^E01 Network Engineer IV
EXPANSIA · $124K–$146K/yr
Defense and Space Manufacturing · 51-200 employees
About the role
Design, implement, and maintain a secure hybrid network architecture connecting Azure Government services with on-premises resources and remote users. Lead the engineering of resilient network solutions while ensuring compliance with cybersecurity requirements and RMF standards.
What they look for
Requirements
Requires a Bachelor's degree with 8-10 years of experience or a Master's degree with 6-8 years of experience in enterprise hybrid-cloud networking. Candidates must hold an active Secret clearance and possess extensive hands-on experience with Azure networking and security controls.
Benefits
Full description
Start Date: Immediate
JHNA, CTSi, and EXPANSIA have come together to form a Defense Technology platform named Aether Aerospace focused on delivering high-impact technologies, technology-enabled services and advanced manufacturing solutions to the U.S. Department of Defense and related national security customers. Backed by Falfurrias Management Partners, the platform brings together deep domain expertise across Army, Navy, and Air Force and Space Force programs, digital engineering, systems integration, and specialized manufacturing capabilities.
The combined organization operates as a multi-entity aerospace and defense technology and tech-enabled services and manufacturing enterprise positioned for scalable growth, operational excellence, and long-term value creation.
OVERVIEW
Full-time/Permanent Employee
Location: Remote
As a Network Engineer IV supporting a Digital Engineering Ecosystem (DEE), you will design, implement, secure, document, and sustain the hybrid network architecture connecting Azure Government-hosted services, approved on-premises resources, remote users, engineering applications, data repositories, and shared enterprise services. You will develop network architectures, traffic-flow diagrams, routing designs, private-connectivity solutions, segmentation policies, security-group and firewall rules, private DNS configurations, monitoring capabilities, and implementation specifications supporting the controlled unclassified information environment and planned future expansion.
You will lead the engineering of resilient Azure virtual networks, hybrid connectivity, boundary protection, private service-access patterns, and network automation while coordinating with cloud architects, cybersecurity engineers, DevSecOps teams, system administrators, application owners, and Risk Management Framework personnel. The role requires the ability to connect network design, engineering-data performance, cybersecurity requirements, configuration management, verification evidence, and operational sustainment across cloud and on-premises boundaries.
\n
RESPONSIBILITIES
Hybrid Azure Architecture and Connectivity
• Design, implement, and maintain the hybrid Azure Government network architecture connecting cloud-hosted DEE services with authorized on-premises systems, enterprise services, remote users, and approved external mission partners.
• Engineer resilient private connectivity using approved technologies such as Azure ExpressRoute, site-to-site VPN, redundant gateways, and approved network virtual appliances.
• Configure and troubleshoot Border Gateway Protocol routing, route propagation, user-defined routes, gateway transit, route filtering, failover, and asymmetric-routing conditions.
• Develop and maintain IP address-management, subnetting, route-table, resiliency, and capacity plans that prevent address conflicts and support future environment growth.
Azure Network Architecture and Segmentation
• Design and administer Azure virtual networks, subnets, peering, route tables, NAT, load-balancing services, gateways, and approved hub-and-spoke or Virtual WAN patterns.
• Design and implement secure network segmentation and communication between DEE functional environments using Azure networking services and approved security controls.
• Design and maintain the networks for the Cloud Upload & Staging service that serves as the controlled network boundary between external content sources and the private DEE environment, supporting secure content ingestion and transfer.
• Develop and maintain network architecture diagrams, authorization-boundary diagrams, trust-zone diagrams, data-flow diagrams, ports/protocols/services matrices, and interface-control information.
• Enforce least-privilege north-south and east-west communication and maintain separate management, data, shared-service, staging, and future classified network boundaries.
Security Groups, Firewall Policies, and Rule Governance
• Design, implement, and maintain Azure Network Security Groups (NSGs) for approved subnets and network interfaces, ensuring inbound and outbound traffic is limited to authorized sources, destinations, protocols, and ports.
• Develop and maintain Application Security Groups (ASGs) that logically group workloads by function, security role, application tier, or service type and reduce dependence on individually maintained IP-address rules.
• Design and administer Azure Firewall Policy rule collection groups, including DNAT, network, and application rule collections, using approved service tags, IP Groups, fully qualified domain names, and threat-intelligence settings where appropriate.
• Implement centrally governed security-admin rules when mandatory enterprise rules must be enforced consistently across selected subscriptions, virtual networks, or network groups.
• Maintain a network-rule register containing the rule identifier, control point, source, destination, direction, protocol, port, action, priority, DEE environment, business justification, security-requirement reference, owner, approval authority, review or expiration date, and test evidence.
• Apply least-privilege and default-deny principles and prohibit unrestricted any-to-any rules unless supported by an approved, documented, time-bounded exception.
• Analyze the combined effect of security-admin rules, subnet and network-interface NSGs, Azure Firewall policies, routing tables, NAT rules, private endpoints, and hybrid connectivity controls.
• Review rules periodically and after architecture, application, interface, or mission changes to identify obsolete, duplicative, shadowed, unused, or overly permissive rules.
Private Access, DNS, and Remote Connectivity
• Implement Private Endpoint and Private Link as the preferred access pattern for supported Azure platform services and document approved exceptions to public network exposure.
• Design and maintain Azure Private DNS zones, Azure DNS Private Resolver, DNS forwarding, conditional forwarding, and integration with approved on-premises DNS services.
• Validate routing, firewall policy, name resolution, and service reachability from Azure, on-premises, remote-access, and shared-service locations.
• Integrate approved remote-access capabilities with identity, multifactor authentication, conditional access, device posture, logging, and least-privilege network access requirements.
Monitoring, Troubleshooting, and Performance
• Configure and maintain applicable SIEM integrations and alerts for ExpressRoute and VPN health, route changes, firewall events, denied traffic, packet loss, latency, DNS failures, private-endpoint availability, and abnormal traffic patterns.
• Perform packet capture, next-hop analysis, connection troubleshooting, effective-security-rule analysis, route validation, and end-to-end network performance testing.
• Analyze bandwidth, throughput, latency, packet loss, storage-access patterns, and transfer performance for digital engineering models, technical data packages, simulation outputs, configuration baselines, and other large engineering datasets.
Automation and Configuration Management
• Develop and maintain network infrastructure as code using approved tools such as Bicep, Terraform, Azure Resource Manager templates, PowerShell, Azure CLI, or program-approved automation frameworks.
• Integrate network and security-rule changes with the DEE DevSecOps process, including source control, peer review, automated validation, testing, approval, deployment, rollback, and configuration-baseline management.
• Develop and maintain reusable Infrastructure as Code modules for virtual networks, subnets, NSGs, ASGs, route tables, private endpoints, private DNS, diagnostic settings, firewall policies, and network-rule collections.
Cybersecurity and RMF Support
• Support NIST SP 800-171 Revision 3, NIST SP 800-53 Revision 5, DoW Cloud Computing Security Requirements Guide, applicable DISA STIGs, RMF, and program-specific cybersecurity requirements.
• Produce and maintain RMF evidence including ports/protocols/services inventories, firewall and NSG rule sets, route tables, private-endpoint and DNS inventories, test results, configuration baselines, change records, and monitoring evidence.
• Participate in technical reviews, design reviews, change-control boards, control assessments, vulnerability-remediation activities, incident response, and authorization-package development.
• Coordinate with the ISSM, ISSO, security architect, system architect, cloud engineers, application owners, and assessment personnel to resolve findings and validate network-control implementation.
Operations, Sustainment, and Technical Leadership
• Develop network implementation plans, maintenance procedures, rollback plans, continuity procedures, and disaster-recovery connectivity strategies.
• Plan and execute upgrades and enhancements without disrupting engineering operations or weakening CUI protections.
• Lead troubleshooting of complex incidents spanning Azure, on-premises infrastructure, identity services, DNS, firewalls, routing, application services, and external connections.
• Evaluate network technologies and provide cost, performance, interoperability, security, authorization, and lifecycle recommendations.
Corporate and Program Responsibilities
• Provide technical support to program operational strategies and initiatives that optimize processes, enhance productivity, and ensure quality across program functions.
• Ensure 100% of planned hours are worked and accurately recorded.
• Identify and forward opportunities that may support growth within the work area and participate in growth efforts as requested.
• Ensure contractual deliverables are met or exceeded to the customer's satisfaction.
• Complete the personal development plan (PDP) and actively participate in Staff Meetings and Storytime with the camera on.
• Build productive and positive professional relationships with clients and cross-functional program teams.
• Execute assigned contract requirements in accordance with the contract-specific labor category and requirements.
• Perform other related duties as assigned.
KEY QUALIFICATIONS
Clearance: Active Secret clearance Education and Years of Experience: Bachelor's degree in computer science, information systems, engineering, cybersecurity, or a related field (or equivalent) with 8-10 years of relevant experience, or a Master's degree with 6-8 years of relevant experience.
• Extensive experience designing, implementing, securing, and sustaining enterprise hybrid-cloud networks.
• Hands-on experience with Azure virtual networks, subnets, peering, route tables, Network Security Groups, Application Security Groups, Azure Firewall Policy, VPN Gateway, ExpressRoute, private endpoints, private DNS, and network monitoring.
• Strong knowledge of TCP/IP, BGP, IPsec, DNS, routing, switching, firewalls, NAT, network segmentation, load balancing, high-availability design, and hybrid name resolution.
• Experience developing and maintaining network diagrams, traffic-flow documentation, firewall and security-group rule matrices, IP-address plans, implementation plans, rollback plans, and test procedures.
• Experience analyzing effective security rules and troubleshooting interactions among NSGs, Azure Firewall, routing, NAT, private endpoints, DNS, and hybrid connectivity.
• Experience implementing network and security-rule configurations through infrastructure as code, source control, peer review, and controlled deployment pipelines.
• Experience with enterprise and Azure-native monitoring, logging, performance analysis, and incident troubleshooting.
• Working knowledge of NIST SP 800-171, NIST SP 800-53, RMF, CMMC, DoD Cloud SRG, and applicable DISA STIG requirements.
• Effective leadership and communication skills for coordinating with system architects, cybersecurity personnel, application owners, program leadership, and Government stakeholders.
PREFERRED ADDITIONAL QUALIFICATIONS
• Microsoft Certified: Azure Network Engineer Associate, Azure Solutions Architect, Azure Security Engineer, or equivalent demonstrated experience.
• Cisco CCNP Enterprise, CCNP Security, or an equivalent advanced networking certification.
• Experience with Azure Government, DoW cloud impact-level environments, controlled unclassified information, or classified network environments.
• Experience with Terraform, Bicep, PowerShell, Python, Azure CLI, Linux, Bash scripting, or other network and cloud automation tools.
• Experience with Azure Firewall Premium, Azure Virtual Network Manager, ExpressRoute, Private Link, Azure DNS Private Resolver, Network Watcher, Connection Monitor, virtual network flow logs, Traffic Analytics, and Log Analytics.
• Experience with approved Palo Alto, Cisco, Fortinet, or other network virtual appliances deployed in Azure.
• Experience supporting MBSE repositories, product lifecycle management systems, configuration-management repositories, simulation environments, high-performance computing, or large engineering-data transfers.
• Experience supporting RMF assessments and producing technical implementation and verification evidence.
• Prior experience in Government, defense, aerospace, or other large-scale regulated network environments.
\n$123,601 - $146,152 a year
There are a host of factors that can influence final salary including, but not limited to, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications. Our employees value the flexibility EXPANSIA allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our unique mix of benefits options is designed to support and protect employees and their families. Employment benefits include health and wellness programs, income protection, paid leave and retirement and savings.
\nAether Aerospace is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.