Network Architect

Talentify

Fort Belvoir (VA)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

ValidaTek seeks an experienced Network Engineer (SME) to support the DTRA program at Fort Belvoir, VA. You’ll work with government leadership to advance modernization across CSfC-based networks and secure multi-layer architectures.

This role requires active TS/SCI clearance, DoD/DoW network experience, and hands-on expertise with Cisco/Aruba VPNs, Palo Alto firewalls, and 802.1X. Join a fast-moving team delivering mission-critical IT services.

Qualifications

  • Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, MIS, or related STEM field; 12–15 years of relevant experience
  • 12+ years of progressive network engineering experience in DoD/DoW, federal, or defense contractor environments
  • Active TS/SCI Clearance
  • Active 8570.01-M/8140 IAT Level II/III baseline certification (e.g., Security+ CE, CySA+, CASP+, CISSP)
  • One or more of: Cisco CCNA/CCNP, Aruba ACSA/ACSP
  • Experience configuring Cisco IOS-XE/ASR and Aruba IPsec/SSL VPNs including IKEv2
  • Experience with Palo Alto PAN-OS, Panorama, IDS/IPS
  • Experience with Cisco ISE and Aruba ClearPass 802.1X deployment
  • X.509 certificates, CA hierarchy, CRLs, OCSP, secure NTP
  • NSA CSfC capabilities (Mobile Access, Multi-Site, Campus WLAN)
  • Familiarity with CNSA suites and HSMs
  • Ansible automation for network configuration and cert rotation

Responsibilities

  • Architect, deploy, and maintain CSfC infrastructure within black/gray/red networks
  • Design, configure, and maintain CSfC architectures aligned with NSA capability packages
  • Implement routing protocols (BGP/OSPF) with multi VPN tunnels across Cisco/Aruba
  • Configure remote access SSL VPNs and ensure end-to-end traffic separation
  • Audit Palo Alto NGFW policies, App-ID, User-ID, URL filtering and IDS/IPS signatures
  • Manage ISE and ClearPass policy managers for 802.1X access control
  • Integrate PKI components including certificates, CA hierarchy, OCSP validation
  • Prepare CSfC compliance artifacts and PMO submission packages
  • Maintain NDA, security posture, and compliance documentation
  • Coordinate with government leadership to drive innovation and efficiency

Skills

CSfC networking
BGP/OSPF
Palo Alto firewalls
802.1X authentication
NIAP/NSA CSfC
PKI/OCSP
NTP security
Ansible

Education

Bachelor's degree or higher in CS/IT/Engineering
Active TS/SCI Clearance

Tools

Cisco IOS-XE/ASR
Aruba Mobility Controllers
Palo Alto PAN-OS
Cisco ISE
Aruba ClearPass

Job description

Company Overview:

At ValidaTek, we modernize and optimize IT services to solve some of the most critical challenges facing federal civilian and defense agencies. From customers to partners to top-talent employees, ValidaTek puts people first, empowering them to exceed expectations and transform government organizations. Our employees are building purpose-driven careers, not just filling jobs. We bring together people with many different perspectives, experiences, and talents to drive innovation and achieve more together than we can individually. Our commitment to quality and performance optimization is the reason why our IT Service Projects and New Development Projects have been appraised at CMMI Maturity Level 5, positioning us as one of a handful of elite companies to receive the highest form of third‑party validation. www.validatek.com

Summary:

ValidaTek is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio.

Responsibilities:
  • The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing.
  • Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks.
  • Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi‑Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual‑tunnel encryption mandates.
  • Understanding of NIAP approved list and monitors for changes
  • Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual‑tunnel encryption mandates.
  • Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end‑to‑end traffic separation.
  • Author, optimize, and audit Palo Alto Next‑Generation Firewall (NGFW) security policies, App‑ID, User‑ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti‑spyware, and vulnerability protection.
  • Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling.
  • Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure.
  • Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission.
Qualifications:
  • Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree.
  • 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments
  • Active TS/SCI Clearance
  • Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP).
  • Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP
  • Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF).
  • Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles.
  • Hands‑on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role‑based access policies.
  • Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization.
  • Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi‑Site Connectivity, or Campus WLAN).
  • Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post‑quantum readiness considerations, and hardware security modules (HSMs).
  • Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations.
  • Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
Salary Disclosure:

Actual salary will be based on a variety of factors including but not limited to experience, geographic location, contract affordability, internal equity, education, and certifications. The upper end of the salary range may be reserved for individuals who have demonstrated tenure with the company, seniority, and proven excellent performance. This includes factors such as education, certifications, and extensive/unique experience beyond what is required.

EEO Statement:

ValidaTek is an Equal Opportunity Employer. All qualified applicants will be considered without regard to disability, protected veteran status, or any other status protected by federal, state, or local laws. Applicants who are selected for employment will be required to verify authorization to work in the United States. Offers of employment will be contingent upon passing a post‑offer background check.

Qualifications
Education
Preferred

Bachelors

Licenses & Certifications
Preferred
ITILv3 Foundations

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Network Architect
Network Architect

Validatek • Fort Belvoir (VA)

On-site
USD 120,000 - 140,000
Network Engineer/Architect
Network Engineer/Architect

Career Listings • Springfield (VA)

On-site
USD 150,000 - 210,000
401(k)
401(k) matching
Dental insurance
+6
Network Engineer/Architect
Network Engineer/Architect

Sarela Technology Solutions • Fort Belvoir (VA)

On-site
USD 120,000 - 180,000
401(k)
401(k) matching
Dental insurance
+6
Senior Network Engineer
Senior Network Engineer

Talentify • Arlington (VA)

Hybrid
USD 115,000 - 190,000
Senior Network Engineer
Senior Network Engineer

Talentify • Quantico (VA)

On-site
USD 95,000 - 140,000
Network Engineer
Network Engineer

Talentify • Arlington (VA)

On-site
USD 120,000 - 180,000
Network Security Engineer CLEARED
Network Security Engineer CLEARED

Take2 Consulting, LLC • Fort Belvoir (VA)

On-site
USD 140,000 - 200,000
Network Engineer (SME)
Network Engineer (SME)

JCS Solutions LLC • Fort Belvoir (VA), Northern (KY)

On-site
USD 87,000 - 127,000
Health, dental, and vision insurance
Life insurance
Short- and long-term disability
+3
Network Engineer
Network Engineer

ITC Federal, Inc • Fort Meade (MD)

On-site
USD 110,000 - 150,000
Network Engineer
Network Engineer

ITC Federal, LLC • Fort Meade (MD), Northern (KY)

Hybrid
USD 110,000 - 140,000