nNetwork Architect

Nabout Leidos
United States
3 days ago
Apply on jobs.military.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$116,350.0 - $210,325.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Border Gateway Protocol Cloud Computing Data Centers IPv4 IPv6 IP Address Management IP Multicasting Multi-protocol Systems Network Configuration and Change Management Network Architecture
+13 more
Network Diagrams Routing Network Segmentation Open Shortest Path First (OSPF) Remote Access Technology Ansible Zero Trust Network Access Wide Area Networks Cloud Platform System Firewalls (Computer Science) Juniper Open Network Automation Platform Cisco

Requirements

  • Clearance: US Citizen with at least an active Top Secret clearance and the ability to obtain a SCI prior to your start date.\n
  • Education: Bachelor’s degree with 12+ years of experience or a Master’s degree with 10+ years of experience. Additional experience may be considered in lieu of a degree.\n
  • Certifications: DoD 8570/8140 IAT Level III certification (e.g., CISSP, CompTIA SecurityX/CASP+ CE) and a professional-level networking certification (e.g., Cisco CCNP Enterprise, Juniper JNCIP).\n
  • Experience: 12-15 years of progressive network engineering experience, including at least 5 years in a network architecture or senior design role supporting DoD environments.\n
  • Technical Expertise:\n \n

  • Expert-level knowledge of routing and switching, including BGP, OSPF, IS-IS, MPLS/L3VPN, IP multicast, and QoS design.\n
  • Proven experience architecting data center fabrics (e.g., VXLAN/EVPN, spine-leaf) and enterprise campus and WAN topologies.\n
  • Hands-on design experience with next-generation firewalls, network segmentation, and secure remote access architectures.\n
  • Working knowledge of Type 1 encryption (HAIPE/TACLANE) and classified network enclaves.\n
  • Strong understanding of dual-stack IPv4/IPv6 design and enterprise IP address management.\n \n

  • Compliance Knowledge: In-depth familiarity with RMF, NIST SP 800-53, DISA Network Infrastructure STIGs, and the DoD Zero Trust Reference Architecture.\n
  • Documentation: Demonstrated ability to produce high-level and low-level designs, network diagrams, and architecture artifacts suitable for ATO packages and design reviews.\n, * Expert Certification: Cisco CCNP, or Juniper JNCIP.\n
  • SD-WAN & Cloud: Design experience with SD-WAN and hybrid connectivity to AWS GovCloud, Azure Government, or classified cloud environments.\n
  • Network Automation: Proficiency with Ansible workflows for network configuration.\n
  • Enterprise Programs: Familiarity with DISN transport services, Joint Regional Security Stacks (JRSS), CSfC, or cross-domain solution (CDS) architectures.\n
  • Tactical Networks: Experience designing deployable, disconnected, or low-bandwidth tactical network architectures.\n

Benefits & conditions

The Defense Sector at Leidos is seeking a highly experienced \nNetwork Architect to lead the design and modernization of enterprise network infrastructure across Department of War networks. This individual will serve as the senior technical authority for network architecture - translating mission requirements into secure, resilient, and scalable designs spanning WAN, campus, data center, and tactical edge environments. The \nNetwork Architect will drive Zero Trust alignment, guide engineering teams through implementation, and ensure every design meets DISA, RMF, and program security requirements from concept through operations.\n \n \nRoles and Responsibilities:\n \n \nArchitecture & Design\n \n \n

  • Develop target-state network architectures and multi-year modernization roadmaps aligned with mission, program, and DoD enterprise objectives.\n
  • Produce high-level and low-level designs for WAN, campus, data center, and cloud-connected environments, including routing policy, segmentation, and redundancy models.\n
  • Architect Zero Trust network capabilities, including micro-segmentation, software-defined perimeter, and policy enforcement points aligned with DoD ZT pillars.\n
  • Design secure interconnections between classification levels and mission partners, coordinating Type 1 encryption and boundary protection requirements.\n

\n \nSecurity & Compliance\n \n \n

  • Ensure all designs incorporate DISA STIG, SRG, and RMF control requirements from inception, and support ISSMs/ISSOs with architecture artifacts for eMASS and ATO submissions.\n
  • Evaluate architectural risk, define compensating controls, and support Plans of Action and Milestones (POA&M) remediation at the design level.\n
  • Align boundary and connection designs with DISA Connection Approval Process (CAP) and cybersecurity service provider (CSSP) requirements.\n

\n \nTechnical Leadership & Governance\n \n \n

  • Serve as the senior technical authority and escalation point for network engineering, operations, and NOC/SOC teams.\n
  • Lead architecture and design reviews, present recommendations to government leadership, and brief Configuration Control Board (CCB) decisions.\n
  • Establish and maintain network design standards, reference architectures, and naming and addressing conventions.\n
  • Mentor senior and mid-level engineers and provide technical oversight during implementation and cutover activities.\n

\n \nLifecycle & Modernization\n \n \n

  • Conduct technology assessments, Analyses of Alternatives (AoA), and proof-of-concept evaluations for emerging network capabilities.\n
  • Drive hardware and software lifecycle planning, including end-of-life replacement, capacity planning, and performance baselining.\n
  • Champion network automation and infrastructure-as-code practices to improve consistency, compliance, and deployment speed.\n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Introducing Skupper for application connectivity

Alex Soto Alex Soto · World Congress 2024

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · World Congress 2025

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

3:05 min

Exploring microcontrollers and communication protocols for amateur hardware

Philipp-Alexander Blum · LIVE

Videos

See all

Related articles

See all