INNOVIM

Senior Network Engineer - CBO

INNOVIM United States · $115K–$142K/yr

Defense & Space · 51-200 employees

10 h ago
network-engineer Principal (10+ yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Network Engineer provides advanced engineering and advisory leadership for a Cisco-based enterprise network, focusing on secure architecture design and Zero Trust adoption. The role involves leading security assessments, managing network monitoring and vulnerability programs, and collaborating with cross-functional teams to ensure network resilience.

What they look for

Cisco routing Cisco switching Network security Zero Trust NIST SP 800-53 NIST SP 800-207 802.1X Cisco ISE Network architecture Vulnerability management Firewall optimization SIEM NDR DNS administration Change control Technical advisory

Requirements

Candidates must possess a Bachelor's degree and 8–10 years of enterprise network engineering experience, with active Cisco CCNP or CCIE certification. Proficiency in NIST security standards, Zero Trust principles, and Cisco network security technologies is required, along with U.S. citizenship or permanent residence status.

Benefits

Health insurance Dental coverage Vision coverage Retirement savings Paid time off Professional development support

Full description

Location Washington, DC — hybrid; on-site as required by task assignment Employment Type Full-time — contingent upon contract award Salary Range $92,000 – $110,000 Clearance / Suitability Public Trust (Tier 2); U.S. citizenship or permanent residence required

Position Summary

The Senior Network Engineer provides advanced engineering, operational, and advisory leadership for a U.S. legislative branch agency's Cisco-based enterprise network. Serving as a senior technical advisor, the role leads the design and implementation of secure network architectures, drives Zero Trust adoption, and leads security assessments and audits — strengthening the security, reliability, and resilience of the network in alignment with NIST SP 800-53, NIST SP 800-207, and Cisco best practices.

Key Responsibilities

  • Design, implement, operate, and optimize secure Cisco network architectures across core, distribution, access, and edge layers for high availability, scalability, and resilience.
  • Serve as senior technical advisor to stakeholders, collaborating with cybersecurity, cloud, and operations teams to resolve complex network issues and improve architecture.
  • Engineer and enforce Zero Trust principles per NIST SP 800-207 — network segmentation, micro-segmentation, least-privilege and identity-aware access, and 802.1X integration with enterprise identity services.
  • Lead or participate in security assessments, audits, and compliance reviews; provide evidence, documentation, and remediation support.
  • Implement and manage network monitoring, logging, and alerting, integrating with enterprise SIEM and Network Detection and Response (NDR) tools.
  • Establish and maintain a structured vulnerability management and device lifecycle program (patching, firmware, remediation).
  • Harden network devices to secure configuration baselines; secure public-facing and perimeter assets (firewall optimization, restricted access, MFA).
  • Continuously evaluate and enhance network security posture through emerging best practices, threat intelligence, and Cisco security innovations.
  • Ensure all network changes follow formal change control with security impact analysis; perform RCA for incidents.
  • Develop and maintain Network SOPs, comprehensive network diagrams, and configuration baselines; administer and troubleshoot enterprise DNS.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or Engineering (Master's preferred; equivalent experience considered).
  • Minimum 8–10 years of enterprise network engineering experience, including a senior or lead role.
  • Deep expertise in Cisco routing, switching, and network security; Zero Trust (NIST SP 800-207); NIST SP 800-53; and 802.1X/NAC (e.g., Cisco ISE).
  • Demonstrated ability to advise senior stakeholders and lead security assessments and audits.
  • Active Cisco CCNP (CCIE a plus) or equivalent demonstrable expertise; CompTIA Security+ or higher.
  • S. citizenship or permanent residence status; ability to obtain a Public Trust (Tier 2) determination.

Preferred Qualifications

  • CCIE Enterprise Infrastructure or CCIE Security.
  • Hands-on experience with Cisco ISE, TrustSec, and MACsec; Catalyst 9300 StackWise architectures.
  • Experience with next-generation firewalls (Check Point or Palo Alto), NDR, and SIEM (Microsoft Sentinel).
  • Experience leading network modernization and Zero Trust implementations in federal environments.
  • Prior experience supporting Congressional / legislative branch agencies.

Clearance, Suitability & Security

U.S. citizenship or permanent residence status is required. The selected candidate must be able to obtain and maintain a Public Trust (Tier 2) suitability determination and will undergo an FBI criminal background check and U.S. Capitol Police fingerprinting prior to starting work, in accordance with the contract's security requirements. Remote work is authorized; however, on-site presence at the customer's facilities in Washington, DC (and, as needed, data-center/computing facilities in Ashburn, VA and Manassas, VA) may be required based on task assignment. Local travel to these sites is non-reimbursable. Core hours are 9:00 AM–6:00 PM ET, Monday–Friday; occasional after-hours or weekend maintenance activity may be required.

Compensation

Salary Range: $115,000 – $142,000, commensurate with experience, education, and certifications. INNOVIM offers a comprehensive benefits package including health, dental, and vision coverage, retirement savings, paid time off, and professional development support.

Similar roles