> Markdown version of [/jobs/ext/3638903-network-engineer-sme](https://www.wearedevelopers.com/jobs/ext/3638903-network-engineer-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Engineer SME - **Company:** Modern Technology Solutions, Inc. - **Location:** Colorado Springs, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Application Layers, Systems Engineering, Microsoft Azure, Computer Networks, Computer Engineering, Data Centers, Dynamic Host Configuration Protocol, Domain Name System Security Extensions, Domain Name System (DNS), Internetworking, IP Address Management, Python (Programming Language), Network Security, Name Server, Network Segmentation, Network Virtualization, Ansible, Zero Trust Network Access, Systems Integration, VCloud, Wide Area Networks, Computer Networking Systems, Software Security, Multi-Cloud, HybridCloud, Firewalls (Computer Science), Information Technology, Palo Alto Networks, Route53, Restful APIs, Terraform, Big Ip, Cisco, Vmware - **Published:** October 8, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9225648/network-engineer-sme ## About the Role Education & Years of Experience: Bachelor of Science degree in Network Engineering, Computer Science, Computer Engineering, Systems Engineering, or a related technical discipline with 12 years of progressive engineering and architectural experience (or Master's degree with 10 years of experience). * Enterprise DDI & DNS Experience: Demonstrated track record architecting enterprise-grade DNS, DHCP, and IPAM solutions, specifically utilizing Infoblox as an Authoritative Source of Truth (ASOT) in hybrid cloud environments. * Hybrid Cloud Track Record: Demonstrated experience designing, deploying, and securing enterprise networks across AWS, Azure, and on-premises VMware VCF / NSX environments. * Classified Environment Experience: Proven track record designing, integrating, and accrediting network transport and boundary security solutions within classified DoD (TS//SCI) enclaves. Security Clearance & Compliance * Clearance: Must possess an active Top Secret security clearance with current SCI eligibility (TS/SCI). * DoD Compliance: Must meet DoD 8140/8570 requirements for an IAT Level III or IASAE Level II position. An active (ISC)² CISSP certification is required., * Infoblox Core Administrator / Engineer (CDCA / CICA) * Cisco Certified Internetwork Expert (CCIE Enterprise Infrastructure) * Palo Alto Networks Certified Network Security Engineer (PCNSE) * F5 Certified Technology Specialist (F5-CTS) * VMware Certified Advanced Professional (VCAP) - Network Virtualization * AWS Certified Advanced Networking - Specialty * Microsoft Certified: Azure Network Engineer Associate (AZ-700) * Demonstrated experience managing Infoblox, firewalls, and cloud routing through Infrastructure as Code (Terraform providers, Ansible collections, Python automation using REST/WAPI). * Deep operational understanding of DISA STIGs, DODNET connection requirements, NIST SP 800-207, and practical engineering experience implementing DISA Thunderdome zero-trust capabilities * Prior experience in a SETA, A&AS, or direct engineering advisory role supporting Government Program Managers, Directors, or CTOs. ## Description We are seeking a highly experienced and technically exceptional Network Engineering Subject Matter Expert (Engineer 4) to serve as a trusted technical advisor in a Systems Engineering and Technical Assistance (SETA) capacity directly supporting the Government Chief Technology Officer (CTO) and Next Generation Environment (NGE) leadership in the Missile Defense Agency. About the Program Join a mission-critical, high-visibility program to architect, build, and secure the Agency's Next Generation Environment (NGE). This initiative establishes a secure, resilient, and flexible hybrid, multi-cloud ecosystem designed to support national security objectives for years to come. Within the NGE, the transport network and core enterprise network services, including DNS, DHCP, and IP Address Management (DDI)-serve as the foundational backbone and enforcement fabric of the Agency's Zero Trust Architecture (ZTA). As the Network Engineering SME, you will guide technical decisions, shape transport and core network services roadmaps, and oversee multi-vendor integration efforts across commercial cloud providers (AWS, Azure), on-premises VMware Cloud Foundation (VCF) environments, and DISA/DODNET boundaries., In this role, you will provide critical oversight and technical direction for the NGE Network and Transport Design Area. You will ensure that all hybrid networking components-spanning software-defined wide area networks (SD-WAN), software-defined data centers (SDDC), enterprise DDI architectures, multi-cloud transit networks, application delivery controllers, and next-generation firewalls-are designed, integrated, and accredited to form a cohesive, secure, and interoperable system. Lead the architecture and governance of the enterprise DDI solution using Infoblox as the Authoritative Source of Truth (ASOT) to automate IP address management and name resolution across hybrid enclaves. Simultaneously, oversee the technical integration of NGE enclaves with DODNET boundaries, ensuring strict compliance with DISA Connection Approval Processes (CAP) and Versa-based SD-WAN gateways. Throughout these efforts, serve as the principal technical liaison translating senior Government leadership requirements into actionable engineering solutions delivered by contractors and vendors, * Serve as a senior technical authority in architectural review boards (ARBs), evaluating and validating vendor-proposed network, boundary, and DDI designs against the NGE Master Architecture and DoD Zero Trust reference mandates. * Design and document holistic, end-to-end transport solutions across AWS, Azure, and on-premises VMware Cloud Foundation (VCF), defining routing topologies, traffic engineering, and resilient transit patterns. * Architect and govern the enterprise Infoblox DDI infrastructure as the centralized Authoritative Source of Truth (ASOT). Design split-horizon DNS, DNSSEC, Anycast routing, and dynamic IPAM synchronizations across multi-cloud and on-prem segments. * Architect and integrate micro-segmentation, software-defined perimeters, and secure access service edge (SASE) capabilities aligned with DISA Thunderdome standards. * Oversee the technical integration of NGE enclaves with DODNET boundaries, ensuring compliance with DISA connection approval processes (CAP) and Versa-based SD-WAN gateways. * Guide the deployment and policy harmonization of F5 BIG-IP (ASG/AWAF) and Palo Alto Networks NGFWs across on-premises and cloud boundaries to enforce Layer 7 inspection and zero-trust controls. * Facilitate technical exchange meetings (TEMs) with integration contractors and software vendors (Cisco, Versa, VMware, Infoblox, F5, Palo Alto). Act as the final escalation authority for complex, cross-domain routing and name resolution issues. The position requires deep technical knowledge, practical engineering skills, and system-level architectural design experience across the following functional areas and vendor platforms: * Design and operation of Infoblox as the Authoritative Source of Truth (ASOT). Integration with AWS Route 53 Resolvers/Private Hosted Zones, Azure Private DNS Resolver, and VMware NSX IP pools. Automation of DDI via REST APIs and Infrastructure as Code. * Transport-independent fabric engineering, overlay routing policies, application-aware routing, and integration with DODNET SD-WAN boundaries utilizing Versa gateways. * Multi-tenant micro-segmentation, distributed firewalling (DFW), logical routing (T0/T1 gateways), and automated segment IP provisioning tied to Infoblox IPAM * Scalable hub-and-spoke transit networks, routing domain segmentation, and automated routing propagation between cloud enclaves and on-premises cores. * Implementation of F5 as an Application Security Gateway (ASG), SSL/TLS offloading and inspection, dynamic access control, and Layer 7 protection for enterprise services. * Deployment of physical and virtual (VM-Series) next-generation firewalls at perimeter inspection points, establishing automated threat prevention and zero-trust micro-perimeters. * Alignment with DISA Thunderdome reference standards, implementing identity-aware network segmentation, secure remote access proxies, and continuous endpoint posture verification