^E01 Network Engineer IV
talentwerx.io · Remote
About The Role
Start Date: Immediate
JHNA, CTSi, and EXPANSIA have come together to form a Defense Technology platform named Aether Aerospace focused on delivering high-impact technologies, technology-enabled services and advanced manufacturing solutions to the U.S. Department of Defense and related national security customers. Backed by Falfurrias Management Partners, the platform brings together deep domain expertise across Army, Navy, and Air Force and Space Force programs, digital engineering, systems integration, and specialized manufacturing capabilities.
The combined organization operates as a multi-entity aerospace and defense technology and tech-enabled services and manufacturing enterprise positioned for scalable growth, operational excellence, and long-term value creation.
OVERVIEW
Full-time/Permanent Employee
Location: Remote
As a Network Engineer IV supporting a Digital Engineering Ecosystem (DEE), you will design, implement, secure, document, and sustain the hybrid network architecture connecting Azure Government-hosted services, approved on-premises resources, remote users, engineering applications, data repositories, and shared enterprise services. You will develop network architectures, traffic-flow diagrams, routing designs, private-connectivity solutions, segmentation policies, security-group and firewall rules, private DNS configurations, monitoring capabilities, and implementation specifications supporting the controlled unclassified information environment and planned future expansion.
You will lead the engineering of resilient Azure virtual networks, hybrid connectivity, boundary protection, private service-access patterns, and network automation while coordinating with cloud architects, cybersecurity engineers, DevSecOps teams, system administrators, application owners, and Risk Management Framework personnel. The role requires the ability to connect network design, engineering-data performance, cybersecurity requirements, configuration management, verification evidence, and operational sustainment across cloud and on-premises boundaries.
RESPONSIBILITIES
Hybrid Azure Architecture and Connectivity
Design, implement, and maintain the hybrid Azure Government network architecture connecting cloud-hosted DEE services with authorized on-premises systems, enterprise services, remote users, and approved external mission partners.
Engineer resilient private connectivity using approved technologies such as Azure ExpressRoute, site-to-site VPN, redundant gateways, and approved network virtual appliances.
Configure and troubleshoot Border Gateway Protocol routing, route propagation, user-defined routes, gateway transit, route filtering, failover, and asymmetric-routing conditions.
Develop and maintain IP address-management, subnetting, route-table, resiliency, and capacity plans that prevent address conflicts and support future environment growth.
Azure Network Architecture and Segmentation
Design and administer Azure virtual networks, subnets, peering, route tables, NAT, load-balancing services, gateways, and approved hub-and-spoke or Virtual WAN patterns.
Design and implement secure network segmentation and communication between DEE functional environments using Azure networking services and approved security controls.
Design and maintain the networks for the Cloud Upload & Staging service that serves as the controlled network boundary between external content sources and the private DEE environment, supporting secure content ingestion and transfer.
Develop and maintain network architecture diagrams, authorization-boundary diagrams, trust-zone diagrams, data-flow diagrams, ports/protocols/services matrices, and interface-control information.
Enforce least-privilege north-south and east-west communication and maintain separate management, data, shared-service, staging, and future classified network boundaries.
Security Groups, Firewall Policies, and Rule Governance
Design, implement, and maintain Azure Network Security Groups (NSGs) for approved subnets and network interfaces, ensuring inbound and outbound traffic is limited to authorized sources, destinations, protocols, and ports.
Develop and maintain Application Security Groups (ASGs) that logically group workloads by function, security role, application tier, or service type and reduce dependence on individually maintained IP-address rules.
Design and administer Azure Firewall Policy rule collection groups, including DNAT, network, and application rule collections, using approved service tags, IP Groups, fully qualified domain names, and threat-intelligence settings where appropriate.
Implement centrally governed security-admin rules when mandatory enterprise rules must be enforced consistently across selected subscriptions, virtual networks, or network groups.
Maintain a network-rule register containing the rule identifier, control point, source, destination, direction, protocol, port, action, priority, DEE environment, business justification, security-requirement reference, owner, approval authority, review or expiration date, and test evidence.
Apply least-privilege and default-deny principles and prohibit unrestricted any-to-any rules unless supported by an approved, documented, time-bounded exception.
Analyze the combined effect of security-admin rules, subnet and network-interface NSGs, Azure Firewall policies, routing tables, NAT rules, private endpoints, and hybrid connectivity controls.
Review rules periodically and after architecture, application, interface, or mission changes to identify obsolete, duplicative, shadowed, unused, or overly permissive rules.
Private Access, DNS, and Remote Connectivity
Implement Private Endpoint and Private Link as the preferred access pattern for supported Azure platform services and document approved exceptions to public network exposure.
Design and maintain Azure Private DNS zones, Azure DNS Private Resolver, DNS forwarding, conditional forwarding, and integration with approved on-premises DNS services.
Validate routing, firewall policy, name resolution, and service reachability from Azure, on-premises, remote-access, and shared-service locations.
Integrate approved remote-access capabilities with identity, multifactor authentication, conditional access, device posture, logging, and least-privilege network access requirements.
Monitoring, Troubleshooting, and Performance
Configure and maintain applicable SIEM integrations and alerts for ExpressRoute and VPN health, route changes, firewall events, denied traffic, packet loss, latency, DNS failures, private-endpoint availability, and abnormal traffic patterns.
Perform packet capture, next-hop analysis, connection troubleshooting, effective-security-rule analysis, route validation, and end-to-end network performance testing.
Analyze bandwidth, throughput, latency, packet loss, storage-access patterns, and transfer performance for digital engineering models, technical data packages, simulation outputs, configuration baselines, and other large engineering datasets.
Automation and Configuration Management
Develop and maintain network infrastructure as code using approved tools such as Bicep, Terraform, Azure Resource Manager templates, PowerShell, Azure CLI, or program-approved automation frameworks.
<li
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring