Defense Engineering, Inc. (DEi) is seeking an expert GovCloud Network Engineer to architect, deploy, and manage highly secure cloud networking environments. This role is dedicated to establishing and maintaining critical connections between the Department of Defense Information Network (DoDIN), NIPRNet/SIPRNet and AWS GovCloud (US) regions.
The ideal candidate possesses deep, hands-on experience working alongside the Defense Information Systems Agency (DISA) to execute Boundary Cloud Access Point (BCAP) cutovers, navigate the SCCA Network Approval Process (SNAP), and implement the Cloud Permission to Connect (CPTC) workflow. You will serve as our primary network authority, designing complex route table topologies across Inspection, Egress, and Perimeter VPCs, leveraging AWS Transit Gateway, and integrating Next-Generation Firewalls (NGFW) to facilitate compliant, secure cloud routing.
Key Responsibilities
1. DISA & BCAP Connectivity Engineering
- BCAP Planning & Execution: Design, coordinate, and execute end-to-end Boundary Cloud Access Point (BCAP) cutovers in collaboration with DISA and mission partners.
- Connection Process Management: Lead the technical submission processes for SCCA Network Approval Process (SNAP) and Cloud Permission to Connect (CPTC) workflows to secure an Authority to Connect (ATC).
- IP & Subnet Allocation: Manage NIPRNet IP block assignments (e.g., issued /24 ranges) and integrate them within a compliant cloud network architecture.
- Hybrid Cloud Transport: Establish resilient, private connectivity into AWS GovCloud using AWS Direct Connect (DX), Direct Connect Gateways (DXGW), and backup IPsec VPNs.
2. AWS Secure Cloud Routing & Topology
- Transit Gateway Architecture: Design, configure, and manage AWS Transit Gateway (TGW) instances, including complex TGW Route Tables, Route Table Associations, Route Table Propagations, and TGW Peerings.
- Multi-VPC Topology Design: Structure and automate route tables across highly isolated, functional enclaves including:
- Perimeter VPCs: Hosting boundary ingress/egress points.
- Inspection VPCs: Centralizing traffic interception, deep packet inspection, and security analysis.
- Egress VPCs: Controlling out-of-band communication and secure software repository syncing.
- Mission Owner VPCs: Containing isolated application tiers.
- VPC Peering & Transit Gateways: Properly evaluate design trade-offs between VPC Peering, Transit Gateway, and Transit Gateway Connect attachments.
3. Network Security & SCCA Compliance (VDSS)
- Virtual Data Center Security Stack (VDSS): Deploy and operate the VDSS layer to protect the network perimeter according to the DISA SCCA framework.
- Firewall Integration: Deploy, configure, and cluster third-party Network Virtual Appliances (NVAs)-such as Palo Alto VM-Series or Fortinet FortiGate-using AWS Transit Gateway Appliance Mode for stateful inspection.
- AWS Native Security Control: Manage AWS Network Firewall rulesets, authorizing custom Suricata stateful rules for both east-west (inter-VPC) and north-south (external/on-premises) traffic.
- DNS Resolution & Security: Implement DNS control using Amazon Route 53 Resolver, private hosted zones, and Route 53 DNS Firewall rules.
- Private Ingress & Egress: Facilitate secure, private API access utilizing AWS PrivateLink (VPC Endpoints) to restrict public-IP exposure.
- Compliance Enforcement: Harden all networking infrastructure and virtual appliances in accordance with the latest DISA Security Technical Implementation Guides (STIGs).
AWS Networking & Security Components Utilized
As a Senior Networking Expert, you must have advanced, practical mastery of the following AWS networking components:
- Core Transport & Transit: AWS Transit Gateway (TGW), TGW VPC Attachments, TGW Route Tables, AWS Direct Connect (DX), Direct Connect Gateway (DXGW), Virtual Private Gateway (VGW), Transit Gateway Connect.
- VPC Routing & Subnetting: Custom AWS Route Tables, local/static routes, VPC Peering, Private Subnets, Public Subnets, and NAT Gateways.
- Network Ingress/Egress & Security: AWS Network Firewall, AWS Web Application Firewall (WAF), AWS Shield, Network Load Balancers (NLB), Application Load Balancers (ALB).
- Private Service Connectivity: AWS PrivateLink (Interface and Gateway VPC Endpoints), Route 53 Resolver (Inbound/Outbound Endpoints), DNS Firewall.
- Traffic Inspection & Monitoring: VPC Flow Logs, Traffic Mirroring (for forwarding copies of packets to IDS/IPS or third-party monitoring appliances).
- Hybrid Connectivity Security: AWS Site-to-Site VPN, IPsec tunnels, Accelerated VPN.
Required Qualifications
- Security Clearance: Active U.S. Government Secret clearance (Top Secret/SCI preferred) due to working on DISN/NIPRNet IL4 and IL5 networks.
- Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience.
- Experience: 5+ years of dedicated cloud and hybrid networking experience with at least 3 years explicitly focused on AWS GovCloud (US)
- DISA/SCCA Expertise: Direct experience managing connections to a DISA BCAP, configuring Boundary protection enclaves (VDSS), and implementing the SCCA Reference Design.
- Protocol Depth: Strong foundation in BGP routing protocols, IPsec, GRE, NAT/PAT, TCP/IP stack behavior, and RFC 1918 private networking guidelines.
- Automation: Proficient in automating network topologies using Terraform or CloudFormation, maintaining configuration versioning via Git.
- DoD 8570/8140 Compliance: Meet IAT Level II baseline certification requirements (e.g., Security+ CE, CCNA Security, or CySA+), with an IAT Level III preferred (CISSP, CASP+).
Preferred Qualifications
- AWS Certified Advanced Networking - Specialty (strongly preferred).
- Palo Alto Networks Certified Network Security Engineer (PCNSE).
- Demonstrated experience with AWS Transit Gateway Appliance Mode configuration for stateful third-party firewall traffic symmetry.
- Previous experience operating within the DoD Joint Warfighting Cloud Capability (JWCC) or similar defense agency multi-cloud networks.