Principal Network Architect/Subject Matter Expert; SME
Silver Spring, Montgomery County, Maryland, 20900, USA
Listed on 2026-09-25
-
IT/Tech
Systems Engineer, Cloud Computing: Infrastructure & Operations, Cybersecurity
Valiant Solutions is seeking a Principal Network Architect / Subject Matter Expert (SME) to serve as the senior technical authority for a nationwide enterprise network operations consolidation supporting our government customer. Today the customer's network is managed in silos by separate vendors and internal teams across cloud, WAN, LAN, and security, which slows incident resolution and stalls modernization. This role owns the end-to-end design that replaces that model: a single operating picture spanning campus LAN, a carrier MPLS WAN reaching roughly 50 sites, two enterprise data centers, and two public cloud platforms.
The architect sets technical direction for the agency's Zero Trust and IPv6 programs, grounded in NIST SP 800-207, TIC 3.0 reference architectures, and the federal IPv6 mandate in OMB M-21-07. This is a hands-on senior engineering role rather than a management position, and it serves as the final escalation point for Tier 3 architectural root cause analysis.
Named one of the Best Places to Work in the Washington DC area for 12 consecutive years
, Valiant is proud of our employee-centric culture and commitment to excellence.
This position is based in Silver Spring, MD, and allows for partial remote work (3 days onsite and 2 days remote). Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.
Transition, Consolidation, and Assessment- Lead the assessment and validation of the device inventory across Cisco Catalyst and Nexus switches, Cisco Firepower Threat Defense firewalls, Cisco ISE appliances, and Ubiquiti Uni Fi and Meraki switches.
- Direct the initial enterprise network assessment covering design, security, redundancy, and performance posture, and identify the gaps that block the target Zero Trust architecture.
- Drive knowledge transfer from incumbent staff and government engineers, capturing undocumented operational procedures and reconciling them against existing network standard operating procedures.
- Define the ITIL v4 aligned service management model that replaces tool-by-tool operation, and set the architecture for a consolidated monitoring dashboard aggregating MPLS WAN, data center fabric, and cloud telemetry.
- Assess the existing Service Now ITSM workflow used for network service requests and deliver written recommendations through the customer's review process.
- Conduct the network design review within the first 90 days of performance and annually thereafter, identifying single points of failure in internet, DMZ, and cloud egress paths.
- Verify that the hot-hot aggregation design across the Seattle and Ashburn data centers survives the loss of any single circuit or backbone device without dropping internet or cloud connectivity.
- Plan and evaluate failover testing with the security team to confirm that backup paths activate automatically.
- Serve as the Tier 3 escalation authority for architectural root cause analysis, complex code upgrades, and disaster recovery execution.
- Review and approve Methods of Procedure before Change Control Board submission, including rollback plans and risk assessments, to protect the change success rate standard.
- Own BGP traffic engineering across the carrier MPLS backbone, transport circuits, and cloud interconnects to prevent suboptimal routing between on-premise and cloud workloads.
- Confirm that all cloud connectivity conforms to TIC 3.0 reference architectures so that cloud traffic is inspected and logged as required.
- Set Quality of Service policy on customer edge routers so that mission data and VoIP traffic receive priority across the wide area network.
- Act as the senior technical escalation point in carrier disputes, directing intrusive testing windows and vendor management escalation during circuit outages.
- Own the enterprise IPv6 transition plan and drive the enterprise from a roughly 5 percent dual-stacked endpoint baseline toward the 80 percent target, including cloud environments that are currently IPv4-only.
- Manage the interim dual-stack environment, keeping OSPFv3 and MP-BGP routing tables synchronized and stable.
- Maintain the enterprise IPv6 addressing plan and prefix allocation across sites, data centers, and cloud tenancies.
- Design NAT
64 and DNS
64 translation services if legacy IPv4-only applications are identified during migration. - Identify End-of-Life and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).