Senior Network Engineer / FISMA Compliance Support

TJ Consulting Group

Washington (District of Columbia)

On-site

USD 120,000 - 180,000

Full time

44 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

PTO
Holiday Pay
401K with 4% Match
Medical Insurance
Dental Insurance
Vision Insurance
Life & AD&D
EAP

Job summary

TJ Consulting Group seeks a Senior Network Engineer to lead PCLOB's enterprise network operations and security engineering. You will own network availability, performance, and security while aligning with FISMA/RMF controls. Hands-on Cisco expertise and VOIP experience are required.

The role emphasizes NIST 800-53, POA&Ms, and Xacta 360 for continuous compliance, with collaboration across government-facing teams in a DC-based environment.

Qualifications

  • Bachelor's degree in information technology or related field.
  • 7+ years hands-on enterprise network/security administration and engineering.
  • 3+ years federal FISMA/RMF security-control validation with NIST SP 800-53 and Xacta.
  • Active TS/SCI security clearance.
  • CCNA/CCNP certification; CCNP preferred.
  • Experience administering Cisco CUCM/Call Manager and enterprise VoIP technologies.
  • Hands-on experience with Cisco routing, switching, firewalls, VPNs, IDS/IPS, and network security.

Responsibilities

  • Own PCLOB enterprise network operations and maintenance, ensuring availability, performance, security, and reliability.
  • Design, configure, operate, and troubleshoot Cisco routing/switching and CUCM/VoIP.
  • Resolve complex incidents, perform root-cause analysis, and implement corrective actions.
  • Plan and maintain network security technologies: firewalls, VPNs, IDS/IPS, monitoring, and policy enforcement.
  • Support FISMA/RMF compliance: evidence, SSPs, POA&M, and Xacta 360.
  • Coordinate with PCLOB OCIO and stakeholders on security-engineering deployments and audits.

Skills

CCNA/CCNP
CUCM/Call Manager
Firewall/VPN/IDS-IPS
Windows Server
Linux
Network troubleshooting
NIST RMF

Education

Bachelor's degree in information technology or related field

Tools

Xacta 360

Job description

Job Overview

Seeking a Senior Network Engineer / FISMA Compliance Support professional to support the Privacy and Civil Liberties Oversight Board (PCLOB). The primary focus of this position is hands‑on ownership of PCLOB's enterprise network environment and the network/security engineering responsibilities. The engineer will independently operate, maintain, secure, troubleshoot, and improve Cisco network and unified communications services. As a secondary responsibility, the position will support the FISMA readiness and continuous compliance activities, including NIST SP 800‑53 control documentation, POA&M management, technical evidence, remediation, and Xacta 360 administration. The ideal candidate is first and foremost a senior network engineer who also understands federal FISMA/RMF compliance and can translate network configurations and remediation actions into auditable security‑control evidence.

Job Type

Full-time

Location

Washington, DC

Support Hours

Applicant shall be available during core work hours as established the Government customer.

Essential Duties & Responsibilities
Enterprise Network Operations and Cisco Engineering – Primary Responsibility
  • Serve as the primary technical owner for PCLOB enterprise network operations and maintenance, ensuring the continuous availability, performance, security, and reliability of production network services.
  • Design, configure, administer, operate, maintain, and troubleshoot Cisco routing and switching infrastructure, including VLANs, subnetting, ACLs, TCP/IP, DNS, DHCP, routing protocols, IP addressing, and related network services.
  • Independently resolve complex production incidents involving routing, switching, firewalls, VPNs, connectivity, name resolution, and IP services; perform root‑cause analysis and implement sustainable corrective actions.
  • Plan, implement, operate, and maintain network‑security technologies and services, including firewalls, VPNs, IDS/IPS, network segmentation, secure remote-access, vulnerability remediation, network monitoring, and security policy enforcement.
  • Develop and execute network technology project plans, including Cisco Unified Communications Manager (CUCM)/Call Manager and enterprise VoIP capabilities, SIP, QoS, voice VLANs, voice gateways, and wireless/network modernization activities.
  • Maintain highly available network services and support integrations with Windows Server, Hyper‑V, Linux, server virtualization, Active Directory/identity and access services, Citrix, and related enterprise infrastructure. Maintain accurate physical/logical network diagrams, device inventories, configurations, change records, operating procedures, and troubleshooting documentation.
Security Architecture and Engineering – Primary/Shared Responsibility
  • Assess network and security architecture, identify gaps in the security stack, and develop practical roadmaps and implementation plans that improve capability, tune existing tools, reduce unnecessary overlap, and maintain reliable operations.
  • Review IT security policies with PCLOB OCIO and provide technical solutions for enforcement through network/security architecture, configuration, access controls, monitoring, and engineering changes.
  • Collaborate with PCLOB OCIO, system, cloud, cybersecurity, and security‑operations personnel on security‑engineering deployments and integrated projects; define milestones, completion dates, resource needs, testing, dependencies, and coordination requirements.
  • Provide weekly project updates when requested, identify concerns that could affect milestones or completion dates, and drive assigned network/security engineering actions to closure.
  • Provide Security Engineering SME reviews, technical analyses, recommendations, and decision‑ready write‑ups on an ad‑hoc basis; support security administrator questions and technical remediation activities.
  • FISMA, NIST, and Xacta 360 Compliance Support – Secondary Responsibility
  • Support Task 3 FISMA readiness and continuous compliance activities by applying the NIST Risk Management Framework (RMF) and NIST SP 800‑53 Rev. 5 requirements to network/security controls, technical configurations, evidence, findings, and remediation.
  • Use and maintain Xacta 360 to support security‑control tracking, control implementation documentation, assessments, evidence repositories, Plans of Action and Milestones (POA&Ms), remediation milestones, technical validation, and ongoing compliance status.
  • Support recurring SSP updates, control inheritance, annual FISMA pre‑assessment preparation, baseline compliance evidence, annual submission data/metrics, corrective‑action planning, and audit/assessment readiness; ensure network‑related artifacts accurately reflect the production environment.
  • Review STIG, vulnerability, configuration, and compliance findings; validate technical impact, implement or coordinate corrective actions, document closure evidence, and support compliance briefings, assessor requests, ATO/accreditation activities, and leadership reporting.
Program Support and Customer Engagement
  • Coordinate directly with PCLOB OCIO leadership, system administrators, cybersecurity personnel, and other stakeholders to clarify network and security requirements, communicate technical risk, and drive assigned actions to closure.
  • Prepare concise network analyses, implementation plans, status updates, risk summaries, and decision‑ready technical recommendations for Government and Nemean leadership.
  • Participate in change‑management reviews, technical exchanges, audit/assessment activities, incident‑response exercises, and recurring status meetings as required.
  • Maintain project milestones, risks, dependencies, action items, completion dates, and documentation for assigned network, security‑engineering, and FISMA‑support activities.
Competencies
  • Excellent verbal and written communication skills.
  • Excellent interpersonal and customer service skills.
  • Excellent organizational skills and attention to detail.
  • Excellent time management skills with a proven ability to meet deadlines.
  • Ability to prioritize tasks and to delegate them when appropriate.
  • Ability to function well in a high‑paced and at times stressful environment.
Requirements
Minimum Requirements/Education
  • Bachelor's degree in information technology or a related technical field, plus strong technical documentation, communication, organization, and customer‑engagement skills.
  • Seven or more years of hands‑on enterprise network/security administration and engineering experience, including network design, installation, operations, maintenance, troubleshooting, security, and performance optimization.
  • Three or more years of federal FISMA/RMF security‑control validation and compliance experience, including NIST SP 800‑53 controls, SSPs, POA&Ms, continuous monitoring, technical control evidence, vulnerability/configuration findings, remediation, annual assessment readiness, and hands‑on Xacta/Xacta 360 experience.
  • Current Cisco Certified Network Associate (CCNA) or Cisco Certified Network Professional (CCNP) certification. CCNP is strongly preferred.
  • Must have experience administering Cisco CUCM/Call Manager and enterprise VoIP technologies, including SIP, QoS, voice VLANs, and voice gateways.
  • Demonstrated ability to independently own enterprise network operations and complex Cisco routing, switching, VLAN, firewall, VPN, DNS/DHCP, IP addressing, network monitoring, and connectivity troubleshooting in a production environment.
  • Hands‑on experience configuring, administering, and maintaining firewalls, VPNs, IDS/IPS, network segmentation, ACLs, secure remote‑access solutions, network security devices, and vulnerability remediation.
  • Hands‑on experience with Windows operating systems, Windows Server/Hyper‑V, and Linux, with the ability to support network dependencies across virtualized and identity/access environments.
Security Requirement
  • An active TS / SCI security clearance.
Preferred Requirements
  • CompTIA Network+ and/or Security+ certification.
  • Advanced hands‑on experience with Xacta 360 supporting authorization packages, control inheritance, assessments, POA&Ms, evidence management, remediation, and ongoing FISMA compliance.
  • Certification in IT audit, internal controls, cybersecurity compliance, or a related field.
  • Hands‑on experience with Cisco ISE/NAC/802.1X, Active Directory/identity services, Citrix, NetScaler, Nutanix, Azure/cloud networking, next‑generation firewalls, or related enterprise network/security technologies.
  • Experience supporting STIG compliance, ATO/accreditation activities, independent assessments, secure federal enterprise environments, and configuration/change‑management processes.
Salary Range

+/- $150,000

Benefits
  • PTO
  • Holiday Pay
  • 401K with a 4% Match
  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Group Life & AD&D
  • Voluntary Life AD&D
  • Short‑term Disability
  • Long‑term Disability
  • Health Savings Account
  • Flexible Spending Account (Health and Dependent)
  • Critical Illness Insurance
  • Accident Insurance
  • Hospital Indemnity Insurance
  • Employee Assistance Program (EAP)

We are committed to fostering an inclusive workplace and provides equal employment opportunities (EEO) to all employees and applicants for employment. We do not employ AI tools in our decision‑making processes. Regardless of race, color, religion, sex (including pregnancy), sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran. ensures that all employment decisions are made in accordance with applicable federal, state, and local laws. Our commitment to non‑discrimination in employment extends to every location in which our company operates.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Engineer / FISMA Compliance Support
Senior Network Engineer / FISMA Compliance Support

Nemean Solutions, LLC • Washington

On-site
USD 120,000 - 170,000
Medical, Dental, and Vision insurance
401k with company match
Paid Time Off
Senior Network Engineer / FISMA Compliance Support - PCLOB
Senior Network Engineer / FISMA Compliance Support - PCLOB

Nemean Solutions, LLC • Washington

On-site
USD 135,000 - 165,000
Medical, Dental, Vision
401(k) with company match
Paid time off
Network Engineer - Information Technology
Network Engineer - Information Technology

Federal Reserve System • Washington

On-site
USD 141,000 - 211,000
Relocation assistance
Senior Infrastructure Engineer- -TS/SCI Security Clearance Required
Senior Infrastructure Engineer- -TS/SCI Security Clearance Required

Power3 Solutions • Columbia (MD)

On-site
USD 150,000 - 165,000
Medical Insurance
Dental & Vision Coverage
401k with company match
+1
Network Engineer, Senior
Network Engineer, Senior

Navstar Inc. • Annapolis (MD)

On-site
USD 190,000 - 240,000
Highly Competitive Health Care Premiums
Flexible Spending Accounts
Generous PTO and Federal Holiday Leave
+4
Network Operations Engineer
Network Operations Engineer

ITC Federal, LLC • Virginia (MN)

Hybrid
USD 120,000 - 180,000
Network Operations Engineer
Network Operations Engineer

ITC Federal, Inc. • Quantico (VA)

On-site
USD 110,000 - 150,000
Senior Network Engineer - Corporate Enterprise Network (WAN)
Senior Network Engineer - Corporate Enterprise Network (WAN)

AGE Solutions • Alexandria (VA)

On-site
USD 90,000 - 110,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
Network Engineer
Network Engineer

FEDITC • Springfield (VA)

On-site
USD 90,000 - 130,000
Senior Network Engineer
Senior Network Engineer

Amentum • Fort Meade (MD)

On-site
USD 225,000 - 275,000
Health, dental, and vision insurance
Paid time off and holidays
Retirement benefits (401(k) matching)
+5