
Network Engineer IV
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in United States.
• Design, implement, and sustain a hybrid Azure Government network architecture and connectivity.
• Engineer robust private connectivity utilizing ExpressRoute, site-to-site VPN, redundant gateways, and network virtual appliances.
• Configure and troubleshoot BGP routing, route propagation, user-defined routes, gateway transit, route filtering, failover, and asymmetric routing.
• Design and manage Azure virtual networks, subnets, peering, route tables, NAT, load balancing, gateways, hub-and-spoke, and Virtual WAN patterns.
• Implement secure network segmentation and facilitate communication between functional environments.
• Design and maintain networks for the Cloud Upload & Staging service.
• Develop documentation for network architecture, authorization boundaries, trust zones, data flows, and interface controls.
• Design and maintain NSGs, ASGs, Azure Firewall Policy rule collections, security-admin rules, and network-rule registers.
• Apply least-privilege and default-deny principles while reviewing rules for obsolescence, duplication, shadowing, and excessive permissiveness.
• Implement Private Endpoint, Private Link, Azure Private DNS zones, DNS Private Resolver, DNS forwarding, and on-premises DNS integration.
• Validate routing, firewall policy, name resolution, and service reachability.
• Configure SIEM integrations and alerts for network health, firewall events, denied traffic, DNS failures, and abnormal traffic.
• Conduct packet capture, next-hop analyses, effective-security-rule analyses, route validations, and end-to-end performance testing.
• Analyze bandwidth, throughput, latency, packet loss, and transfer performance for extensive engineering datasets.
• Develop network infrastructure as code and reusable IaC modules.
• Integrate network and security-rule modifications with DevSecOps processes, including source control, peer reviews, automated validation, testing, approval, deployment, rollback, and configuration-baseline management.
• Support NIST, DoD Cloud SRG, DISA STIG, RMF, and specific program cybersecurity requirements.
• Produce and maintain RMF evidence and engage in technical reviews, change-control boards, assessments, remediation, incident response, and authorization-package development.
• Collaborate with cybersecurity, architecture, engineering, application, and assessment personnel.
• Develop plans for implementation, maintenance, rollback, continuity, and disaster recovery.
• Lead complex incident troubleshooting across Azure, on-premises infrastructure, identity, DNS, firewalls, routing, applications, and external connections.
• Evaluate network technologies and provide recommendations regarding cost, performance, interoperability, security, authorization, and lifecycle.
• Support program operations, contractual deliverables, growth initiatives, personal development activities, and stakeholder relationships.
• Active Secret clearance.
• Bachelor's degree in computer science, information systems, engineering, cybersecurity, or a related field, or equivalent experience of 8–10 years.
• Alternatively, a Master's degree with 6–8 years of relevant experience is acceptable.
• Extensive experience in designing, implementing, securing, and maintaining enterprise hybrid-cloud networks.
• Hands-on experience with Azure virtual networks, subnets, peering, route tables, NSGs, ASGs, Azure Firewall Policy, VPN Gateway, ExpressRoute, private endpoints, private DNS, and network monitoring.
• Strong knowledge of TCP/IP, BGP, IPsec, DNS, routing, switching, firewalls, NAT, network segmentation, load balancing, high availability, and hybrid name resolution.
• Experience in creating network diagrams, traffic-flow documentation, firewall and security-group rule matrices, IP address plans, implementation plans, rollback plans, and test procedures.
• Experience in analyzing effective security rules and troubleshooting NSGs, Azure Firewall, routing, NAT, private endpoints, DNS, and hybrid connectivity.
• Experience in implementing network and security-rule configurations through infrastructure as code, source control, peer review, and controlled deployment pipelines.
• Experience with enterprise and Azure-native monitoring, logging, performance analysis, and incident troubleshooting.
• Working knowledge of NIST SP 800-171, NIST SP 800-53, RMF, CMMC, DoD Cloud SRG, and applicable DISA STIG requirements.
• Effective leadership and communication skills for coordinating with technical and Government stakeholders.
• Preferred: Microsoft Azure, Cisco CCNP, or equivalent networking certifications.
• Preferred: Azure Government, DoD cloud impact level, CUI, classified network, Terraform, Bicep, PowerShell, Python, Azure CLI, Linux, Bash, Azure networking, network virtual appliances, RMF, defense, aerospace, or regulated environment experience.
• Health and wellness programs.
• Income protection.
• Paid leave.
• Retirement and savings.
• Flexible work arrangements that support work-life balance.
• Competitive compensation.
• Opportunities for learning and development.
TRAC Recruiting
Circle
Astreya
Vamonos IT LLC
Get handpicked remote jobs straight to your inbox weekly.