Network Operations Lead - Zero Trust

Northramp LLC
Washington, DC, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Private Networks IEEE 802.1X Amazon Web Services Microsoft Azure Border Gateway Protocol Cloud Computing Cyber Security Information Systems Computer Networks System Configuration Enhanced Interior Gateway Routing Protocol
+43 more
Networking Hardware Internet Protocol Security (IP SEC) IPv4 IPv6 Virtual Private Networks (VPN) Internet Service Provider Python (Programming Language) Network Security Microsoft Visio Network Architecture Network Diagrams Routing Network Segmentation Packet Analyzer Open Shortest Path First (OSPF) Paessler Router Traffic Grapher Lucidchart Ansible Zero Trust Network Access Security Information and Event Management Systems Integration Wireshark Virtual Local Area Networks Software Vulnerability Management Wide Area Networks Wireless Networks VLAN Trunking Protocol (VTP) Transport Layer Security Network Access Control Computer Network Operations HybridCloud Firewalls (Computer Science) Juniper SC Clearance Information Technology SolarWinds (Software) Palo Alto Networks Performance Monitor Routing & Switching Terraform Open Network Automation Platform Network Server Cisco

Job description

  • Lead the Network Operations workstream across DFC, owning the reliability, performance, and security posture of DFC’s enterprise network.
  • Drive operational execution of DFC’s Zero Trust strategy - identity-based access, micro-segmentation, continuous verification, and least-privilege enforcement across network and application traffic.
  • Own incident response for network and connectivity issues across DFC HQ (Washington, DC) and DFC NYC (100 Pearl St); maintain availability SLAs.
  • Lead and mentor the network engineering and operations team; set clear technical direction and develop talent on engagement.
  • Maintain and continuously improve network architecture documentation, runbooks, and operational procedures.
  • Operate and evolve DFC’s perimeter and internal network controls - next-generation firewalls (Palo Alto, Cisco, or equivalent), WAF, network access control (802.1X, NAC), and SD-WAN where applicable.
  • Coordinate with the security operations team on threat detection, SIEM integration, vulnerability management, and incident response.
  • Support DFC’s CIO and security leadership with executive briefings, capacity planning, and technology investment decisions.
  • Lead vendor coordination with DFC’s ISPs, carrier partners, and security tool vendors.
  • Define network operations metrics and produce regular reporting for DFC government leadership.

Requirements

Do you have experience in Zero trust architecture design?, Do you have a Bachelor’s degree?, You have led network operations in a federal environment under real security pressure - and you understand Zero Trust. You can run a network incident bridge, design segmentation and identity-based access policies, and lead a team of engineers through the operational maturity needed to actually implement Zero Trust. You operate with low ego, high accountability., * 7-10 years of progressive, hands-on experience in enterprise network operations leadership, with hands-on experience implementing or operating in a Zero Trust architecture.

  • Bachelor’s degree in Computer Science, Network Engineering, Information Systems, or a related technical field. Equivalent professional experience considered.
  • Demonstrated experience leading network operations in a federal or comparable regulated environment.
  • Hands-on expertise designing, implementing, or operating Zero Trust architectures - including identity-based access, micro-segmentation, and continuous-verification controls.
  • Strong working knowledge of enterprise network infrastructure - routing, switching, firewalls, VPN, SD-WAN, wireless, and IPv4/IPv6 networking.
  • Hands-on experience with Cisco, Palo Alto, Juniper, or equivalent enterprise infrastructure.
  • Strong understanding of network security - segmentation, NAC (802.1X, RADIUS), WAF, SIEM integration, and STIG compliance.
  • Proven leadership; track record of leading technical teams through operational incidents and strategic transitions.
  • Excellent written and verbal communication; ability to brief senior federal stakeholders.
  • U.S. Citizenship and the ability to obtain and maintain a Secret clearance., * Professional-level networking certification - Cisco CCNP/CCIE or Palo Alto Networks Certified Network Security Engineer (PCNSE). CCNA may be considered with substantial hands-on experience.
  • CISSP, CISM, or comparable security leadership certification.
  • Cloud networking certification - AWS Advanced Networking, Azure Network Engineer Associate, or equivalent.
  • Prior federal civilian or defense network operations experience.
  • Familiarity with NIST 800-207 (Zero Trust Architecture) and the CISA Zero Trust Maturity Model.
  • Hands-on experience with Aruba Central, Aruba Wireless infrastructure, and Aruba ClearPass Policy Manager in large enterprise or government networks.
  • Practical experience deploying, configuring, and troubleshooting Palo Alto Networks firewalls, including Panorama management.
  • Experience integrating Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) for secure remote connectivity and Zero Trust enforcement.
  • Extensive experience in enterprise network architecture and topology design - LAN/WAN, wireless, SD-WAN, and hybrid cloud integrations - including: IPv4 and IPv6 configuration, migration, and troubleshooting. Routing protocols (BGP, OSPF, EIGRP) and switching technologies (VLANs, STP, VTP). Network security technologies (VPNs, ACLs, IPsec, SSL/TLS, NGFW). Cloud networking in AWS, Azure, or GCP. Network automation tools (Python, Ansible, Terraform).
  • Proven ability to activate, back up, deactivate, and restart network resources and services with minimal downtime.
  • Strong background diagnosing complex LAN/MAN/WAN issues using packet analysis and performance monitoring tools (Wireshark, SolarWinds, PRTG).
  • Excellent documentation skills, including network diagrams in Visio or Lucidchart.

Physical Requirements

This role requires the ability to lift and carry up to 50 pounds, with or without reasonable accommodation, when handling IT equipment such as servers, network hardware, and end-user devices. Reasonable accommodations will be considered for qualified individuals with disabilities in accordance with the Americans with Disabilities Act.

Clearance

An active or current-eligible Secret clearance is required for this role. Selected applicants will be subject to a security investigation and may need to meet eligibility requirements for access to classified information. Failure to maintain clearance eligibility may result in removal from the role.

Benefits & conditions

Pulled from the full job description

  • AD&D insurance
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Family leave, * Competitive Salary, commensurate with experience, certifications, and clearance.
  • Managed Revenue Bonus eligibility: tied to performance against revenue and margin targets on the assigned portfolio. Specific structure and targets to be discussed during the offer process.
  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Work From Home
  • Wellness Resources

About the company

Northramp is seeking a Network Operations Lead - Zero Trust to join the team supporting the U.S. International Development Finance Corporation (DFC) Enterprise IT Operations Services Support (ITOPS) program. ITOPS is a five-year effort to operate and modernize DFC’s enterprise IT environment, providing service management, network operations, IT asset management, and end-user support across DFC’s mission.

You will lead the Network Operations workstream supporting DFC, owning operational reliability, performance, and security across DFC’s enterprise network - and driving the agency’s transition to a Zero Trust architecture. The role pairs senior NOC leadership with the architectural judgment to advance Zero Trust principles within a real operational environment.

This role is part of Northramp’s integrated delivery model, where engineers and advisors work as one team to bring sound judgment, disciplined execution, and deep federal experience to mission-critical operations programs., Primary place of performance is DFC Headquarters at 1100 New York Ave NW, Washington, DC.. On-site presence at DFC HQ is expected on a regular cadence; periodic travel between DFC HQ and the DFC NYC site (100 Pearl St) may be required., Northramp is a federal consulting firm that helps agencies modernize and operate mission-critical systems with sound judgment, disciplined execution, and deep federal experience. We specialize in high-stakes digital transformation in highly regulated environments where failure is not an option. Our integrated delivery model brings engineers and advisors together as one team, combining technical depth with an operator’s mindset to move organizations from strategy to execution with confidence.

We hold high standards because our clients’ missions demand it, and we support our people in meeting them. Northramp is where you are challenged, trusted, and supported - a place for people who take pride in their work, value clarity and follow-through, and want to make a meaningful impact through technology.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · WWC 2025

2:22 min

Introducing Skupper for application connectivity

Alex Soto Alex Soto · WWC 2024

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

7:50 min

Prioritizing cybersecurity and zero trust in development

Ash Ryan Arnwine Ash Ryan Arnwine +3 · WWC 2024

3:05 min

Exploring microcontrollers and communication protocols for amateur hardware

Philipp-Alexander Blum · LIVE

3:58 min

Implementing zero trust on traditional cloud providers and serverless

Jan Peer Stöcklmair Jan Peer Stöcklmair · WWC Europe 2026

Videos

See all

Related articles

See all