Network Engineer - CBO
Listed on 2026-09-16
-
IT/Tech
Cybersecurity, Network Security
Location Washington, DC — hybrid; on-site as required by task assignment
Employment Type Full-time — contingent upon contract award
Salary Range $92,000 – $110,000
Clearance / Suitability Public Trust (Tier
2); U.S. citizenship or permanent residence required
The Network Engineer provides secure engineering and operational support for a U.S. legislative branch agency's Cisco-based enterprise network. The role designs, implements, and sustains secure network architectures that enforce Zero Trust principles — segmentation, micro-segmentation, and least-privilege access — while hardening and continuously monitoring switches, routers, and perimeter systems in accordance with federal cybersecurity standards (NIST SP 800-53 and NIST SP 800-207) and Cisco best practices.
Key Responsibilities- Operate, optimize, and troubleshoot the Cisco core, distribution, access, and edge network infrastructure to ensure reliability, performance, and availability.
- Configure and manage routing, switching, VLANs, DNS, DHCP, and VPN services with secure, standards-aligned configurations.
- Implement and maintain network security controls aligned with NIST SP 800-53 (AC, CM, SC, AU control families).
- Enforce Zero Trust architecture per NIST SP 800-207, including network segmentation, micro-segmentation, and continuous verification of users and devices.
- Deploy and manage 802.1X port-based network access control (NAC) and least-privilege, identity-aware access across all network layers.
- Harden network devices to secure configuration baselines (e.g., Cisco Secure Configuration Guides); secure perimeter and public-facing assets through ingress/egress filtering, firewall rule optimization, and MFA for administrative access.
- Configure centralized logging and forward logs to the enterprise SIEM; support continuous, real-time (24/7) monitoring and alerting.
- Conduct continuous monitoring and vulnerability assessments aligned with the NIST Risk Management Framework (RMF); coordinate patching, firmware updates, and remediation.
- Support incident response with network-level analysis, containment actions, and forensic data collection.
- Perform root cause analysis (RCA) for network incidents; develop and maintain network diagrams, configuration baselines, and Standard Operating Procedures (SOPs).
- Serve as technical adviser on complex service-desk tickets, collaborating with cloud, Microsoft engineering, and cybersecurity teams.
- Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field (equivalent experience considered).
- Minimum 8 years of hands-on enterprise network engineering experience in Cisco environments.
- Demonstrated expertise in routing and switching, VLANs, DNS/DHCP, VPNs, and 802.1X network access control.
- Working knowledge of NIST SP 800-53 controls and NIST SP 800-207 Zero Trust Architecture.
- Active Cisco certification (CCNP or CCNA) or equivalent demonstrable expertise.
- S. citizenship or permanent residence status; ability to obtain a Public Trust (Tier
2) determination.
- CCNP Enterprise or CCNP Security;
CompTIA Security+ (DoD 8140/8570 IAT Level II). - Experience with Cisco ISE, Trust Sec/MACsec, and Catalyst 9300 Stack Wise environments.
- Experience with next-generation firewalls (Check Point or Palo Alto) and secure web gateways (e.g., iBoss).
- Familiarity with SIEM (Microsoft Sentinel or Splunk) and network monitoring tools (Solar Winds, Thousand Eyes).
- Prior experience supporting federal or Congressional / legislative branch environments.
U.S. citizenship or permanent residence status is required. The selected candidate must be able to obtain and maintain a Public Trust (Tier
2) suitability determination…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).