Principal Network Architect

KSAT INC.
Denver, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 160K

Job location

Denver, United States of America

Tech stack

Amazon Web Services (AWS)
Systems Engineering
Azure
Border Gateway Protocol
Cloud Computing
Information Systems
Computer Networks
Computer Engineering
Software Design Documents
Distributed Systems
Internet Protocol Security (IP SEC)
Virtual Private Networks (VPN)
Multi-protocol Systems
Python
Network Security
Network Layer
Network Architecture
Networking Basics
Routing
Network Segmentation
Open Shortest Path First
Remote Access Technology
Ansible
Zero Trust Network Access
Systems Integration
Virtual Local Area Networks
Wide Area Networks
Computer Networking Systems
Network Access Control
Cloud Platform System
System Availability
HybridCloud
Firewalls (Computer Science)
Gitlab
SC Clearance
Information Technology
Low Latency
Enterprise Integration
Hardware Infrastructure
Terraform
Open Network Automation Platform
Cisco networks

Job description

The Senior Network Architect serves as the technical authority responsible for the design, architecture, security, scalability, and evolution of KSAT's global network infrastructure. This role will lead the development of highly available, secure, and resilient network architectures connecting worldwide ground systems, customer environments, remote operational sites, and cloud-based platforms supporting U.S. Government and commercial missions.

The successful candidate will possess deep expertise in enterprise and carrier-class networking, secure WAN design, SD-WAN architectures, IPSec VPN technologies, cloud networking, and hybrid network integration. This individual will architect and guide implementation of global network solutions that transport sensitive data, including Controlled Unclassified Information (CUI), across geographically distributed environments while meeting U.S. Government security requirements and industry best practices.

This position requires a seasoned network professional capable of translating mission and business requirements into secure, scalable, and supportable architectures while collaborating with cybersecurity, systems engineering, software, cloud, and operations teams throughout the system lifecycle.

Joining the KSAT Team means

  • Opportunity to work across the commercial, civil, and defense space industry
  • Flexible work environment
  • Experience in an international company with a global footprint and opportunities to work across cultures
  • Engaging team: inspire small, dedicated, "A-class" teammates. Being part of a nimble and passionate "start-up" team, with the financial security and product technology readiness level of an established company - the best of both worlds, * Serve as the lead architect for KSAT's US-based mission networks, establishing network architecture standards, design principles, and technology roadmaps.
  • Design and evolve secure global SD-WAN architectures supporting connectivity between remote sites, ground stations, customer locations, cloud environments, and corporate networks.
  • Architect highly available hybrid-cloud networking solutions spanning on-premises infrastructure, commercial cloud services, and U.S. Government cloud environments.
  • Develop scalable routing, switching, segmentation, and traffic engineering strategies that support worldwide operations and future growth.
  • Design secure transport architectures utilizing IPSec VPNs, overlay networks, encryption technologies, and zero-trust networking principles.
  • Partner with cybersecurity teams to ensure network architectures align with NIST 800-171/53 controls, RMF requirements, CMMC objectives, and other applicable government security standards.
  • Conduct architecture reviews, threat-informed design assessments, and risk analyses to identify and reduce network and infrastructure vulnerabilities.
  • Architect connectivity solutions between physical infrastructure and cloud environments including Azure Government, AWS GovCloud, and other mission-supporting cloud platforms.
  • Provide technical leadership on complex routing and switching architectures utilizing BGP, OSPF, ISIS, MPLS, EVPN, VXLAN, and related technologies where applicable.
  • Design resilient international connectivity supporting low-latency, high-availability, and mission-critical operational requirements.
  • Serve as technical design authority for major infrastructure programs and strategic initiatives.
  • Develop and maintain network reference architectures, design standards, implementation guides, and engineering documentation.
  • Collaborate with international engineering teams to ensure consistency of design standards across global operations.
  • Participate in customer engagements, technical reviews, audits, and compliance activities supporting business growth and mission success.

Requirements

  • U.S. Citizenship required.
  • Ability to support USG programs involving Controlled Unclassified Information (CUI).
  • Ability to obtain and maintain a US SECRET Clearance.
  • Ability to travel internationally as required., * Minimum 10+ of progressive experience in enterprise, service provider, government, or mission-critical network engineering and architecture roles.
  • Demonstrated experience architecting and deploying large-scale WAN, SD-WAN, and hybrid-cloud networking solutions.
  • Expertise in enterprise routing and switching technologies with deep knowledge of:
  • BGP
  • OSPF
  • Route redistribution
  • VRF technologies
  • VLAN and Layer 2/Layer 3 segmentation
  • High availability and resiliency architectures
  • Extensive experience architecting global IPSec VPN solutions supporting geographically distributed environments.
  • Experience designing network architectures aligned with NIST 800-171/53 security controls and risk management frameworks.
  • Demonstrated knowledge of network segmentation, access control, encryption technologies, and secure network design methodologies.
  • Experience integrating cloud networking with physical enterprise infrastructure.
  • Hands-on experience with enterprise network technologies including:
  • SD-WAN platforms
  • Firewalls
  • Network access control solutions
  • VPN concentrators
  • Core routing and switching platforms
  • Experience producing architecture diagrams, technical design documentation, implementation plans, and engineering standards.
  • Ability to communicate complex technical concepts effectively to executive leadership, customers, engineers, and program stakeholders.

Preferred

  • Experience designing networks supporting Azure Government, Microsoft Azure, AWS GovCloud, or comparable cloud environments.
  • Familiarity with U.S. Government accreditation processes including RMF, FedRAMP, DISA STIGs, and related compliance frameworks.
  • Working knowledge of network automation and Infrastructure-as-Code technologies including:
  • Python
  • Ansible
  • AWX
  • GitLab
  • Terraform
  • NetBox
  • Experience designing and supporting globally distributed operational and mission networks.
  • Experience integrating satellite communications systems, ground stations, RF transport systems, and related operational technologies.
  • Industry certifications such as:
  • Cisco CCNP Enterprise
  • Cisco CCIE Enterprise Infrastructure
  • Azure Network Engineer Associate or AWS Advanced Networking Specialty

Education

  • Bachelor's degree in Network Engineering, Computer Engineering, Electrical Engineering, Computer Science, Information Systems, or a related technical discipline.
  • Equivalent combinations of advanced industry certifications, demonstrated network architecture expertise, and relevant professional experience will be considered in lieu of a degree.

Benefits & conditions

3.83.8 out of 5 stars 7600 East Eastman Avenue, Denver, CO 80231 $130,000 - $160,000 a year, Pulled from the full job description

  • Travel reimbursement
  • Tuition reimbursement
  • Health insurance
  • Paid time off
  • Gym membership, The On-Target base salary range is $130K-$160K annually.

Benefits Package Highlights

  • Four weeks of PTO annually
  • $0 individual medical insurance with generous coverage
  • Flexible working environment
  • Fitness expense reimbursement program
  • Tuition reimbursement program
  • International travel opportunities, Travel
  • Travel estimated at approximately 10-15%.
  • Travel to customer, government, and operational sites in the United States and internationally as required.

About the company

With headquarters in Tromsø, Norway, Kongsberg Satellite Services AS (KSAT) supplies ground station services for satellite communications. KSAT is the world's largest supplier of telemetry, tracking and command (TT&C) and data acquisition services for non-geostationary satellites. Founded in 1968, KSAT has grown to over 500 employees with about 50% of KSAT's annual revenue coming from the US. The wholly owned subsidiary KSAT Inc. (aka. KSAT USA) is located in Denver, Colorado and is rapidly growing in response to strong US Government and industry demand for commercial ground segment services. As a result of KSAT's continued growth in the US, more critical talent is needed.

Apply for this position