Description
Concept Solutions is seeking a Senior Network and Cloud Engineer to support the Federal Aviation Administration Command Control and Communications office. The C3 office helps FAA leaders maintain situational awareness and continuity of communications during national emergencies, natural disasters, and major technology disruptions. When service is interrupted, the team supports rapid recovery of essential communications.
This position is a senior hands-on engineering role focused on the network infrastructure that connects FAA data centers, field locations, and AWS environments. The engineer will lead assigned network and hybrid-cloud workstreams, provide tier-three troubleshooting, and advise program leadership on secure, available, and supportable solutions. The role works closely with cloud platform, cybersecurity, systems, application, and telecommunications teams.
Enterprise Network Engineering
- Design, implement, maintain, and improve enterprise LAN, WAN, and metropolitan network services supporting mission-critical operations.
- Configure and troubleshoot routers, switches, firewalls, load balancers, network segmentation, routing protocols, and high-availability designs in multi-vendor environments.
- Assess capacity, performance, resiliency, carrier diversity, and technical lifecycle risks, and recommend practical improvements.
- Coordinate with systems administrators and application teams to verify server-to-network integration and reliable access for local and remote users.
AWS Hybrid Networking
- Design, build, and support secure connectivity between FAA on-premises environments and AWS using services such as Direct Connect, Transit Gateway, Site-to-Site VPN, VPC routing, and Route 53.
- Lead the network portions of cloud migration and modernization efforts, including connectivity planning, routing, segmentation, firewall policy, cutover, testing, and rollback preparation.
- Configure and maintain VPC network components, including subnets, route tables, security groups, network access control lists, endpoints, and shared connectivity across AWS accounts.
- Support networking within established multi-account landing zones and coordinate changes with the cloud platform and security teams.
- Implement redundant connectivity and disaster recovery network designs that support established recovery time and recovery point objectives.
- Identify network-related opportunities to improve AWS utilization and cost efficiency and support the program's broader cloud cost-governance process.
Security and Federal Compliance
- Implement and validate network security controls across on-premises and AWS environments in support of NIST SP 800-53, FISMA, FedRAMP, OMB Circular A-130, applicable STIGs, and the program's Authorization to Operate.
- Apply Zero Trust principles through segmentation, least-privilege access, secure remote connectivity, identity-aware controls, and continuous monitoring.
- Configure and support firewalls, IPsec tunnels, client VPN services, 802.1X, AWS security groups, AWS Network Firewall or WAF where applicable, and related logging and alerting.
- Partner with cybersecurity staff on security assessments, evidence collection, vulnerability remediation, configuration reviews, and continuous monitoring.
Operations Automation and Support
- Provide tier-three troubleshooting for complex outages and performance issues involving routing, packet loss, latency, asymmetric paths, firewall policy, DNS, or carrier services.
- Use packet analysis, flow data, logs, and monitoring platforms to determine root cause and restore service within operational priorities.
- Automate repeatable network and AWS configuration tasks using infrastructure-as-code, configuration management, scripting, version control, and controlled deployment pipelines.
- Maintain accurate diagrams, configurations, procedures, implementation plans, rollback plans, and operational documentation.
- Validate patches, firewall changes, automation, and cloud network modifications in a segregated test environment before production release.
- Coordinate with telecommunications carriers and internet service providers to troubleshoot circuits and restore external connectivity.
- Mentor junior engineers and share operational knowledge with the broader team.
- Participate in an after-hours on-call rotation and respond promptly to critical network incidents.
Requirements
- Bachelor's degree in computer science, electrical engineering, information technology, or a related technical discipline. Eight additional years of directly relevant network engineering experience may substitute for the degree.
- Relevant Experience**: Minimum of fifteen (15) years of progressive, relevant experience in enterprise-scale network design, implementation, and operations.
- At least three years of recent hands-on experience supporting AWS networking or hybrid connectivity in an enterprise, federal, or similarly regulated environment.
- Demonstrated experience with Cisco routing and switching, TCP IP, BGP or OSPF, VLANs, high availability, and enterprise firewalls.
- Hands-on experience with AWS VPC networking and at least two of the following: Direct Connect, Transit Gateway, Site-to-Site VPN, or Route 53.
- Experience troubleshooting complex network incidents using packet captures, flow data, logs, and network monitoring tools.
- Experience working in a federal contracting, government, defense, or other highly regulated environment.
- Ability to obtain and maintain a Secret security clearance and to meet the position's on-site, travel, and on-call requirements.
- Ability to explain technical risks and recommendations clearly to engineers, program leaders, customers, and external vendors.
Preferred Qualifications:
- Active Secret or higher security clearance.
- Experience supporting AWS GovCloud, multi-account environments, Control Tower, AWS Organizations, or enterprise landing zones.
- Experience with Juniper routing, Cisco Catalyst or Nexus, Palo Alto or Cisco Secure Firewalls, F5 BIG-IP, SD-WAN, MPLS, or network virtualization.
- Working knowledge of one or more automation tools such as Terraform, AWS CloudFormation, Ansible, or Python, with experience using Git and a controlled CI CD process.
- Experience supporting NIST SP 800-53, FISMA, FedRAMP, STIG implementation, vulnerability remediation, continuous monitoring, or ATO evidence activities.
- Experience with AWS security and visibility services such as IAM, KMS, Security Hub, GuardDuty, Config, CloudWatch, VPC Flow Logs, Network Manager, Network Firewall, or WAF.
- Experience with SolarWinds, NetFlow, Riverbed, Cisco Catalyst Center, Splunk, Wireshark, or comparable monitoring and diagnostic platforms.
- Relevant certification such as CCNP Enterprise, CCIE, JNCIP, AWS Certified Advanced Networking Specialty, AWS Certified Solutions Architect Professional, AWS Certified Security Specialty, Security Plus CE, or CISSP.
Location and Schedule
Location Washington DC
Schedule Full time Monday through Friday with core hours from 9:00 a.m. to 3:00 p.m. local time
Work arrangement On site during onboarding and until fully trained; limited telework may be available afterward based on demonstrated proficiency and customer approval
Travel Approximately 10 to 15 percent, primarily within the Maryland and Virginia area
Clearance Must be eligible to obtain and maintain a Secret clearance; active Secret clearance is strongly preferred
Salary $160,000 to $170,000
Company Profile:
Founded in 1999 and headquartered in Reston, Virginia, Concept Solutions, LLC (CS) is a leading small business in technology, engineering, and management consulting. We are the innovative and agile force behind strategic solutions that enhance organizational efficiency and safeguard our nation across Aerospace, Defense, and National Security sectors.
For over 25 years, CS has been a trusted partner for the Federal Aviation Administration (FAA), Department of Homeland Security (DHS), Department of Justice (DOJ), Department of Defense (DoD) and other federal agencies delivering vital IT, security, and project management services.
Our commitment to excellence is reflected in our adherence to CMMI-DEV ML3, ISO 9001:2015, ISO/IEC 20000-1:2018, and ISO/IEC 27001-1:2013 standards. CS boasts company highlights that include:
- Over two decades of experience across over $300 million in contract awards supporting critical FAA programs
- Multiple contract vehicles providing opportunities across FAA, DoD, NOAA, and other Federal agencies
- Innovation Council - CS maintains an active Internal Research and Development (IR&D) program that is geared towards identifying emerging technologies and pursuing technological innovations
At CS, we know our success stems from our talented team. That’s why we prioritize the wellbeing and growth of our employees, fostering a positive culture centered on innovation, engagement, and career development.
Benefits: Concept Solutions offers a competitive benefits and salary package you would receive from a large company. We offer health, dental, vision and life insurance, as well as a comprehensive 401(k) plan with matching and immediate vesting.
Concept Solutions is an Equal Opportunity Employer, and we value workplace diversity. We invite resumes from all interested parties and consider applicants for all positions without regard to race, color, religion, sex, national origin, age, marital status, sexual preference, personal appearance, family responsibility, the presence of a non-job-related medical condition or physical disability, matriculation, political affiliation, veteran status, or any other legally protected status. Concept Solutions is a VEVRAA federal contractor, and we request priority referral of veterans for available positions.