Cloud Network Security Engineer (Top Secret clearance)
Washington, DC
Full Time
Experienced
The Opportunity
We are seeking an experienced Cloud Network Security Engineer to own network connectivity between a federal government customer’s on-premises infrastructure and its cloud environments, currently spanning Microsoft Azure and AWS. This is a fully onsite role in Washington, D.C. or Bethesda, MD.
This is a senior, hands-on engineering role responsible for the configuration, troubleshooting, security, and lifecycle management of hybrid and multi-cloud network infrastructure. The engineer will serve as a primary technical bridge between the customer's on-premises network organization and cloud/platform teams.
The ideal candidate combines deep traditional networking expertise with hands-on cloud networking and security experience and understands how network architecture, routing, security controls, and capacity constraints affect application and platform design.
What You'll Do
As a Cloud Network Security Engineer, you will:
Required Qualifications
Preferred Qualifications
Compensation
The estimated salary range for this position is $175,000 – $200,000 annually, based on market benchmarks within the Washington, D.C. metropolitan area. This range represents a good faith estimate and may vary depending on several factors, including the scope of the role, geographic location, education, certifications, technical skills, and overall relevant experience.
We are seeking an experienced Cloud Network Security Engineer to own network connectivity between a federal government customer’s on-premises infrastructure and its cloud environments, currently spanning Microsoft Azure and AWS. This is a fully onsite role in Washington, D.C. or Bethesda, MD.
This is a senior, hands-on engineering role responsible for the configuration, troubleshooting, security, and lifecycle management of hybrid and multi-cloud network infrastructure. The engineer will serve as a primary technical bridge between the customer's on-premises network organization and cloud/platform teams.
The ideal candidate combines deep traditional networking expertise with hands-on cloud networking and security experience and understands how network architecture, routing, security controls, and capacity constraints affect application and platform design.
What You'll Do
As a Cloud Network Security Engineer, you will:
- Configure and maintain hybrid and multi-cloud networking components, including virtual networks, gateways, site-to-site VPNs, and dedicated circuit connectivity across Azure and AWS.
- Manage technologies including Azure VNets, ExpressRoute, Virtual WAN, AWS VPCs, Transit Gateways, DNS, IPAM, load balancing, and private connectivity to platform services.
- Configure and manage firewall and network security policies across cloud and enterprise platforms, including NSGs, Azure Firewall, Palo Alto, and Cisco.
- Perform firewall policy configuration, log analysis, and troubleshooting of complex connectivity and security issues.
- Design and optimize routing and traffic engineering using BGP, route tables, and user-defined routes, accounting for application traffic patterns, bandwidth constraints, and mission requirements.
- Manage DNS configurations, including Azure DNS and Private DNS Zones, and IP address management across Azure environments.
- Deploy and maintain Private Link and Private Endpoint configurations to secure connectivity to PaaS services.
- Monitor network health, performance, availability, and security across on-premises and cloud environments.
- Develop and maintain Infrastructure-as-Code (IaC) to enable repeatable, auditable network configuration and deployment.
- Maintain network diagrams, technical documentation, and standard operating procedures.
- Respond to and resolve network incidents within established SLAs and coordinate with telecommunications carriers and colocation providers when necessary.
- Partner with security, infrastructure, application, and cloud teams to design network solutions for new workloads, migrations, and long-term multi-cloud initiatives.
Required Qualifications
- Active Top Secret clearance with SCI eligibility.
- U.S. citizenship required.
- Bachelor's degree in a related technical field or equivalent professional experience.
- 8+ years of overall network engineering experience.
- 5+ years of hands-on experience configuring, administering, and troubleshooting cloud networking environments.
- Strong understanding of networking fundamentals, including TCP/IP, routing, switching, DNS, DHCP, BGP, and VPN technologies.
- CompTIA Security+ certification.
Preferred Qualifications
- Hands-on experience with both Azure networking (VNets, subnets, NSGs, ExpressRoute, VPN Gateway, Azure Firewall) and AWS networking (VPCs, Transit Gateways, Site-to-Site VPN, Security Groups).
- Experience troubleshooting complex hybrid connectivity between on-premises and multi-cloud environments.
- Hands-on experience administering enterprise firewall platforms, particularly Palo Alto and Cisco, including policy configuration and firewall log analysis.
- Experience with Infrastructure-as-Code technologies such as Terraform, Bicep, ARM templates, or CloudFormation.
- Strong understanding of network security principles, including segmentation, least-privilege access, firewall policy management, and secure cloud connectivity.
- Demonstrated ability to independently own and lead network engineering efforts within a complex customer environment.
- Microsoft Certified: Azure Network Engineer Associate, Azure Administrator Associate, and/or AWS Certified Advanced Networking – Specialty.
- Experience with multi-region or multi-cloud architectures utilizing technologies such as Azure Virtual WAN, Azure Front Door, AWS Transit Gateway, or AWS Direct Connect.
- Experience with carrier cloud-connect or colocation solutions such as AT&T NetBond, Verizon Software-Defined Interconnect, Equinix, or Digital Realty.
- Scripting and automation experience using PowerShell, Python, Azure CLI, or AWS CLI.
- Familiarity with Trusted Internet Connection (TIC) 3.0 and Policy Enforcement Point (PEP) concepts.
- Experience supporting federal government, regulated, or compliance-driven environments, including FedRAMP and NIST 800-53.
Compensation
The estimated salary range for this position is $175,000 – $200,000 annually, based on market benchmarks within the Washington, D.C. metropolitan area. This range represents a good faith estimate and may vary depending on several factors, including the scope of the role, geographic location, education, certifications, technical skills, and overall relevant experience.
Apply for this position
Required*