Network Architect

Leidos•Bedford, MA
•$131,300 - $237,350

About The Position

Leidos is seeking a Cloud Network Architect to provide technical leadership for the design, integration, and evolution of secure multi-cloud networking capabilities supporting the U.S. Air Force Cloud One Next (C1N) ACSS contract. In this role, you will serve as a senior technical authority for network architecture across AWS, Microsoft Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI). You will develop common networking patterns while accounting for the unique capabilities and constraints of each Cloud Service Provider (CSP), enabling secure and resilient connectivity across Cloud One environments, Department of the Air Force (DAF) networks, mission systems, and external services. The Cloud Network Architect will work closely with cloud engineering, cybersecurity, platform engineering, operations, and program leadership to translate mission and security requirements into scalable network architectures. The role will establish technical standards, reference architectures, and automation patterns that reduce CSP-specific complexity while maintaining the security, availability, performance, and compliance requirements of DoD environments.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Network Engineering, Systems Engineering, or a related technical discipline and 12–15 years of prior relevant experience, or equivalent additional experience in lieu of degree.
  • Extensive experience designing and operating enterprise-scale network architectures, including routing, switching, firewalls, DNS, load balancing, VPNs, private connectivity, and network segmentation.
  • Demonstrated experience designing cloud network architectures in multiple CSPs, with strong knowledge of at least two of the following: AWS, Azure, GCP, or OCI, and the ability to architect common solutions across heterogeneous cloud environments.
  • Advanced knowledge of cloud networking concepts including VPC/VNet architectures, transit networking, peering, private endpoints, cloud-native firewalls, NAT, load balancing, DNS, and private connectivity services.
  • Advanced knowledge of TCP/IP and enterprise routing technologies, including BGP, route propagation, route filtering, CIDR planning, and IP address management.
  • Strong understanding of network security architecture, Zero Trust principles, network segmentation, firewalls, security groups, access control policies, encryption, and traffic inspection.
  • Experience designing secure hybrid cloud connectivity using technologies such as AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect, OCI FastConnect, and IPsec VPNs.
  • Experience implementing network infrastructure through Infrastructure as Code, preferably using Terraform, Ansible, GitLab CI/CD, and Git-based configuration management practices.
  • Experience designing resilient network architectures across multiple availability zones, regions, and connectivity paths with clearly defined failure and recovery strategies.
  • Experience designing or operating network architectures within DoD, federal, or other highly regulated environments, including familiarity with RMF, STIGs, NIST security controls, and secure enclave architectures.
  • Ability to translate complex network architectures and technical tradeoffs into clear recommendations for engineering teams, cybersecurity stakeholders, program leadership, and Government customers.
  • Ability to obtain and maintain a DoD Secret security clearance.

Nice To Haves

  • Active DoD Secret or Top Secret clearance.
  • Advanced cloud networking certifications such as AWS Certified Advanced Networking – Specialty, Microsoft Certified: Azure Network Engineer Associate, Google Cloud networking certifications, or equivalent OCI certifications.
  • Professional networking certifications such as CCNP, CCIE, or equivalent advanced network architecture certification.
  • Experience designing networking solutions supporting DoD Impact Levels (IL) 2, 4, 5, and 6, including connectivity and isolation requirements across multiple security boundaries.
  • Experience with Zero Trust Architecture (ZTA) and DoD Zero Trust implementation strategies.
  • Experience with enterprise firewall, SD-WAN, Secure Access Service Edge (SASE), microsegmentation, or cloud network security platforms.
  • Experience implementing centralized DNS, IPAM, network observability, flow-log analysis, and network policy management across multiple CSPs.
  • Familiarity with Kubernetes and container networking, including ingress/egress architecture, service networking, network policies, and cloud-native load balancing.
  • Experience developing multi-cloud network reference architectures and reusable IaC modules that abstract CSP-specific implementations into standardized enterprise patterns.
  • Experience supporting large-scale cloud migration, application modernization, or enterprise cloud platform programs within the Department of Defense.

Responsibilities

  • Design and maintain enterprise network architectures across AWS, Azure, GCP, and OCI, including virtual networks, routing, segmentation, ingress/egress, private connectivity, DNS, load balancing, and network security services.
  • Develop reusable reference architectures, design patterns, and technical standards that provide consistency across CSPs while appropriately leveraging cloud-native networking capabilities.
  • Architect secure connectivity between cloud environments, DoD networks, mission partner environments, and external services using technologies such as VPNs, private circuits, cloud interconnects, and software-defined networking.
  • Define enterprise routing, IP address management (IPAM), network segmentation, traffic isolation, and trust-boundary strategies supporting multiple environments, tenants, security domains, and DoD Impact Levels.
  • Partner with cybersecurity teams to implement Zero Trust networking principles, network access controls, firewall policies, encryption, traffic inspection, microsegmentation, and secure ingress/egress architectures.
  • Design highly available and fault-tolerant network architectures that account for CSP regions, availability zones, redundant connectivity, failure domains, disaster recovery, and continuity of operations.
  • Define and implement automated network provisioning using Infrastructure as Code (IaC) technologies such as Terraform and Ansible, integrating network configuration into GitLab-based engineering and deployment workflows.
  • Establish approaches for network monitoring, flow logging, telemetry, performance analysis, capacity management, and troubleshooting across heterogeneous cloud environments.
  • Review proposed network changes and cloud architectures to ensure alignment with established standards, security requirements, operational constraints, and enterprise architecture objectives.
  • Serve as a senior technical advisor to cloud, network, cybersecurity, DevSecOps, and operations teams, providing design guidance and resolving complex networking and connectivity challenges.
  • Evaluate cloud-native and third-party networking technologies to identify opportunities to improve scalability, security, automation, observability, and operational efficiency.
  • Develop architecture diagrams, interface definitions, network patterns, technical decision records, and implementation guidance that enable engineering teams to consistently implement approved architectures.

Benefits

  • competitive salaries
  • a 401(k) retirement plan
  • comprehensive medical/dental/vision coverage
  • flexible work schedules for work/life balance
  • tuition reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service