Network Engineer- CBP

SHERPA LLC
Ashburn, VA, United States
2 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$115,000.0 - $155,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Amazon Web Services Android Software Development IOS Applications Apple IOS Software Applications Systems Engineering Microsoft Azure Backup Devices Client Server Models Command-Line Interface
+72 more
Cloud Computing Complex Networks CompTIA Network+ CompTIA Security+ Cyber Security Computer Networks System Configuration Network Congestion Data Distribution Service Dynamic Host Configuration Protocol Linux Network Address Translation Domain Name System (DNS) Failover Firmware Hyper-V Networking Hardware IP Addressing IPv4 IPv6 Interoperability Subnetting Virtual Private Networks (VPN) Network Security Lightweight Directory Access Protocols (LDAP) Windows Servers Network Configuration and Change Management Network Architecture Network Diagrams Network Connections Network Diagnostics Network Installation Services Network Monitoring Routing Network Segmentation Network Service Packet Analyzer Public Key Infrastructure X.509 Remote Access Technology Remote Infrastructure Management Server Administration Systems Integration TCP/IP Virtual Local Area Networks VirtualBox Virtualization Technology Wireless Networks Data Logging Network Routers Diagnostic Tools Dynamic Routing Scripting Computer Network Operations System Availability Test Scripts Firewalls (Computer Science) Juniper Templating Information Technology Low Latency Network Support Palo Alto Networks Fortinet 3-tier Architectures Firewall Services Module Wearables Open Network Automation Platform Software Version Control Cisco Network Optimization Vmware

Job description

The Network Engineer supports the U.S. Customs and Border Protection (CBP) Operational Technology Operations Center (OTOC) and the design, implementation, testing, deployment, operation, and sustainment of network infrastructure supporting the Office of Information and Technology (OIT) ISS OTOC. This is a full-time onsite position focused on network engineering, secure connectivity, Watchtower Mobile Device Management (MDM), laboratory validation, and field support for operational technology during an assigned 8-hour day shift.

The Network Engineer designs, configures, implements, validates, troubleshoots, documents, and sustains secure network infrastructure supporting OT and tactical systems across laboratory, enterprise, edge, cloud, and field environments. The position engineers solutions using routers, switches, firewalls, VPNs, wireless networks, network services, cloud connectivity, identity and certificate services, and endpoint technologies to provide reliable, resilient, and secure end-to-end communications.

The position provides hands-on network engineering support for Watchtower and associated Android, Windows, Linux, iOS, radio, sensor, wearable, and tactical endpoints; develops representative lab environments; performs network validation and acceptance testing; supports deployment readiness and technology fielding; and resolves complex network, performance, and interoperability issues. The Network Engineer coordinates with systems integrators, cybersecurity, engineering, OTOC operations, program leadership, vendors, and government stakeholders to implement and sustain approved network solutions in operational environments.

Responsibilities:

Network Engineering and Architecture

  • Design, configure, implement, test, troubleshoot, optimize, and document network solutions supporting OTOC, Watchtower, operational technology, and tactical systems.
  • Configure and support routers, switches, firewalls, VPN gateways, wireless infrastructure, and associated network services in lab and operational environments.
  • Support IPv4/IPv6 addressing, subnetting, VLANs, routing, switching, NAT, DNS, DHCP, VPNs, access control, and secure network segmentation.
  • Engineer network connectivity across on-premise, cloud, edge, mobile, and disconnected or limited-connectivity environments.
  • Analyze network paths and dependencies to identify connectivity, latency, packet loss, routing, name-resolution, firewall, VPN, or configuration issues.
  • Use packet captures, logs, monitoring platforms, command-line tools, and other network diagnostic methods to isolate and resolve complex problems.
  • Develop and maintain network diagrams, IP address plans, interface definitions, configuration baselines, port/protocol matrices, build records, and implementation documentation.
  • Maintain network configuration management, backups, version control, standards, configuration baselines, and repeatable deployment practices.
  • Engineer and review network changes for technical dependencies, capacity and performance impacts, security considerations, validation requirements, implementation sequencing, and rollback needs.

Watchtower and Operational Technology Networking

  • Provide network engineering and connectivity support for the Watchtower MDM platform and supported OT and tactical devices.
  • Validate network requirements for Android, Windows, Linux, iOS, radios, sensors, wearables, and other supported endpoints.
  • Support device enrollment, provisioning, policy delivery, certificate distribution, remote management, compliance reporting, and over-the-air updates by ensuring required network paths and services are available.
  • Validate Watchtower communications across enterprise, wireless, VPN, cloud, edge, offline, and disconnected-use scenarios.
  • Troubleshoot connectivity between Watchtower services, managed endpoints, identity services, certificate infrastructure, cloud resources, and other integrated systems.
  • Support secure communications architectures and certificate-based connectivity using PKI, X.509 certificates, Certificate Authorities, and client/server certificate lifecycle processes.

Network Laboratory Engineering and Testing

  • Build, configure, and maintain representative network lab environments used to evaluate new technologies, network configurations, devices, software releases, and integration changes before operational fielding.
  • Develop and execute network connectivity, interoperability, performance, failover, regression, and operational acceptance test procedures.
  • Reproduce field network issues in the lab, collect diagnostic data, isolate root causes, validate fixes or workarounds, and document results.
  • Validate routing, firewall rules, VPN connectivity, DNS/DHCP services, certificates, wireless connectivity, bandwidth requirements, and endpoint communications before deployment.
  • Test network behavior under representative operational conditions, including degraded, edge, intermittent, or disconnected connectivity when applicable.
  • Document test objectives, topology, configurations, procedures, results, defects, limitations, corrective actions, and deployment-readiness findings.
  • Coordinate network test events with Systems Integrators, cybersecurity, OTOC support personnel, vendors, and government stakeholders.

Network Implementation and Field Deployment

  • Engineer and support the staging, configuration, validation, implementation, deployment, and fielding of network-enabled technologies to operational locations.
  • Perform site and deployment readiness assessments to identify network connectivity, addressing, routing, firewall, VPN, wireless, power, rack/space, and other infrastructure dependencies.
  • Prepare network configurations, deployment packages, diagrams, implementation plans, test checklists, validation procedures, and rollback procedures.
  • Perform pre-deployment verification of network devices, firmware/software versions, configurations, certificates, accounts, connectivity, and external dependencies.
  • Provide onsite or remote network support during installation, activation, acceptance testing, and transition to operations.
  • Troubleshoot field network issues and coordinate corrective actions with systems integration, cybersecurity, carriers/service providers, vendors, and OTOC support teams.
  • Capture as-built network configurations, fielding results, lessons learned, known issues, and follow-on actions.
  • Support transition of fielded technology to OTOC operations by providing network documentation, troubleshooting guidance, knowledge transfer, and escalation procedures.

Network Operations, Security, Performance, and Sustainment

  • Monitor and assess network health, availability, utilization, performance, and connectivity using approved tools and methods.
  • Provide Tier 2/Tier 3 network engineering support for incidents and problems requiring advanced protocol analysis, lab reproduction, configuration changes, performance analysis, or engineering coordination.
  • Support incident, problem, and change management activities associated with network infrastructure, integrated systems, releases, deployments, and configuration changes.
  • Perform root cause analysis for recurring or high-impact network issues and develop documented corrective and preventive actions.
  • Coordinate with cybersecurity personnel to implement approved network security controls, segmentation, access restrictions, secure protocols, and remediation actions.
  • Support network device lifecycle activities, including configuration, upgrades, patching, firmware updates, backup/restore, replacement, and decommissioning in accordance with approved processes.
  • Maintain technical documentation, SOPs, troubleshooting guides, knowledge articles, network standards, and operational procedures.
  • Provide technical briefings, demonstrations, knowledge transfer, and hands-on training to OTOC support personnel and government stakeholders as required.

Requirements

Security Clearance: Must possess existing DHS EOD or DHS Suitability, * Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Network Engineering, Systems Engineering, Communications, Business Technology, or a related field.

  • 5+ years of progressively responsible experience in network engineering, network operations, enterprise networking, network architecture/design, operational technology networking, lab testing, technical fielding, or a related technical role.
  • Demonstrated hands-on experience configuring and troubleshooting routers, switches, firewalls, VPNs, wireless networks, and enterprise network services.
  • Strong knowledge of TCP/IP networking, IPv4/IPv6, subnetting, VLANs, routing, switching, NAT, DNS, DHCP, VPN technologies, firewall concepts, and network segmentation.
  • Experience using packet analysis, network monitoring, logging, command-line, and diagnostic tools to troubleshoot connectivity and performance issues.
  • Experience engineering network connectivity for Windows, Linux, mobile endpoints, identity services, certificates, cloud platforms, and/or operational technology.
  • Experience building or supporting network lab/test environments and executing structured connectivity, interoperability, regression, performance, failover, or acceptance testing.
  • Experience preparing, configuring, validating, implementing, and fielding network infrastructure or network-enabled technology into operational or customer environments.
  • Demonstrated ability to troubleshoot multi-vendor and cross-domain technical issues and coordinate resolution across network, systems, cybersecurity, application, and vendor teams.
  • Ability to create and maintain network diagrams, IP plans, configuration records, implementation procedures, test plans, deployment checklists, troubleshooting guides, and knowledge articles.
  • Strong written and verbal communication skills and the ability to communicate effectively with technical teams, program leadership, vendors, and government stakeholders.
  • Ability to work full-time onsite during an assigned 8-hour day shift and support fielding/deployment travel as mission requirements dictate.

Strong working knowledge of:

  • Cisco or comparable enterprise routing and switching technologies
  • Enterprise firewall and VPN technologies
  • TCP/IP, IPv4/IPv6, VLANs, routing protocols, NAT, DNS, DHCP, and network segmentation
  • Wireless networking and mobile/edge connectivity
  • Windows Server and Desktop Operating Systems
  • Linux Operating Systems
  • Android and iOS Mobile Platforms
  • Mobile Device Management (MDM) Solutions
  • Active Directory and LDAP Administration
  • Microsoft Azure Cloud Services
  • AWS Cloud Services
  • Virtualization Technologies (Hyper-V, VirtualBox, VMware)
  • Knowledge and experience supporting Tactical Awareness Kit (TAK) software applications, including:
  • TAK Server Administration
  • ATAK/WinTAK Client Configuration
  • TAK Infrastructure Deployment and Support
  • Tactical Data Distribution and Network Engineering/Integration
  • Experience with:
  • Public Key Infrastructure (PKI)
  • X.509 Certificates
  • Certificate Authorities (CA)
  • Client and Server Certificate Lifecycle Management
  • Secure Communications Architectures, * Experience supporting Watchtower or a similar MDM, situational awareness, mobility, or operational technology platform.
  • Experience engineering and fielding network technologies for government, public safety, defense, border security, tactical, or other mission-oriented environments.
  • Experience with enterprise network monitoring and management platforms, packet capture/analysis tools, and centralized logging solutions.
  • Experience with dynamic routing protocols, high availability, redundancy, failover, QoS, and network performance analysis.
  • Experience supporting cloud networking, hybrid connectivity, virtual networks, security groups, gateways, and related Azure or AWS networking services.
  • Experience supporting disconnected, edge, tactical, cellular, satellite, or limited-connectivity environments.
  • Experience with network automation, scripting, configuration templating, or infrastructure-as-code concepts.
  • Experience with network configuration management, release/change management, implementation planning, and transition-to-operations processes.
  • Experience developing or executing formal network engineering test plans, test cases, acceptance criteria, and test reports.
  • Relevant technical certifications such as Cisco CCNA/CCNP, CompTIA Network+/Security+, Juniper, Palo Alto Networks, Fortinet, Microsoft Azure, AWS, or comparable certifications., The proposed salary range is reflective across all Sherpa 6 locations, years of experience, and skill levels. Salary negotiations will be based on a host of factors including but not limited to your geographic location, prior experience, relevant skills, education, and certifications.

Benefits & conditions

We offer a competitive benefits package, covering the cost of medical for you and your family; we also offer dental, vision, health and wellness benefits and a generous retirement savings plan. We believe that our employees can manage their workload and their personal life, therefore we extend a generous PTO policy. This allows our employees to balance their lives as they see fit., $115,000-$155,000

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · World Congress 2025

2:22 min

Introducing Skupper for application connectivity

Alex Soto Alex Soto · World Congress 2024

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:05 min

Exploring microcontrollers and communication protocols for amateur hardware

Philipp-Alexander Blum · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all