Senior Network Architect IRES - SSFB/HSV
Amentum · US CO Colorado Springs + 1 more · Posted 2026-08-31
Job description
Position Title: Senior Network Architect Location: Schriever Space Force Base, Colorado Springs, CO or Redstone Arsenal, Huntsville, ALRelocation Assistance: None available at this timeRemote/Telework: NO - Not available for this positionClearance Type: DoW SecretShift: Day shiftTravel Required: Up to 10% of the timeDescription of Duties: The Senior Network Architect supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. Senior Network Architects are responsible for enterprise network architecture, modernization, and security across DoW mission environments (IL4/5/6). This role sets standards and roadmaps; leads end to end design for data center, campus/branch, WAN/SD WAN, and cloud connectivity; and drives Zero Trust–aligned segmentation and automation to deliver resilient, scalable, and compliant networks. Key Responsibilities: Strategy & Architecture Governance: • Participate in Architecture Review Boards (ARB) and Change/Configuration Control Boards, maintaining traceability with HLD/LLD, ADRs, ICDs, and security overlays. • Evaluate emerging capabilities (e.g., EVPN VXLAN fabrics, SD WAN/SASE, advanced telemetry) with adoption criteria, risk posture, and migration approaches • Develop and maintain network architecture roadmaps, standards, and best practices aligned with DoW and Agency requirements. Core Network Architecture & Design: • Design underlay/overlay topologies for data centers and campuses (spine leaf, EVPN VXLAN, MPLS L2/L3VPN) and for WAN/backbone (BGP/OSPF/IS IS, traffic engineering, route policy, communities). • Engineer HA and fast convergence (ECMP, FHRP, FRR, ISSU/GSU) and plan for capacity, growth, and performance (QoS, queuing, shaping, policing). • Define IPv4/IPv6 addressing strategy, NAT policies, multicast/RP design where required, and DNS/DHCP/IPAM governance. Security Architecture & Zero Trust: • Architect segmentation and micro segmentation (identity /policy based), secure access (802.1X, certificate based auth), and crypto/crypto boundary designs (IPsec, MACsec) using FIPS validated algorithms. • Align to DoW RMF, NIST SP 800 53/37, and DISA STIGs; map control inheritance and produce artifacts needed for ATO/cATO. • Integrate network security controls (firewall policy frameworks, IDS/IPS, SWG, DLP) and validate with tabletop/blue team exercises. Cloud, Edge & Cross Domain Connectivity: • Design hybrid and multi cloud connectivity (IL cloud constructs, private connectivity, transit/segmentation, inspection service insertion, east west control). • Engineer remote access/telework, edge footprints, and mission partner/coalition interconnects with explicit security demarcation and monitoring. • Campus & Branch • Define campus access, distribution, and core designs with 802.1X, posture assessment, guest/IoT segmentation. • Establish branch patterns (SD WAN, DIA/MPLS mix, local breakout controls) with consistent policy and centralized governance. Automation, Reliability & Observability: • Drive intent based and policy driven operations: configuration standards, golden baselines, compliance drift detection, and repeatable change. • Establish observability requirements (model driven/streaming telemetry, logs/metrics/flows) and SLOs; ensure runbooks and test plans cover failure scenarios. • Documentation & Deliverables Produce and maintain: • Enterprise Network Standards, High/Low Level Designs (HLD/LLD), Architecture Decision Records (ADRs), Interface Control Documents (ICDs), test/validation plans, cutover plans, security overlays, addressing/IP plans, and runbooks. The successful candidate will: • Have excellent communication skills • Be able to brief senior leaders and translate technical concepts into mission impact. Resumes, in month and year format, must be submitted with application in order to be considered for the position. The selected candidate may be assigned as an employee for one of our teammate companies. Basic Requirements: • Must have 10 , or more, years of general (full-time) work experience • May be reduced with completion of advanced education • Must have 5 , or more, years of direct experience designing and leading large-scale enterprise or DoW networks across data center, WAN/backbone, campus/branch domains. • Must have 1 , or more, years of experience working in a management or leadership role • Must have expert level knowledge of routing and switching (BGP, OSPF, IS IS), EVPN VXLAN and/or MPLS, QoS, IPv6, multicast, and network resiliency patterns. • Must have demonstrated success implementing Zero Trust segmentation, 802.1X/NAC, identity aware firewall policy, and FIPS validated cryptography. • Must be familiar with hybrid/multi cloud networking patterns and IL4/5/6 operational constraints; strong grasp of RMF/STIG compliance. • IAT III or IAM II baseline (examples: CISSP, CASP+ CE, CISM). • Must have an active DoW Secret Security Clearance Desired Requirements: • Have an active DoW Top Secret Security Clearance w/ SCI eligibility • Have a Bachelor’s degree, or higher, in computer science, Information Technology • Have experience with ITIL, TOGAF, or other architecture frameworks. • Have experience supporting the Missile Defense Agency (MDA) or other DoW organizations. • Have experience with software-defined networking (SDN), automation, and cross-domain solutions. • Have 1, or more, of the following certifications: • CCIE (Enterprise Infrastructure, Security, or Data Center) • CCNP (Enterprise, Service Provider, or Security) or equivalent expert credentials (JNCIE, NSE 7/8, PCNSE). • ITIL® 4 Foundation (service alignment) and an architecture framework credential (TOGAF/DoDAF familiarity). • Cloud networking foundations (e.g., AWS/Azure associate level) helpful for hybrid designs. This position will be posted for a minimum of 3 days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is