Senior Network and Cloud Engineer – AWS Hybrid Infrastructure

CONCEPT SOLUTIONS LLC•Washington, DC
•$160,000 - $170,000•Onsite

About The Position

Concept Solutions is seeking a Senior Network and Cloud Engineer to support the Federal Aviation Administration Command Control and Communications office. The C3 office helps FAA leaders maintain situational awareness and continuity of communications during national emergencies, natural disasters, and major technology disruptions. When service is interrupted, the team supports rapid recovery of essential communications. This position is a senior hands-on engineering role focused on the network infrastructure that connects FAA data centers, field locations, and AWS environments. The engineer will lead assigned network and hybrid-cloud workstreams, provide tier-three troubleshooting, and advise program leadership on secure, available, and supportable solutions. The role works closely with cloud platform, cybersecurity, systems, application, and telecommunications teams.

Requirements

  • Bachelor's degree in computer science, electrical engineering, information technology, or a related technical discipline. Eight additional years of directly relevant network engineering experience may substitute for the degree.
  • Minimum of fifteen (15) years of progressive, relevant experience in enterprise-scale network design, implementation, and operations.
  • At least three years of recent hands-on experience supporting AWS networking or hybrid connectivity in an enterprise, federal, or similarly regulated environment.
  • Demonstrated experience with Cisco routing and switching, TCP IP, BGP or OSPF, VLANs, high availability, and enterprise firewalls.
  • Hands-on experience with AWS VPC networking and at least two of the following: Direct Connect, Transit Gateway, Site-to-Site VPN, or Route 53.
  • Experience troubleshooting complex network incidents using packet captures, flow data, logs, and network monitoring tools.
  • Experience working in a federal contracting, government, defense, or other highly regulated environment.
  • Ability to obtain and maintain a Secret security clearance and to meet the position's on-site, travel, and on-call requirements.
  • Ability to explain technical risks and recommendations clearly to engineers, program leaders, customers, and external vendors.

Nice To Haves

  • Active Secret or higher security clearance.
  • Experience supporting AWS GovCloud, multi-account environments, Control Tower, AWS Organizations, or enterprise landing zones.
  • Experience with Juniper routing, Cisco Catalyst or Nexus, Palo Alto or Cisco Secure Firewalls, F5 BIG-IP, SD-WAN, MPLS, or network virtualization.
  • Working knowledge of one or more automation tools such as Terraform, AWS CloudFormation, Ansible, or Python, with experience using Git and a controlled CI CD process.
  • Experience supporting NIST SP 800-53, FISMA, FedRAMP, STIG implementation, vulnerability remediation, continuous monitoring, or ATO evidence activities.
  • Experience with AWS security and visibility services such as IAM, KMS, Security Hub, GuardDuty, Config, CloudWatch, VPC Flow Logs, Network Manager, Network Firewall, or WAF.
  • Experience with SolarWinds, NetFlow, Riverbed, Cisco Catalyst Center, Splunk, Wireshark, or comparable monitoring and diagnostic platforms.
  • Relevant certification such as CCNP Enterprise, CCIE, JNCIP, AWS Certified Advanced Networking Specialty, AWS Certified Solutions Architect Professional, AWS Certified Security Specialty, Security Plus CE, or CISSP.

Responsibilities

  • Design, implement, maintain, and improve enterprise LAN, WAN, and metropolitan network services supporting mission-critical operations.
  • Configure and troubleshoot routers, switches, firewalls, load balancers, network segmentation, routing protocols, and high-availability designs in multi-vendor environments.
  • Assess capacity, performance, resiliency, carrier diversity, and technical lifecycle risks, and recommend practical improvements.
  • Coordinate with systems administrators and application teams to verify server-to-network integration and reliable access for local and remote users.
  • Design, build, and support secure connectivity between FAA on-premises environments and AWS using services such as Direct Connect, Transit Gateway, Site-to-Site VPN, VPC routing, and Route 53.
  • Lead the network portions of cloud migration and modernization efforts, including connectivity planning, routing, segmentation, firewall policy, cutover, testing, and rollback preparation.
  • Configure and maintain VPC network components, including subnets, route tables, security groups, network access control lists, endpoints, and shared connectivity across AWS accounts.
  • Support networking within established multi-account landing zones and coordinate changes with the cloud platform and security teams.
  • Implement redundant connectivity and disaster recovery network designs that support established recovery time and recovery point objectives.
  • Identify network-related opportunities to improve AWS utilization and cost efficiency and support the program's broader cloud cost-governance process.
  • Implement and validate network security controls across on-premises and AWS environments in support of NIST SP 800-53, FISMA, FedRAMP, OMB Circular A-130, applicable STIGs, and the program's Authorization to Operate.
  • Apply Zero Trust principles through segmentation, least-privilege access, secure remote connectivity, identity-aware controls, and continuous monitoring.
  • Configure and support firewalls, IPsec tunnels, client VPN services, 802.1X, AWS security groups, AWS Network Firewall or WAF where applicable, and related logging and alerting.
  • Partner with cybersecurity staff on security assessments, evidence collection, vulnerability remediation, configuration reviews, and continuous monitoring.
  • Provide tier-three troubleshooting for complex outages and performance issues involving routing, packet loss, latency, asymmetric paths, firewall policy, DNS, or carrier services.
  • Use packet analysis, flow data, logs, and monitoring platforms to determine root cause and restore service within operational priorities.
  • Automate repeatable network and AWS configuration tasks using infrastructure-as-code, configuration management, scripting, version control, and controlled deployment pipelines.
  • Maintain accurate diagrams, configurations, procedures, implementation plans, rollback plans, and operational documentation.
  • Validate patches, firewall changes, automation, and cloud network modifications in a segregated test environment before production release.
  • Coordinate with telecommunications carriers and internet service providers to troubleshoot circuits and restore external connectivity.
  • Mentor junior engineers and share operational knowledge with the broader team.
  • Participate in an after-hours on-call rotation and respond promptly to critical network incidents.

Benefits

  • health, dental, vision and life insurance
  • comprehensive 401(k) plan with matching and immediate vesting
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service