Network Engineer III

Gentry Professional Services, Inc.

San Antonio (TX)

On-site

USD 140,000 - 210,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) with 4% match
Health insurance
Dental insurance
Vision insurance
HSA

Job summary

Gentry Professional Services seeks a Senior Principal Network Systems Engineer to architect and sustain high-availability launch and test networks for classified and unclassified enclaves in the San Antonio area. The role requires TS clearance with SCI eligibility and hands-on expertise across routers, switches, firewalls, and related security controls.

You will lead design, testing, and implementation plans, coordinate with ISSMs/ISSOs, and drive RMF-aligned protections while embedding security

Qualifications

  • U.S. citizenship with active DoD Top Secret clearance and SCI eligibility/access within the last 24 months.
  • DoD 8570 IAT Level II certification or equivalent prior to start.
  • Hands-on experience planning, implementing, operating, and troubleshooting routed and switched IP networks (IPv4, OSPF, VLANs, VPNs, firewalls).
  • Strong collaboration with cyber teams and ISSMs/ISSOs to maintain RMF-aligned protections.

Responsibilities

  • Design, plan, configure, and sustain complex, multi-node networks spanning classified and unclassified enclaves with detailed schematics for routers, switches, firewalls, and gateways.
  • Lead end-to-end testing and validation, verify configurations, and monitor performance for reliability and security policy compliance.
  • Develop and execute implementation plans for enhancements, upgrades, and migrations while coordinating with stakeholders to minimize disruption.
  • Engineer and operate core network services (DNS, DHCP, NTP, AAA) and segmented architectures with trusted boundaries across enclaves.
  • Implement and tune network security controls (firewalls, VPNs, ACLs, IDS/IPS, NAC) in coordination with cyber teams.
  • Support NOC/SOC operations with fault and performance monitoring, incident response, and change management.

Job description

In this role you will help architect, build, and sustain high-availability launch and test networks that span classified and unclassified enclaves. As a network-strong engineer with meaningful cyber depth, you will lead network design, implementation, and performance tuning while partnering with cyber teams to embed RMF-aligned protections and secure baselines into the infrastructure. You will design and plan network communications systems, produce specifications and detailed schematics, recommend hardware and software to meet present and future capacity requirements, test network designs, and evaluate emerging communications technologies. You will join a customer-supported engineering team in the San Antonio, TX area and maintain deep technical expertise across routers, switches, firewalls, multiplexers, bridges, and gateways. This position is 100% onsite and requires an active Top Secret clearance with SCI eligibility.

Schedule: full-time schedule.

Responsibilities
  • Design, plan, configure, and sustain complex, multi-node enterprise-scale networks spanning classified and unclassified enclaves, maintaining detailed schematics and specifications for routers, switches, firewalls, multiplexers, bridges, and gateways.
  • Partner with customer ISSMs/ISSOs and cyber engineering teams to develop and implement network changes in environments operating under, or seeking, an ATO/IATT, keeping designs aligned to RMF requirements.
  • Lead end-to-end testing and validation of network designs, verifying configurations and monitoring hardware and link performance for reliability, availability, and compliance with security policy.
  • Develop and execute implementation plans for enhancements, upgrades, and migrations, coordinating with stakeholders to minimize service disruption and documenting all changes and rollback plans.
  • Engineer and operate core network services (DNS, DHCP, NTP, AAA) and segmented architectures that enforce well-defined trust boundaries and enable controlled information sharing across enclaves.
  • Implement and tune network-level security controls — firewalls, VPNs, ACLs, IDS/IPS, and NAC — in close coordination with cyber and security teams so protections are built in rather than bolted on.
  • Support network operations including fault and performance monitoring, incident response, and change management, using NMS and log/SIEM platforms within an integrated NOC/SOC construct.
  • Perform physical-layer installation work (fiber, patch panels, encryption devices), maintain accurate as-built documentation and configuration baselines, and brief technical options, trade-offs, risks, and recommendations to internal and external stakeholders.
Basic Qualifications
  • Bachelor's degree in a Science, Technology, Engineering, or Mathematics (STEM) discipline from an accredited institution and 8 years of related professional/military engineering experience; or a Master's degree in a STEM discipline and 6 years; or a Ph.D. in a STEM discipline and 4 years.
  • U.S. citizenship with a current DoD Top Secret security clearance and SCI eligibility/access active within the last 24 months.
  • DoD 8570 IAT Level II certification (e.g., Security+ CE) or equivalent prior to start.
  • Hands-on experience planning, implementing, operating, and troubleshooting routed and switched IP networks (IPv4, OSPF, VLANs, VPNs, firewalls) in mission-critical or real-time environments, including administration of Microsoft and Linux networked systems and applying foundational cybersecurity practices (hardening, secure configuration, access control) alongside cyber/security teams.
Preferred Qualifications
  • Proven experience as a network design authority or principal engineer for new deployments or major redesigns from concept through cutover, including high- and low-level designs, ICDs, addressing and routing plans, firewall/ACL matrices, and NOC runbooks.
  • Extensive hands-on experience designing, implementing, and maintaining enterprise-scale physical and virtual networks (Cisco routing/switching, firewalls, VPNs, VMware vSphere/ESXi/NSX) with well-maintained schematics and configuration baselines.
  • Deep routing and switching expertise in enterprise or mission networks — route filtering, convergence tuning, VLAN/VXLAN, spanning-tree variants, MLAG/port-channeling, QoS and traffic engineering — plus tuning of firewalls, IDS/IPS, NAC, and endpoint protection; Cisco CCNP or higher (e.g., CCIE) strongly preferred.
  • Experience architecting and supporting multi-node test or launch networks for test ranges, weapon systems, or other real-time mission systems where latency, determinism, and availability are critical.
  • Strong experience engineering and securing DNS, DHCP, NTP, and AAA (RADIUS/TACACS+) in mission-critical networks, including split-horizon DNS, DNSSEC, DHCP authorization, authenticated NTP, and integration with identity systems such as Active Directory.
  • Extensive experience designing segmented architectures (user, server, management, security, out-of-bag) with well-defined trust boundaries in multi-domain or cross-domain environments, including controlled information sharing between classified and unclassified networks using guards, data diodes, and MLS/CDS solutions.
  • Demonstrated ability to align network architecture with RMF/ATO requirements and apply DISA STIGs and CIS benchmarks to routers, switches, firewalls, and VPN gateways, building standard baselines (AAA, logging, NTP, SNMP, management access, banners, crypto settings) and verifying compliance at scale.
  • Proficiency in network automation, configuration management, and Infrastructure-as-Code (Ansible, Python, Bash, PowerShell), including device provisioning, configuration templating, drift detection, bulk policy updates, and automated compliance checks.
  • Experience working within an integrated Network Operations Center — fault and performance monitoring, event correlation, escalation workflows, and SOC collaboration — with strong layer 1–7 troubleshooting and a track record of restoring service quickly.
  • Experience leading end-to-end network testing and validation, including performance, resiliency, and failover testing in distributed environments, and executing upgrade and migration plans while minimizing mission impact; experience with VoIP, SIP trunking, and QoS in converged voice/data networks is highly desired.
  • Strong interpersonal, written, and verbal communication skills, with demonstrated ability to work across cyber, systems, software, and test teams to capture requirements, document designs and decisions, and brief options, trade-offs, and risks to technical stakeholders and leadership.

Note: This position is intended to be contract-to-hire. While that is the intent, it is not a promise of conversion by our client. This contract role aligns with a full-time Senior Principal Network Systems Engineer position.

Benefits — tailored to your needs

When establishing benefits, our employees lead the charge. Benefits available may include:

  • Flexible scheduling where available
  • 401(k) with 4% company match
  • Health, dental, and vision insurance
  • Healthcare savings account (HSA)
  • Paid time off, including holidays
  • Performance-based bonuses
About Gentry Professional Services

Gentry Professional Services is an elite consulting firm connecting top-tier industry experts with challenging projects and alternative work arrangements. For more information, visit gentryservices.com or follow us on LinkedIn.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Engineer
Senior Network Engineer

Abile Group, Inc • Virginia (MN)

On-site
USD 90,000 - 120,000
Senior Network Engineer
Senior Network Engineer

Abile Group, Inc • Quantico (VA)

On-site
USD 100,000 - 130,000
Network Engineer (Clearance Required)
Network Engineer (Clearance Required)

Kroll • Fort Meade (MD)

On-site
USD 100,000 - 150,000
Comprehensive healthcare coverage
Generous paid time off
401(k) matching plans
Network Engineer 2-909
Network Engineer 2-909

Onyx Point, Inc. • Hanover (MD)

On-site
USD 78,000 - 250,000
Health Coverage
401(k) plan
PTO & holidays
+6
Network Engineer 2-905
Network Engineer 2-905

Onyx Point, Inc. • Hanover (MD)

Hybrid
USD 78,000 - 250,000
Health Coverage
Retirement Plan
Paid Time Off
+8
Senior Network Engineer
Senior Network Engineer

Abile Group, LLC • Quantico (VA)

On-site
USD 80,000 - 120,000
Network Engineer - TS/SCI w/ Poly
Network Engineer - TS/SCI w/ Poly

General Dynamics Information Technology • Herndon (VA)

On-site
USD 120,000 - 160,000
401K with company match
Comprehensive health packages
Internal mobility team
Network Engineer - TS/SCI w/ Poly
Network Engineer - TS/SCI w/ Poly

General Dynamics Information Technology • McLean (VA)

On-site
USD 182,750 - 247,250
401K with company match
Comprehensive health packages
Professional growth opportunities
Sr. Network Engineer
Sr. Network Engineer

Astrion • Columbia (MD)

On-site
USD 145,000 - 165,000
Network Engineer Senior – TS/SCI required
Network Engineer Senior – TS/SCI required

General Dynamics Information Technology • Charlottesville (VA)

On-site
USD 127,500 - 172,500
401(k) with company match
Medical, dental, vision plans
Paid time off
+1