cybersecurity Engineer & Architect as the network-side technical counterpart on zero trust design — translating security strategy into network configuration, routing, and segmentation, and flagging network-layer constraints or trade-offs back into that strategy
  • Execute network-layer containment actions (segmentation, isolation) in support of the security incident response plan owned by cybersecurity

TSA Exit & Migration

  • Lead technical design and execution oversight for replacing L3Harris-inherited network infrastructure and circuits with Rocketdyne-owned network infrastructure across all five sites
  • Sequence site cutovers to minimize downtime for engineering, manufacturing, and business operations during the TSA exit window
  • Validate WAN/SD-WAN, wireless, and segmentation architecture is fully independent of L3Harris infrastructure ahead of TSA expiration

Outsource Partner Management

  • Direct and manage outsourced network delivery partners performing day-to-day operations, monitoring, break/fix, and moves/adds/changes across all sites
  • Own technical acceptance of outsourced partner deliverables — review, test, and approve network designs and configuration changes before they move to production
  • Set technical priorities and work assignments for outsourced partner teams, translating the network architecture roadmap into partner-executable scopes of work
  • Escalate and manage partner performance issues (quality, schedule, cost) in partnership with vendor management/procurement
  • Evaluate outsourced partner statements of work, circuit/carrier proposals, and level-of-effort estimates for technical soundness before commitment

Required Qualifications

  • 8+ years in network engineering/architecture roles, with demonstrated ownership of enterprise network design (not just operations)
  • Deep hands-on expertise across LAN switching, enterprise wireless, and WAN/SD-WAN platforms
  • Direct experience designing and implementing SD-WAN architectures, including local internet breakout strategies
  • Experience with packet shaping/QoS design for mixed voice, video, and real-time application traffic
  • Experience implementing zero trust network access (ZTNA) and micro-segmentation to a security team's architecture and standards
  • Working knowledge of CMMC, ITAR, and/or DFARS network segmentation and boundary requirements, and demonstrated ability to partner effectively with cyber/compliance teams
  • U.S. Person status required (ITAR data access)
  • Demonstrated experience directing and managing outsourced/MSP network delivery partners — assigning work, reviewing deliverables, and holding partners accountable for quality and schedule without formal supervisory authority over them

Preferred Qualifications

  • Multi-site aerospace, defense, or complex discrete manufacturing network experience
  • Experience replacing or migrating off inherited network infrastructure in a carve-out, divestiture, or M&A context
  • Vendor-specific certifications (e.g., CCNP/CCIE, or equivalent for the SD-WAN/wireless platforms in use)
  • Experience integrating network architecture with a broader zero trust security program alongside a cybersecurity architect

Similar roles