001 Sr AWS GovCloud Network Engineer

Defense Engineering Inc.

Northern (KY)

Hybrid

USD 130,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Defense Engineering, Inc. seeks an expert GovCloud Network Engineer to architect, deploy, and manage secure cloud networking environments across DoDIN, NIPRNet/SIPRNet, and AWS GovCloud (US).

The ideal candidate will work with DISA to perform BCAP cutovers, navigate SNAP and CPTC workflows, and design complex TGW route tables across multiple VPCs with NGFW integration for compliant, private cloud routing.

Qualifications

  • Active U.S. Government Secret clearance; Top Secret/SCI preferred.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience.

Responsibilities

  • DISA BCAP connectivity planning, execution with mission partners.
  • Lead SNAP and CPTC workflows to secure ATC.
  • Manage NIPRNet IP blocks and integrate into cloud architecture.
  • Design TGW topologies with complex route tables and associations.
  • Integrate NGFWs and TGW Appliance Mode for inspection traffic.
  • Enforce DISA STIGs and SCCA compliance across the network.

Skills

BCAP engineering
DISA
SCCA SNAP
CPTC
GovCloud AWS
Transit Gateway
NGFW integration
IPsec VPNs
Route Tables
NIPRNet
Route53 Resolver
VDSS
Terraform
CloudFormation
Git

Education

Bachelor’s degree in CS/Cybersecurity/IS

Tools

Palo Alto VM-Series
Fortinet FortiGate
Terraform
CloudFormation

Job description

Defense Engineering, Inc. (DEi) is seeking an expert GovCloud Network Engineer to architect, deploy, and manage highly secure cloud networking environments. This role is dedicated to establishing and maintaining critical connections between the Department of Defense Information Network (DoDIN), NIPRNet/SIPRNet and AWS GovCloud (US) regions.

The ideal candidate possesses deep, hands-on experience working alongside the Defense Information Systems Agency (DISA) to execute Boundary Cloud Access Point (BCAP) cutovers, navigate the SCCA Network Approval Process (SNAP), and implement the Cloud Permission to Connect (CPTC) workflow. You will serve as our primary network authority, designing complex route table topologies across Inspection, Egress, and Perimeter VPCs, leveraging AWS Transit Gateway, and integrating Next-Generation Firewalls (NGFW) to facilitate compliant, secure cloud routing.

Key Responsibilities
1. DISA & BCAP Connectivity Engineering
  • BCAP Planning & Execution: Design, coordinate, and execute end-to-end Boundary Cloud Access Point (BCAP) cutovers in collaboration with DISA and mission partners.
  • Connection Process Management: Lead the technical submission processes for SCCA Network Approval Process (SNAP) and Cloud Permission to Connect (CPTC) workflows to secure an Authority to Connect (ATC).
  • IP & Subnet Allocation: Manage NIPRNet IP block assignments (e.g., issued /24 ranges) and integrate them within a compliant cloud network architecture.
  • Hybrid Cloud Transport: Establish resilient, private connectivity into AWS GovCloud using AWS Direct Connect (DX), Direct Connect Gateways (DXGW), and backup IPsec VPNs.
2. AWS Secure Cloud Routing & Topology
  • Transit Gateway Architecture: Design, configure, and manage AWS Transit Gateway (TGW) instances, including complex TGW Route Tables, Route Table Associations, Route Table Propagations, and TGW Peerings.
  • Multi-VPC Topology Design: Structure and automate route tables across highly isolated, functional enclaves including:
  • Perimeter VPCs: Hosting boundary ingress/egress points.
  • Inspection VPCs: Centralizing traffic interception, deep packet inspection, and security analysis.
  • Egress VPCs: Controlling out-of-band communication and secure software repository syncing.
  • Mission Owner VPCs: Containing isolated application tiers.
  • VPC Peering & Transit Gateways: Properly evaluate design trade-offs between VPC Peering, Transit Gateway, and Transit Gateway Connect attachments.
3. Network Security & SCCA Compliance (VDSS)
  • Virtual Data Center Security Stack (VDSS): Deploy and operate the VDSS layer to protect the network perimeter according to the DISA SCCA framework.
  • Firewall Integration: Deploy, configure, and cluster third-party Network Virtual Appliances (NVAs)-such as Palo Alto VM-Series or Fortinet FortiGate-using AWS Transit Gateway Appliance Mode for stateful inspection.
  • AWS Native Security Control: Manage AWS Network Firewall rulesets, authorizing custom Suricata stateful rules for both east-west (inter-VPC) and north-south (external/on-premises) traffic.
  • DNS Resolution & Security: Implement DNS control using Amazon Route 53 Resolver, private hosted zones, and Route 53 DNS Firewall rules.
  • Private Ingress & Egress: Facilitate secure, private API access utilizing AWS PrivateLink (VPC Endpoints) to restrict public-IP exposure.
  • Compliance Enforcement: Harden all networking infrastructure and virtual appliances in accordance with the latest DISA Security Technical Implementation Guides (STIGs).
AWS Networking & Security Components Utilized

As a Senior Networking Expert, you must have advanced, practical mastery of the following AWS networking components:

  • Core Transport & Transit: AWS Transit Gateway (TGW), TGW VPC Attachments, TGW Route Tables, AWS Direct Connect (DX), Direct Connect Gateway (DXGW), Virtual Private Gateway (VGW), Transit Gateway Connect.
  • VPC Routing & Subnetting: Custom AWS Route Tables, local/static routes, VPC Peering, Private Subnets, Public Subnets, and NAT Gateways.
  • Network Ingress/Egress & Security: AWS Network Firewall, AWS Web Application Firewall (WAF), AWS Shield, Network Load Balancers (NLB), Application Load Balancers (ALB).
  • Private Service Connectivity: AWS PrivateLink (Interface and Gateway VPC Endpoints), Route 53 Resolver (Inbound/Outbound Endpoints), DNS Firewall.
  • Traffic Inspection & Monitoring: VPC Flow Logs, Traffic Mirroring (for forwarding copies of packets to IDS/IPS or third-party monitoring appliances).
  • Hybrid Connectivity Security: AWS Site-to-Site VPN, IPsec tunnels, Accelerated VPN.
Required Qualifications
  • Security Clearance: Active U.S. Government Secret clearance (Top Secret/SCI preferred) due to working on DISN/NIPRNet IL4 and IL5 networks.
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience.
  • Experience: 5+ years of dedicated cloud and hybrid networking experience with at least 3 years explicitly focused on AWS GovCloud (US)
  • DISA/SCCA Expertise: Direct experience managing connections to a DISA BCAP, configuring Boundary protection enclaves (VDSS), and implementing the SCCA Reference Design.
  • Protocol Depth: Strong foundation in BGP routing protocols, IPsec, GRE, NAT/PAT, TCP/IP stack behavior, and RFC 1918 private networking guidelines.
  • Automation: Proficient in automating network topologies using Terraform or CloudFormation, maintaining configuration versioning via Git.
  • DoD 8570/8140 Compliance: Meet IAT Level II baseline certification requirements (e.g., Security+ CE, CCNA Security, or CySA+), with an IAT Level III preferred (CISSP, CASP+).
Preferred Qualifications
  • AWS Certified Advanced Networking - Specialty (strongly preferred).
  • Palo Alto Networks Certified Network Security Engineer (PCNSE).
  • Demonstrated experience with AWS Transit Gateway Appliance Mode configuration for stateful third-party firewall traffic symmetry.
  • Previous experience operating within the DoD Joint Warfighting Cloud Capability (JWCC) or similar defense agency multi-cloud networks.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GovCloud Network Architect for DoD & BCAP
Senior GovCloud Network Architect for DoD & BCAP

Defense Engineering Inc. • Northern (KY)

Hybrid
USD 130,000 - 190,000
System Engineer (Cloud)
System Engineer (Cloud)

By Light Professional IT Services LLC • Scott Air Force Base (IL)

On-site
USD 120,000 - 170,000
System Engineer (Cloud)
System Engineer (Cloud)

By Light Professional IT Services • Scott Air Force Base (IL)

On-site
USD 140,000 - 190,000
NS-Cloud Network Architect, Senior (Tactical / Hybrid Cloud / Zero Trust)
NS-Cloud Network Architect, Senior (Tactical / Hybrid Cloud / Zero Trust)

NetSEA Technologies • Aberdeen Proving Ground (MD)

On-site
USD 120,000 - 160,000
Network Engineer
Network Engineer

PineQ Lab Technology • United States

On-site
USD 100,000 - 130,000
Senior Cloud Infrastructure Consultant (Active TS/SCI)
Senior Cloud Infrastructure Consultant (Active TS/SCI)

cginfinity • Chantilly (VA)

On-site
USD 180,000 - 230,000
Network Security Cloud Engineer
Network Security Cloud Engineer

Fixity Technologies • Phoenix (AZ)

On-site
USD 130,000 - 190,000
Cloud Infrastructure Architect - AWS (TS/SCI Clearance Required)
Cloud Infrastructure Architect - AWS (TS/SCI Clearance Required)

North Point Technology • Washington

On-site
USD 130,000 - 170,000
Cloud Network Engineer
Cloud Network Engineer

Angsignal • Washington

On-site
USD 100,000 - 130,000
401(k) matching
Dental insurance
Health insurance
+1
Cloud Engineer
Cloud Engineer

Endurion • Tampa (FL)

On-site
USD 95,000 - 140,000