Network Engineer
Canadian Breaks Consulting LLC Amarillo, Texas, United States · $140K–$180K/yr
Business Consulting and Services · 2-10 employees
About the role
The Network Engineer is responsible for designing, engineering, and sustaining enterprise network infrastructure, including routers, switches, and firewalls. They must also resolve complex network issues and ensure the stability, security, and performance of the infrastructure within a high-security environment.
What they look for
Requirements
Candidates must have 10+ years of network engineering experience and hold an active federal security clearance (DOE Q or DoD Top Secret). A bachelor's degree in an IT-related field or equivalent experience is required, along with U.S. citizenship.
Benefits
Full description
Network Engineer – Senior Consultant
About CBC
Canadian Breaks Consulting, LLC is a growing consulting firm based in Amarillo, TX serving clients with customized project management solutions to complex problems on critical projects.
Our Mission: "To plan, manage, and execute projects with hearts, hands, and feet of Christ."
Our Core Values
Integrity: A commitment to Truth with a consistent and uncompromising adherence to strong moral and ethical principles and values.
Excellence: A constant and consistent drive to uphold and raise standards in whatever you do.
Prudence: A commitment to taking the extra step and considering the reasonableness of your actions as well as their consequences.
Stewardship: An unwavering willingness to carefully and responsibly manage interests separate from and greater than your own.
About the Role
Introduction
The Network Engineer designs, engineers, and sustains the enterprise network infrastructure at a National Nuclear Security Administration (NNSA) site in the Texas Panhandle, on one of the most security-sensitive missions in the country. This is a hands-on engineering role: administering and hardening routers, switches, firewalls, VPNs, and wireless infrastructure, engineering complex routing and segmentation strategies, and resolving the difficult problems that surface on a network where availability and security are both non-negotiable. The Network Engineer works alongside client IT, cybersecurity, operations, and vendor personnel, operates within formal configuration control and change management discipline, and documents the network to a standard that withstands audit. This position is fully onsite in the Amarillo, TX area on a 9/80 schedule with every other Friday off and requires an active federal security clearance.
Years of Experience
10+ years of relevant network engineering experience
Qualifications
Required
- 10+ years of relevant network engineering experience, including 5+ years supporting enterprise-scale routing, switching, and firewall infrastructure.
- Active DOE Q clearance or active DoD Top Secret clearance, or previously held either with eligibility for reinstatement, along with the ability to obtain and maintain a DOE Q clearance. U.S. citizenship is required.
- Hands-on command of enterprise routing and switching, including Cisco routers and switches, complex routing strategies using EIGRP, OSPF, and BGP, route redistribution, convergence, and path selection, plus next-generation firewall, VPN, and wireless infrastructure administration.
- Bachelor's degree in an engineering, science, or information technology discipline, or a master's degree in one of those disciplines, or a combination of 10 or more years of relevant education, training, and experience in lieu of a degree. Able to work fully onsite in the Amarillo, TX area, pass a federal background investigation and pre-employment and random drug testing, participate in medical monitoring, and, if assigned scope requires Materials Access Area entry, participate in the Human Reliability Program including a counterintelligence-scope polygraph pursuant to 10 CFR 709.
Preferred
- Prior experience supporting DOE, NNSA, DoD, or other federal secure environments.
- Next-generation firewall depth on Palo Alto or Cisco ASA/FirePower platforms, including high availability configuration, SSL decryption, policy optimization, and IDS/IPS.
- Network access control experience with Cisco Identity Services Engine (ISE), including network access devices, authentication policies, identity groups, and endpoint compliance.
- Cisco Catalyst Center (DNA Center) administration.
- Wireless infrastructure experience with Cisco wireless LAN controllers and access point deployments.
- Administration of load balancers (LTM/GTM), DNS, DHCP, and IP address management (IPAM) systems.
- Unified communications and voice experience with Cisco Unified Communications Manager (CUCM), Unity Connection, voice gateways, and VoIP infrastructure.
- Hybrid and cloud networking experience, including Microsoft Azure virtual networks, ExpressRoute, and peering.
- Network automation and scripting with Python or Perl.
- Monitoring and security tooling experience with Tenable, Splunk, or comparable enterprise platforms, including NOC/SOC integration and telemetry reporting.
- Formal change management experience in ServiceNow or an equivalent platform, including RFC submission and Change Advisory Board participation.
- Accredited classified network or enclave experience, including Risk Management Framework, NIST SP 800-53 controls, and authorization documentation.
- Operational technology or industrial control system network experience, including segmentation and IT/OT boundary security.
- Networking experience supporting physical security systems such as access control, surveillance, and alarm systems.
- Industry certifications such as CCNP or CCIE, PCNSE, or CompTIA Security+.
- Proficient in Windows and Microsoft Office 365 (Excel, Word, Outlook, Power Point and Teams), and have a strong understanding of working within a computer network.
- Experience in organizing technical data in a neat and accurate method.
- Ability to work well and maintain a cooperative attitude in a fast-paced environment and manage multiple priorities.
- Work schedule must be flexible to allow extended hours, off-shift work, and scheduled maintenance windows to accommodate operational requirements.
Key Responsibilities
- Administer, engineer, and sustain enterprise network infrastructure including routers, switches, firewalls, VPNs, wireless, and data center environments.
- Design and implement complex routing and segmentation strategies using EIGRP, OSPF, and BGP, optimizing route redistribution, convergence, and path selection.
- Implement and manage next-generation firewall platforms, including high availability configuration, SSL decryption, policy optimization, and IDS/IPS.
- Configure and perform lifecycle management of network devices, including service packs, patches, hotfixes, firmware, and security configurations.
- Develop lifecycle management plans covering upgrades, patching, maintenance windows, and rollback strategies.
- Monitor network performance and integrity and ensure network stability, reliability, and security.
- Troubleshoot and resolve complex network issues and restore service in accordance with established service levels.
- Administer network access control solutions, network access devices, authentication policies, and identity groups.
- Administer load balancers, DNS, DHCP, and IP address management systems.
- Manage wireless network infrastructure and access point deployments.
- Support voice and VoIP administration, including adds, moves, changes, and troubleshooting.
- Implement and maintain security protections across networked devices, and stay current on IT vulnerabilities and countermeasures.
- Support NOC/SOC integration and telemetry reporting.
- Develop and deploy scalable, resilient network architectures supporting high availability, fault tolerance, and future growth.
- Provide recommendations for network optimization, capacity planning, and infrastructure modernization.
- Maintain network documentation including topology diagrams, configuration baselines, IP address management records, inventories, and change control records.
- Support formal change management processes, including change request submission and Change Advisory Board activities, and participate in change windows and off-hours maintenance.
- Collaborate with client IT, cybersecurity, operations, and vendor personnel, and present complex technical and operational information verbally and in writing.
Pay and Benefits
$140,000-$180,000
- Fully covered Employee+Fam BCBS PPO health insurance
- Fully covered Employee+Fam Dental & Vision Insurance
- 2 weeks PTO
Similar roles
-
Network Engineer
AAC Washington, District of Columbia, United States · $100K/yr
-
Network Engineer
E-Infosol LLC United States
-
Network Engineer
Vailexa Pickering, Ontario, Canada
-
Principal Network Engineer
Nscale San Francisco, California, United States
-
Network Engineer I - Winter (Entry Level)
Vertech Phoenix, Arizona, United States
-
Network Engineer I - Summer (Entry Level)
Vertech Phoenix, Arizona, United States