NGE - Network Design Engineer Architect / Lead IRES - SSFB/HSV/F

Amentum Services, Inc.
Arlington, VA, United States
8 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$175,000.0 - $225,000.0
Working hours
Regular working hours

Tech stack

IEEE 802.1X Amazon Web Services Microsoft Azure Border Gateway Protocol Cloud Computing Cyber Security Data Centers Dynamic Host Configuration Protocol Domain Name System (DNS) Network Interface Controllers Federal Information Processing Standards (FIPS) High-Level Architecture
+27 more
Identity and Access Management Internet Protocol Security (IP SEC) IPv6 IP Address Management Multi-protocol Systems Multicasting Network Architecture Network Planning and Design Routing Network Segmentation Cisco Nexus Switches Open Shortest Path First (OSPF) Zero Trust Network Access Software Deployment VCloud Wide Area Networks Transport Layer Security Load Balancing Nx-os Multi-Cloud HybridCloud Togaf Information Technology SDN Network DODAF Big Ip Vmware

Job description

As the Network Design Engineering Architect / Lead for the Next Generation Environment (NGE) on the Integrated Research and Development for Enterprise Solutions (IRES) contract, you will serve as the principal network authority and Lead Network Integrator driving the architecture, modernization, and cross-performer technical governance of the Missile Defense Agency’s (MDA) unified digital ecosystem.

In this high-visibility role, you will lead a dedicated team of network engineers and act as the primary interface between the Government NGE Technical Director, Government Network Design Lead, MDA leadership, and industry partners within the multi-contractor program consortium. You will establish and enforce technical baselines across Cisco Nexus Spine-Leaf EVPN-VxLAN fabrics, VMware NSX software-defined networks, Versa SD-WAN WAN/edge transport, F5 application delivery controllers, and Infoblox enterprise DDI bridging on-premises and hybrid multi-cloud (AWS/Azure GovCloud/IL5/IL6/IL7) environments.

Consortium & Stakeholder Integration:

  • Serve as the Lead Network Integrator across the program enterprise; align network technical roadmaps and Interface Control Documents (ICDs) among government stakeholders, military leadership, and multiple industry performers/teammate companies.

Government & Technical Advisory:

  • Serve as direct technical advisor to the Government NGE Technical Director and Government Network Design Lead; translate mission capability needs into actionable network architecture roadmaps, technical baseline decisions, and engineering trade studies.

Team Leadership & Engineering Oversight:

  • Oversee, guide, and mentor a multidisciplinary team of network design and implementation engineers; manage technical task assignments, design reviews, peer code/config audits, and engineering deliverables.

Data Center & Fabric Architecture:

  • Architect scalable multi-site Data Center fabrics utilizing Spine-Leaf topologies, Cisco Nexus (NX-OS) platforms, and EVPN-VxLAN overlay technologies; integrate with VMware NSX / VMware Cloud Foundation (VCF) to establish software-defined networking and distributed micro-segmentation.

Application Delivery & Traffic Management:

  • Design enterprise load balancing, traffic distribution, and SSL offloading/decryption architectures using F5 BIG-IP (LTM/GTM/APM); establish high-availability application routing across hybrid cloud boundaries.

Edge, WAN & SD-WAN Architecture:

  • Architect resilient WAN transport and secure branch interconnects leveraging Versa Networks SD-WAN/SASE solutions, MPLS, and zero-trust edge boundary controls.

DDI & IPAM Strategy:

  • Govern enterprise IP address management, automated DNS resolution, and DHCP provisioning frameworks utilizing Infoblox DDI integrated with hybrid cloud orchestration pipelines.

Zero Trust & Security Architecture:

  • Define network segmentation, micro-segmentation, ICAM integration, dynamic policy enforcement (802.1X/NAC), and FIPS-validated cryptography (IPsec/MACsec); align designs with DoW Zero Trust Strategy, NIST SP 800-53, and DISA STIGs to support continuous ATO (cATO).

Governance, MBSE & ARB Leadership:

  • Lead Network Architecture Review Boards (ARB) and Engineering Change Boards; establish authoritative High-Level Designs (HLD), Low-Level Designs (LLD), Architecture Decision Records (ADRs), and Interface Control Documents (ICDs) leveraging Model-Based Systems Engineering (MBSE) concepts.

Requirements

  • Have excellent communication skills with the ability to brief senior leaders and translate technical concepts into mission impact., * Must have 12, or more, years of general (full-time) work experience
  • May be reduced with completion of advanced education
  • Must have 6, or more, years of directly related experience designing and leading large-scale enterprise or DoW networks across data center, WAN/backbone, campus/branch domains.
  • Must have 1, or more, years of experience working in a management or leadership role
  • Must have expert level knowledge of routing and switching (BGP, OSPF, IS IS), EVPN VXLAN and/or MPLS, QoS, IPv6, multicast, and network resiliency patterns.
  • Must have demonstrated success implementing Zero Trust segmentation, 802.1X/NAC, identity aware firewall policy, and FIPS validated cryptography.
  • Must be familiary with hybrid/multi cloud networking patterns and IL4/5/6 operational constraints; strong grasp of RMF/STIG compliance.
  • Must have a current IAT III or IAM II baseline certification (examples: CISSP, CASP+ CE, CISM).
  • Must have an active DoW Secret Security Clearance

Desired Requirements:

  • Have, or obtain, an active DoW Top Secret Security Clearance with SCI eligibility
  • Have a Bachelor’s degree (or higher) in computer science, Information Technology
  • Have experience performing within ITIL, TOGAF, or other architecture frameworks.
  • Have experience supporting the Missile Defense Agency (MDA) or other DoW organizations.
  • Have experience with software-defined networking (SDN), automation, and cross-domain solutions.

Desired Certifications:

  • CCIE (Enterprise Infrastructure, Security, or Data Center)
  • CCNP (Enterprise, Service Provider, or Security) or equivalent expert credentials (JNCIE, NSE 7/8, PCNSE).
  • ITIL® 4 Foundation (service alignment) and an architecture framework credential (TOGAF/DoDAF familiarity).
  • Cloud networking foundations (e.g., AWS/Azure associate level) helpful for hybrid designs.

This position will be posted for a minimum of 3 days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.

Benefits & conditions

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O’Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · World Congress 2025

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

3:05 min

Exploring microcontrollers and communication protocols for amateur hardware

Philipp-Alexander Blum · LIVE

1:45 min

Replacing traditional security workarounds with foundational access controls

Ross Kukulinski Ross Kukulinski · World Congress 2026 Europe

4:16 min

Engaging globally and expanding infrastructure operations engineering teams

Stephanie Cohen Stephanie Cohen +1 · World Congress 2025

Videos

See all

Related articles

See all