Network Engineer - Mid Level - DoD Clearance Required
Listed on 2026-08-31
-
IT/Tech
Systems Engineer, Cybersecurity, Network Engineer
About the Mission
The Persistent Cyber Training Environment (PCTE) supports United States Cyber Command (USCYBERCOM) by meeting a critical need for the DoD and Joint Cyberspace Operations Forces to train at the individual, team, and force level. PCTE is an online platform that gives Cybercom’s cyber mission force access from anywhere in the world for individual training, collective training, and mission rehearsal. It is one of the five elements of the Joint Cyber Warfighting Architecture (JCWA) and is managed on behalf of Cybercom and the joint cyber force by the Army’s Program Executive Office for Simulation, Training and Instrumentation.
The program has matured well past initial fielding. The infrastructure team now sustains a fleet of enterprise environments in parallel — development, test, and multiple production systems — while simultaneously standing up new environments, executing platform-wide version upgrades, replacing hardware in place, and integrating a growing catalog of mission applications. This role sits at the center of that work.
Position SummaryThe Mid Level Network Engineer owns the network layer — physical and virtual — across the PCTE enterprise fleet. This is not a ticket-queue or single-domain networking job. The successful candidate designs and implements routing, switching, load balancing, and micro-segmentation across a hyperconverged VMware Cloud Foundation environment; hardens that infrastructure to DISA STIG and RMF standards; racks and cables the gear personally;
plans and executes hardware migrations and maintenance windows against real delivery dates; integrates mission applications end-to-end across system boundaries; and serves as the technical authority other teams come to when connectivity, segmentation, or system integration is the blocker.
- Design, configure, and troubleshoot Layer 2 and Layer 3 infrastructure across Cisco Nexus (NX-OS) and Catalyst platforms in spine/leaf data center fabrics — VLANs, port-channels, vPC, trunking, BGP peering and advertisement, prefix-lists, route-maps, VRFs, and access-lists.
- Build and maintain F5 BIG-IP configurations including virtual servers, pools, nodes, health monitors, HTTP/SSL profiles, certificate management, firewall rules, and WAF policies supporting externally reachable mission services.
- Design and implement VMware NSX networking and security — Tier-0/Tier-1 gateways, overlay and VLAN segments, distributed firewall (DFW) rules, context profiles, and route advertisement — and reconcile NSX policy with physical switch ACLs and F5 rules so traffic actually flows end to end.
- Own the full connectivity path for new services: trace and resolve issues across NSX, F5, physical switching, DNS, and endpoint configuration rather than handing off at a domain boundary.
- Execute OS upgrades and baseline patching across the fleet for Nexus switches, Catalyst switches, F5 BIG-IP, and Cisco ISE, coordinated within approved change windows.
- Rack, cable, and bring up new compute, storage, and network racks — including iDRAC/BMC configuration, ESXi installation, and integration of new hardware into existing VCF workload domains.
- Plan and execute physical infrastructure changes: hardware refresh and vendor migrations, rack deliveries, data center relocations (system shutdown, physical move, reinstallation, recabling, power-up, and functional validation), and post-power-event health checks.
- Coordinate the non-technical half of these efforts — data center access requests, shipping and logistics scheduling, change approval, and maintenance window negotiation with government stakeholders.
- Design and rehearse migrations in a lab or non-fielded system before touching production, with the objective of zero or near-zero service interruption, and brief the plan and findings to project leads before execution.
- Support VMware Cloud Foundation (VCF) lifecycle work — major-version upgrades, SDDC Manager operations, workload domain creation, and post-deployment network configuration — across development, test, and production…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).