This role will help improve network resilience, reduce single-point-of-failure risk, stabilize network operations, advance site and program deployments. The successful candidate will become a key technical resource for the CUI environment and work closely with Network Architecture, Information Assurance, program teams, vendors, and other IT organizations.
The CUI environment supports 23 active programs, approximately nine sites with additional sites planned, network switches, firewalls, and TACLANEs. This role requires a hands-on technical professional who can troubleshoot complex issues, execute secure network changes, support deployments, and help establish a durable operational foundation for the transition to the future eWAN architecture.
Key Responsibilities
- Provide senior-level administration, maintenance, troubleshooting, and operational support for CUI network infrastructure.
- Configure, maintain, and troubleshoot Cisco switching and routing environments, including VLANs, VSS/VSL, OSPF, EIGRP, BGP, IPsec VPNs, DMVPN, and/or L2 eVPN.
- Administer and support firewall technologies, including Cisco Firepower Threat Defense (FTD), Firepower Management Center (FMC), Palo Alto firewalls, and Panorama.
- Support Cisco Identity Services Engine (ISE), 802.1X authentication, network access controls, and Zero Trust architecture.
- Deploy, maintain, and troubleshoot firewall configuration for double-encapsulation requirements.
- Configure, maintain, and troubleshoot TACLANE devices; coordinate keying activities and related connectivity requirements as applicable.
- Perform network monitoring, analyze performance trends, respond to alerts, investigate incidents, and restore service during outages or degraded network conditions.
- Execute patching, vulnerability remediation, configuration-hardening, and network health improvement activities.
- Support program and site deployments, site expansions, circuit activations, firewall requests, and related infrastructure changes.
- Coordinate with carriers, vendors, site personnel, program teams, Information Assurance, and other IT organizations to resolve technical and operational issues.
- Develop and maintain network diagrams, technical documentation, configuration records, asset information, and standard operating procedures.
- Support audit preparation, evidence collection, compliance activities, and Information Assurance requirements, including SSP and ATO-related activities.
- Partner with the Network Architect on network standardization, modernization, technical projects, and the transition to the future eWAN architecture.
- Mentor and provide technical guidance to less-experienced network personnel.
- Participate in cross-training activities to provide resilient support across both CUI and classified network environments.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Engineering, or a related discipline; equivalent relevant education, certifications, and experience may be considered.
- Ten or more years of relevant network administration, network engineering, or network security experience preferred.
- Current CCNP and Security+ certifications, or CCNP Security certification.
- Secret security clearance required
- Strong hands-on experience with Cisco switching and routing technologies, including VLANs, VSS/VSL, OSPF, EIGRP, BGP, and IP addressing/subnetting.
- Strong experience with Cisco ISE, 802.1X, and Zero Trust network-access concepts.
- Experience administering and troubleshooting IPsec VPN, DMVPN, and/or Layer 2 EVPN technologies.
- Hands-on experience with Cisco Firepower Threat Defense and Firepower Management Center.
- Experience with Palo Alto firewalls and Panorama.
- Experience with Cisco Catalyst Center.
- Demonstrated ability to troubleshoot complex network, routing, switching, firewall, and connectivity issues in a multi-site environment.
- Ability to execute approved network changes in accordance with security, configuration-management, and change-control processes.
- Strong written and verbal communication skills, including the ability to create technical documentation and coordinate effectively with diverse stakeholders.
- Ability to work full-time on-site in Scottsdale, Arizona, with occasional on-call support and travel as required.
Preferred Qualifications
- Experience supporting Department of Defense, classified, CUI, restricted, or air-gapped network environments.
- Experience with DoD Comply to Connect requirements.
- Knowledge of DoD Security Technical Implementation Guides (STIGs), network hardening, vulnerability remediation, and security compliance practices.
- Experience supporting Risk Management Framework (RMF), System Security Plans (SSPs), Authorization to Operate (ATO) activities, audits, or inspections.
- Experience with SolarWinds or comparable network monitoring and management tools.
- TACLANE configuration, troubleshooting, and operational-support experience.
- Experience supporting remote-access infrastructure and secure remote engineering connectivity.
- Experience coordinating multi-site deployments, circuit providers, vendors, and field personnel.
#CJ3