network engineer

True Anomaly
Long Beach, CA, United States
3 days ago
Apply on job-boards.greenhouse.io
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$170,000.0 - $260,000.0
Working hours
Regular working hours

Tech stack

Access Network Amazon Web Services Microsoft Azure Cascading Style Sheets (CSS) Cyber Security Computer Networks System Configuration Networking Hardware Internet Protocol Interoperability IP Routing Subnetting
+16 more
Network Security Network Configuration and Change Management Network Architecture Network Control Network Diagrams Network Connections Network Installation Services Routing Zero Trust Network Access Virtual Local Area Networks Cloud Platform System Amazon Virtual Private Cloud (VPC) SC Clearance Information Technology Open Network Automation Platform Vulnerability Analysis

Job description

As a Staff Mission Network Engineer, you will be a critical hands-on technical contributor responsible for the deployment, configuration, and operation of terrestrial and cloud network infrastructure supporting classified U.S. Government programs. You will work as part of the Mission Security Engineering team, executing against defined network architectures to deliver secure, compliant, and operational networks across multiple classification levels and locations across the United States.

This is an execution-focused role for a senior network engineer who thrives in the field - someone equally comfortable racking hardware in a classified facility and configuring cloud network infrastructure in AWS. You will work across on-premise and IL-6+ cloud environments, partnering closely with the Staff Security Architect - Networks and cross-functional engineering teams to bring network designs to life and keep them running at mission tempo.

This position requires an active Secret clearance to start, with the ability to obtain and maintain a TS/SCI.

Responsibilities

  • Deploy, configure, and operate terrestrial network infrastructure for classified capabilities spanning multiple on-premise locations across the U.S., including switching, routing, cabling, and boundary protection hardware

  • Implement and maintain network configurations in AWS GovCloud and classified cloud environments, including VPCs, transit gateways, route tables, security groups, and network access controls

  • Configure and maintain network connectivity between AWS classified cloud environments, USG networks, and end-user physical networks in close coordination with cloud engineers

  • Implement endpoint networks connecting on-premise and IL-6+ cloud environments across geographically distributed sites

  • Deploy and configure network hardware in accordance with DoD Approved Products Lists (APLs) and Trade Agreements Act (TAA) compliance requirements

  • Implement and validate network security controls including boundary protection, traffic segmentation, filtering, and encrypted communications across classification domains

  • Implement and validate DISA STIG requirements at the network and infrastructure layer across on-premise and cloud environments

  • Identify and remediate network-layer findings from STIGs, vulnerability scans, and SCA activities to maintain ATO posture

  • Support RMF activities including network control implementation, STIG validation, and assessment preparation in coordination with ISSEs

  • Maintain accurate and up-to-date network documentation including topology diagrams, as-built configurations, and security artifacts required for ATO activities

  • Partner with ISSEs, industrial security personnel, cloud engineers, and the Staff Security Architect - Networks to ensure network deployments meet program security and compliance requirements

  • Deploy, configure, and operate NSA Type 1 cryptographic devices (including KG-175 TACLANE and KG-142 units) within terrestrial classified networks, ensuring proper integration with network infrastructure and compliance with NSA/CSS operational policies

  • Manage keying material (KEYMAT) handling, DTA transfers, and controlled cryptographic item (CCI) documentation in accordance with USG regulations and best practices

  • Troubleshoot and resolve NSA Type 1 device connectivity, configuration, and interoperability issues across classified terrestrial network environments

  • Troubleshoot and resolve network connectivity, configuration, and performance issues across classified on-premise and cloud environments, * Work Location- Long Beach, CA, or Denver, CO. While we observe a hybrid work environment, you will need to be onsite as the business needs require. Onsite requirements are subject to change, particularly when work on classified systems is required. On an average week, you can expect to spend at least 3 days per week in office.
  • Work environment-the work environment; temperature, noise level, inside or outside, or other factors that will affect the person’s working conditions while performing the job.
  • Physical demands-the physical demands of the job, including bending, sitting, lifting and driving.

This position will be open until it is successfully filled. To submit your application, please follow the directions below. #LI-Onsite

Requirements

  • 10+ years of hands-on experience in network engineering, with demonstrated experience deploying and operating classified DoD or IC networks at classification levels up to and including TS/SCI and special access networks

  • Active Secret clearance required; must be able to obtain and maintain TS/SCI

  • DoD 8140 IAT Level III certification (CASP+, CISSP, CISA, or equivalent) required

  • Deep expertise in IP networking including routing protocols, switching, VLANs, subnetting, QoS, and network boundary protection

  • Experience deploying and configuring network hardware in compliance with DoD APL and TAA requirements

  • Working knowledge of NIST SP 800-53 and how network controls are implemented, documented, and validated within the RMF process

  • Hands-on experience implementing STIGs at the network and infrastructure layer

  • Experience supporting RMF and ATO activities including control implementation and assessment preparation

  • Strong documentation skills, with experience producing network diagrams, as-built documentation, and hardware configuration records

  • Ability to collaborate effectively with ISSEs, architects, cloud engineers, and cross-functional program teams

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Technology, or related field (or equivalent experience)

Preferred Qualifications

  • Active Top Secret or TS/SCI clearance

  • Professional networking certifications (e.g., CCNP, CCIE, or equivalent)

  • Experience with AWS IL-6+ or Microsoft Azure IL-6+ classified cloud environments, including VPC/VNet design, transit gateway configuration, and network security controls

  • Experience supporting classified ground station or satellite Command & Control (C2) network infrastructure is a significant plus

  • Hands-on experience deploying, configuring, and operating NSA Type 1 cryptographic devices, including KG-175 (TACLANE) and/or KG-142 units, within terrestrial classified network environments

  • Familiarity with KEYMAT handling procedures, DTA transfer processes, and CCI inventory and documentation requirements

  • Experience with Cross Domain Solutions (CDS), data guards, or inter-domain network traffic control

  • Experience with NSA Type 1 cryptographic devices and their integration into classified network architectures

  • Familiarity with zero trust network architectures applied to classified or highly regulated environments

  • Experience supporting DoD or IC customers through ATO, re-ATO, or continuous authorization

  • Familiarity with Software Defined Networking (SDN) or network automation tooling

Work Environment

  • Fast-paced, mission-critical environment supporting national security space operations

  • Requires coordination across distributed teams including spacecraft engineers, ground operations, and government partners

  • High degree of autonomy and ownership as a trusted, cleared team member

  • Occasional travel to government sites, classified facilities, launch facilities, or partner locations may be required, To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR), you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

Benefits & conditions

Be an Early Applicant In-Office Denver, CO, USA 170K-260K Annually Expert/Leader In-Office Denver, CO, USA 170K-260K Annually Expert/Leader Deploys and operates classified terrestrial and cloud networks across on-premise, AWS GovCloud, and IL-6+ environments. Responsibilities include routing, switching, boundary protection, segmentation, encrypted communications, STIG implementation, RMF/ATO support, network documentation, and troubleshooting. The role also configures NSA Type 1 cryptographic devices, manages KEYMAT and CCI documentation, and collaborates with security, cloud, and engineering teams. An active Secret clearance and ability to obtain TS/SCI are required, with occasional travel to government and classified facilities. The summary above was generated by AI

Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it., * Competitive salary commensurate with experience and clearance level

  • Opportunity to drive security posture for cutting-edge space systems with national security impact

  • Professional development support including conferences, training, and security certifications

  • Collaborative culture working alongside spacecraft engineers, mission operators, and experienced security professionals

  • Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave, * Base Salary: Denver - $170,000 - $250,000, Long Beach - $180,000 - $260,000
  • Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave

Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, location, and experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on job-boards.greenhouse.io
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:30 min

Navigating preview bugs in Azure Container Apps

Matthias Falkenberg +1 · World Congress 2022

1:35 min

Translating domain names to server IP addresses

Shem Magnezi Shem Magnezi · World Congress 2025

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

2:07 min

Shifting network trust from subnets to combined identities

Ross Kukulinski Ross Kukulinski · World Congress 2026 Europe

1:32 min

Ensuring secure and reliable connectivity for remote employees

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all