Network Engineer- CBP
Listed on 2026-09-27
-
IT/Tech
Network Engineer, Systems Engineer, Cybersecurity, Network Security
Description
Work Location: Ashburn, VA (onsite)
Travel Requirement
:
Up to 25%
Citizenship: US Citizenship required
Security Clearance
:
Must possess existing DHS EOD or DHS Suitability
The Network Engineer supports the U.S. Customs and Border Protection (CBP) Operational Technology Operations Center (OTOC) and the design, implementation, testing, deployment, operation, and sustainment of network infrastructure supporting the Office of Information and Technology (OIT) ISS OTOC. This is a full-time onsite position focused on network engineering, secure connectivity, Watchtower Mobile Device Management (MDM), laboratory validation, and field support for operational technology during an assigned 8-hour day shift.
The Network Engineer designs, configures, implements, validates, troubleshoots, documents, and sustains secure network infrastructure supporting OT and tactical systems across laboratory, enterprise, edge, cloud, and field environments. The position engineers solutions using routers, switches, firewalls, VPNs, wireless networks, network services, cloud connectivity, identity and certificate services, and endpoint technologies to provide reliable, resilient, and secure end-to-end communications.
The position provides hands-on network engineering support for Watchtower and associated Android, Windows, Linux, iOS, radio, sensor, wearable, and tactical endpoints; develops representative lab environments; performs network validation and acceptance testing; supports deployment readiness and technology fielding; and resolves complex network, performance, and interoperability issues. The Network Engineer coordinates with systems integrators, cybersecurity, engineering, OTOC operations, program leadership, vendors, and government stakeholders to implement and sustain approved network solutions in operational environments.
ResponsibilitiesNetwork Engineering and Architecture
- Design, configure, implement, test, troubleshoot, optimize, and document network solutions supporting OTOC, Watchtower, operational technology, and tactical systems.
- Configure and support routers, switches, firewalls, VPN gateways, wireless infrastructure, and associated network services in lab and operational environments.
- Support IPv4/IPv6 addressing, subnetting, VLANs, routing, switching, NAT, DNS, DHCP, VPNs, access control, and secure network segmentation.
- Engineer network connectivity across on-premise, cloud, edge, mobile, and disconnected or limited-connectivity environments.
- Analyze network paths and dependencies to identify connectivity, latency, packet loss, routing, name-resolution, firewall, VPN, or configuration issues.
- Use packet captures, logs, monitoring platforms, command-line tools, and other network diagnostic methods to isolate and resolve complex problems.
- Develop and maintain network diagrams, IP address plans, interface definitions, configuration baselines, port/protocol matrices, build records, and implementation documentation.
- Maintain network configuration management, backups, version control, standards, configuration baselines, and repeatable deployment practices.
- Engineer and review network changes for technical dependencies, capacity and performance impacts, security considerations, validation requirements, implementation sequencing, and rollback needs.
- Provide network engineering and connectivity support for the Watchtower MDM platform and supported OT and tactical devices.
- Validate network requirements for Android, Windows, Linux, iOS, radios, sensors, wearables, and other supported endpoints.
- Support device enrollment, provisioning, policy delivery, certificate distribution, remote management, compliance reporting, and over-the-air updates by ensuring required network paths and services are available.
- Validate Watchtower communications across enterprise, wireless, VPN, cloud, edge, offline, and disconnected-use scenarios.
- Troubleshoot connectivity between Watchtower services, managed endpoints, identity services, certificate infrastructure, cloud resources, and other integrated systems.
- Support secure communications architectures and certificate-based connectivity using PKI, X.509 certificates, Certificate Authorities, and client/server certificate lifecycle processes.
- Build, configure, and maintain representative network lab environments used to evaluate new technologies, network configurations, devices, software releases, and integration changes…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).