Cloud Architect - Network (REMOTE)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+32 more
Job description
The Cloud Architect (Network) will perform a key technical role supporting ACF cloud modernization, cybersecurity, operational resilience, and mission delivery., * Design, implement, and manage advanced AWS networking architectures, including VPCs, Transit Gateways, Direct Connect, VPNs, PrivateLink, Route 53, Elastic Load Balancing, CloudFront, Global Accelerator, and related services.
- Develop and maintain network architecture documentation, diagrams, technical standards, and configuration baselines to promote consistency, resilience, and compliance across cloud environments.
- Collaborate with security teams to implement network-security controls, including security groups, network ACLs, AWS WAF, AWS Shield, AWS Network Firewall, segmentation, secure ingress and egress, and Zero Trust-aligned controls.
- Design and support PKI-enabled application and network capabilities for digital signatures, encryption, identification, authentication, and secure communications.
- Plan and document physical and network-access requirements for security testing; define internal and external test-environment connectivity, segmentation, access paths, and safeguards.
- Evaluate existing network infrastructure and provide recommendations for optimization, modernization, risk reduction, and migration to AWS cloud environments.
- Lead the design and implementation of hybrid cloud-networking solutions that securely connect on-premises data centers and other external environments to AWS.
- Work closely with DevOps and engineering teams to integrate network solutions into CI/CD pipelines and IaC frameworks using Terraform, AWS CloudFormation, AWS CDK, or equivalent tools.
- Implement and maintain advanced monitoring, detection, and analysis capabilities for cybersecurity threats using network telemetry, VPC Flow Logs, CloudWatch, and other approved tools.
- Monitor network performance, troubleshoot complex connectivity and security issues, and implement corrective actions to maintain service availability and reliability.
- Participate in Red Team/Blue Team exercises by designing test environments, validating network controls, analyzing results, and implementing approved remediation actions.
- Support compliance efforts by ensuring network designs adhere to FedRAMP, NIST SP 800-53, FISMA, and other applicable federal security requirements.
- Operate in an Agile delivery environment while satisfying government project requirements, stage gates, and documentation expectations.
- Provide technical leadership, mentorship, and guidance to junior cloud and network engineers.
- Remain current on emerging AWS networking technologies, services, and industry practices to continually improve cloud-networking capabilities.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Network Engineering, or a related field from an accredited college or university.
- 7+ years of experience in network engineering or architecture, with at least 4+ years focused on cloud networking in AWS environments.
- AWS Certified Advanced Networking - Specialty certification.
Security Requirement:
- Ability to obtain public trust
Preferred:
- Master’s degree in a related field.
- Experience supporting federal government IT programs and projects.
- Required Skills and Competencies
- Exceptional written and oral communication skills in English, with the ability to communicate complex technical concepts to technical and non-technical stakeholders.
- Deep expertise in AWS networking services, including VPC, Transit Gateway, Direct Connect, AWS PrivateLink, Route 53, Elastic Load Balancing, CloudFront, and AWS Global Accelerator.
- Strong understanding of networking fundamentals, including TCP/IP, DNS, BGP, OSPF, MPLS, SD-WAN, routing, switching, segmentation, and network troubleshooting.
- Experience designing and implementing hybrid and multi-cloud network architectures connecting on-premises environments to AWS.
- Proficiency with IaC tools such as Terraform, AWS CloudFormation, or AWS CDK for automating network provisioning and configuration.
- Experience implementing network-security controls, including AWS Security Groups, Network ACLs, AWS WAF, AWS Shield, AWS Network Firewall, and secure network segmentation.
- Knowledge of PKI concepts and application of PKI-supported capabilities for authentication, encryption, identification, and digital signatures.
- Experience planning network-access and connectivity requirements for internal and external security-testing environments.
- Familiarity with federal security and compliance frameworks, including FedRAMP, NIST SP 800-53, FISMA, and related standards.
- Experience with network monitoring, threat analysis, and performance management tools, including AWS CloudWatch, VPC Flow Logs, and third-party monitoring platforms.
- Ability to troubleshoot and resolve complex cloud-networking and network-security issues in production environments.
- Ability to work collaboratively, provide technical leadership and mentorship, and participate in Agile delivery teams.
- Desired Skills and Competencies
- Experience working in a federal government IT environment.
- Additional AWS certifications, such as AWS Certified Solutions Architect - Professional or AWS Certified Security - Specialty.
- Experience with multi-cloud networking strategies involving Azure and/or Google Cloud Platform (GCP).
- Knowledge of Zero Trust network-architecture principles and implementation.
- Experience with container networking in Kubernetes and Amazon EKS environments.
- Familiarity with DevSecOps practices and integrating network-security controls into CI/CD pipelines.
- Experience with network automation using Python, Ansible, or similar scripting and automation tools.
- Experience supporting FedRAMP authorization processes, including preparation of System Security Plans (SSPs) and related documentation.
- Experience participating in Red Team/Blue Team exercises or implementing network-control remediation based on exercise findings.
Benefits & conditions
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
About the company
Koniag Data Solutions LLC, a Koniag Government Services company, is seeking a Cloud Architect - Network to support KDS and our government customer. The position is remote. This position requires the candidate to be able to obtain a Public Trust., Koniag Data Solutions, LLC (KDS), a Koniag Government Services company, is seeking an experienced Cloud Architect (Network) with an AWS Advanced Networking Specialty to support secure, scalable, and highly available cloud-networking solutions for the Administration for Children and Families (ACF), a U.S. Department of Health and Human Services component. The ideal candidate is a seasoned cloud-networking professional with deep expertise in AWS networking services, hybrid connectivity, Zero Trust architecture, and federal security requirements., Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com .
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
7 Cloud Computing Trends Coming in 2025 for Developers
Best Paying Jobs in Technology
Best Coding Boot Camps in Germany
Highest Paying Tech Companies for Developers