Senior Network Architect IRES - SSFB/HSV

Amentum Services, Inc.
Redstone Arsenal, AL, United States
4 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$155,000.0 - $175,000.0
Working hours
Regular working hours

Tech stack

IEEE 802.1X Amazon Web Services Microsoft Azure Border Gateway Protocol Cloud Computing Configuration Management Cyber Security Computer Networks Data Centers Dynamic Host Configuration Protocol Domain Name System (DNS) Network Interface Controllers
+23 more
Federal Information Processing Standards (FIPS) Identity and Access Management Internet Protocol Security (IP SEC) IPv4 IPv6 Intrusion Detection Systems Multi-protocol Systems Network Security Multicasting Network Architecture Routing Open Shortest Path First (OSPF) Remote Access Technology Zero Trust Network Access Runbook SAP Sales and Distribution Model-Driven Development Multi-Cloud Togaf Information Technology SDN Network DODAF Blue Team (Cyber Security)

Job description

The Senior Network Architect supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. Senior Network Architects are responsible for enterprise network architecture, modernization, and security across DoW mission environments (IL4/5/6). This role sets standards and roadmaps; leads end to end design for data center, campus/branch, WAN/SD WAN, and cloud connectivity; and drives Zero Trust-aligned segmentation and automation to deliver resilient, scalable, and compliant networks., Strategy & Architecture Governance:

  • Participate in Architecture Review Boards (ARB) and Change/Configuration Control Boards, maintaining traceability with HLD/LLD, ADRs, ICDs, and security overlays.
  • Evaluate emerging capabilities (e.g., EVPN VXLAN fabrics, SD WAN/SASE, advanced telemetry) with adoption criteria, risk posture, and migration approaches
  • Develop and maintain network architecture roadmaps, standards, and best practices aligned with DoW and Agency requirements.

Core Network Architecture & Design:

  • Design underlay/overlay topologies for data centers and campuses (spine leaf, EVPN VXLAN, MPLS L2/L3VPN) and for WAN/backbone (BGP/OSPF/IS IS, traffic engineering, route policy, communities).
  • Engineer HA and fast convergence (ECMP, FHRP, FRR, ISSU/GSU) and plan for capacity, growth, and performance (QoS, queuing, shaping, policing).
  • Define IPv4/IPv6 addressing strategy, NAT policies, multicast/RP design where required, and DNS/DHCP/IPAM governance.

Security Architecture & Zero Trust:

  • Architect segmentation and micro segmentation (identity /policy based), secure access (802.1X, certificate based auth), and crypto/crypto boundary designs (IPsec, MACsec) using FIPS validated algorithms.
  • Align to DoW RMF, NIST SP 800 53/37, and DISA STIGs; map control inheritance and produce artifacts needed for ATO/cATO.
  • Integrate network security controls (firewall policy frameworks, IDS/IPS, SWG, DLP) and validate with tabletop/blue team exercises.

Cloud, Edge & Cross Domain Connectivity:

  • Design hybrid and multi cloud connectivity (IL cloud constructs, private connectivity, transit/segmentation, inspection service insertion, east west control).
  • Engineer remote access/telework, edge footprints, and mission partner/coalition interconnects with explicit security demarcation and monitoring.
  • Campus & Branch
  • Define campus access, distribution, and core designs with 802.1X, posture assessment, guest/IoT segmentation.
  • Establish branch patterns (SD WAN, DIA/MPLS mix, local breakout controls) with consistent policy and centralized governance.

Automation, Reliability & Observability:

  • Drive intent based and policy driven operations: configuration standards, golden baselines, compliance drift detection, and repeatable change.
  • Establish observability requirements (model driven/streaming telemetry, logs/metrics/flows) and SLOs; ensure runbooks and test plans cover failure scenarios.
  • Documentation & Deliverables

Produce and maintain:

  • Enterprise Network Standards, High/Low Level Designs (HLD/LLD), Architecture Decision Records (ADRs), Interface Control Documents (ICDs), test/validation plans, cutover plans, security overlays, addressing/IP plans, and runbooks.

Requirements

  • Have excellent communication skills
  • Be able to brief senior leaders and translate technical concepts into mission impact.

Resumes, in month and year format, must be submitted with application in order to be considered for the position. The selected candidate may be assigned as an employee for one of our teammate companies.

Basic Requirements:

  • Must have 10, or more, years of general (full-time) work experience
  • May be reduced with completion of advanced education
  • Must have 5, or more, years of direct experience designing and leading large-scale enterprise or DoW networks across data center, WAN/backbone, campus/branch domains.
  • Must have 1, or more, years of experience working in a management or leadership role
  • Must have expert level knowledge of routing and switching (BGP, OSPF, IS IS), EVPN VXLAN and/or MPLS, QoS, IPv6, multicast, and network resiliency patterns.
  • Must have demonstrated success implementing Zero Trust segmentation, 802.1X/NAC, identity aware firewall policy, and FIPS validated cryptography.
  • Must be familiar with hybrid/multi cloud networking patterns and IL4/5/6 operational constraints; strong grasp of RMF/STIG compliance.
  • IAT III or IAM II baseline (examples: CISSP, CASP+ CE, CISM).
  • Must have an active DoW Secret Security Clearance

Desired Requirements:

  • Have an active DoW Top Secret Security Clearance w/ SCI eligibility
  • Have a Bachelor’s degree, or higher, in computer science, Information Technology
  • Have experience with ITIL, TOGAF, or other architecture frameworks.
  • Have experience supporting the Missile Defense Agency (MDA) or other DoW organizations.
  • Have experience with software-defined networking (SDN), automation, and cross-domain solutions.
  • Have 1, or more, of the following certifications:
  • CCIE (Enterprise Infrastructure, Security, or Data Center)
  • CCNP (Enterprise, Service Provider, or Security) or equivalent expert credentials (JNCIE, NSE 7/8, PCNSE).
  • ITIL® 4 Foundation (service alignment) and an architecture framework credential (TOGAF/DoDAF familiarity).
  • Cloud networking foundations (e.g., AWS/Azure associate level) helpful for hybrid designs.

This position will be posted for a minimum of 3 days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.

Benefits & conditions

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O’Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Introducing Skupper for application connectivity

Alex Soto Alex Soto · World Congress 2024

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · World Congress 2025

2:52 min

Addressing junior hiring bottlenecks and mitigating widespread employee burnout

Hung Lee Hung Lee +3 · World Congress 2026 Europe

3:05 min

Exploring microcontrollers and communication protocols for amateur hardware

Philipp-Alexander Blum · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

1:45 min

Replacing traditional security workarounds with foundational access controls

Ross Kukulinski Ross Kukulinski · World Congress 2026 Europe

Videos

See all

Related articles

See all