CSfC Network Engineer Subject Matter Expert (SME)
Fort Belvoir, VA - USA
Job Summary
Leidos is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation growth and efficiencies within the I3TS portfolio.
Clearance: Must have an active TS/SCI clearance at time of consideration. U.S. Citizen is a must.
Primary Responsibilities:
TheCommercial Solutions for Classified (CSfC) Network & Security Engineerwill architect and operate secure dual-layer cryptographic boundaries utilizingCisco and Aruba IPsec/SSL VPNsand dynamic routing (BGP/OSPF) in strict compliance with NSA Capability this role you will author and tunePalo Alto NGFW security policies and IDS/IPS threat prevention signatures implement enterprise network access control and 802.1X policies viaCisco ISE and Aruba ClearPass integrate enterprisePKI/OCSP services and hardened NTP and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing.
Architect deploy and maintain CSfC infrastructure operating within Black/Gray/Red networks.
Design configure and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA) Multi-Sight (MSC) Capability Packages with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
Understanding of NIAP approved list and monitors for changes
Design configure and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC MA and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates.
Implement enterprise routing protocols (BGP OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation.
Author optimize and audit Palo Alto Next-Generation Firewall (NGFW) security policies App-ID User-ID and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures anti-spyware and vulnerability protection.
Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control RADIUS/TACACS administration posture assessment and endpoint profiling.
Integrate enterprise Public Key Infrastructure (PKI) components managing X.509 certificate lifecycles Certificate Authorities (CAs) CRL/OCSP validation and hardened authenticated Network Time Protocol (NTP) infrastructure.
Prepare CSfC compliance artifacts Key Management Plans (KMPs) Continuous Monitoring Plans (CMPs) and registration packages for NSA CSfC PMO submission.
Basic Qualifications:
Bachelors degree or higher in Computer Science Information Technology Engineering Engineering Management Management Information Systems or related STEM degree program and 12-15 years of relevant experience. Specific experience education and training may be considered in lieu of degree.
12 years of progressive network engineering experience within DoD/DoW federal or defense contractor enterprise environments
Active TS/SCI Clearance
Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g. Security CE CySA CASP or CISSP).
Active Computing Environment certification including one or more of: Cisco CCNA CCNP Aruba ACSA or ACSP
Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs including IKEv2 Suite B/CNSA cryptography and dynamic routing (BGP OSPF).
Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS) Panorama central management and advanced IDS/IPS inspection profiles.
Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X EAP-TLS authentication and role-based access policies.
Strong working knowledge of X.509 certificates CA hierarchy integration certificate revocation lists (CRLs) OCSP and secure NTP stratum synchronization.
Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access Multi-Site Connectivity or Campus WLAN).
Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements post-quantum readiness considerations and hardware security modules (HSMs).
Familiarity with Ansible for automating network device configuration backups policy compliance checks and certificate rotations.
Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise) Palo Alto PCNSE Aruba Certified ClearPass Expert (ACCX) or Aruba Certified Mobility Expert (ACMX).
If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
IC
About Company
Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.