Senior Network Engineer - WAN

LeidosHampton, VA
$92,300 - $166,850Onsite

About The Position

The Defense sector at Leidos is seeking a cleared Senior Wide Area Network (WAN) Engineer to engineer, operate, and sustain long-haul transport and routing infrastructure across Department of Defense (DoD/DoW) networks. This individual serves as a Subject Matter Expert on routing for the enterprise WAN — assisting the Network Architect with Border Gateway Protocol (BGP) design, peering, and policy across NIPRNet, SIPRNet, and DISN service delivery points — and is accountable for the availability, performance, and STIG compliance of circuits supporting operational mission traffic worldwide. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Requirements

  • US Citizen with at least a Top Secret clearance and the ability to obtain a SCI prior to your start date.
  • Bachelor’s degree with 8+ years of experience or a Master’s degree with 6+ years of experience. Additional experience may be considered in lieu of a degree.
  • 8+ years of hands-on enterprise WAN engineering and operations experience, with demonstrated ownership of multi-site routed transport in a DoD environment.
  • DoD 8570/8140 IAT Level II certification (Security+ CE or equivalent) plus an active CCNP Enterprise, JNCIP-SP, or equivalent routing certification.
  • Expert-level configuration and troubleshooting of eBGP and iBGP, including route reflectors, confederations, and full-mesh peering designs.
  • Proven ability to author and tune BGP routing policy using route maps, prefix lists, AS-path filters, communities, local preference, MED, and AS-path prepending.
  • Experience establishing and sustaining BGP peering with DISA/DISN service delivery nodes and commercial transport providers.
  • Working knowledge of BGP convergence tuning, dampening, BFD, and route leak/hijack mitigation.
  • Strong proficiency with OSPF, EIGRP, MPLS L2/L3 VPNs, VRFs, QoS policy for voice and mission traffic, and IPv4/IPv6 dual-stack operations.
  • Hands-on administration of Cisco (IOS-XE/IOS-XR/NX-OS) and Juniper (Junos) routing platforms in an operational production network.
  • Experience with Type 1 inline network encryptors (TACLANE/KG-175, HAIPE) and with DISA circuit lifecycle actions (TSR/TSO, DISA Direct/SNAP).
  • Working knowledge of DISA STIGs, RMF, IAVA remediation, and change control under DoD configuration management processes.
  • Demonstrated packet-level analysis skill using Wireshark/tcpdump, SPAN/TAP captures, and NetFlow to isolate faults across provider and government segments.
  • Ability to support on-call rotation, scheduled maintenance windows, and after-hours cutovers; occasional CONUS/OCONUS travel may be required.

Nice To Haves

  • CCIE Enterprise Infrastructure or Service Provider, JNCIE-SP, or DoD 8570/8140 IAT Level III (CASP+ or CISSP).
  • Experience with segment routing, MPLS traffic engineering, or EVPN in a large-scale transport core.
  • Hands-on experience with Cisco SD-WAN or Juniper SDWAN or comparable overlay transport in a DoD/DoW deployment.
  • Proficiency with Python, Ansible, for configuration deployment, compliance auditing, and network state validation.
  • Familiarity with JRSS, DODIN operations, and DoD boundary/CDS architectures.
  • Working knowledge of DWDM, SONET/SDH, and carrier Ethernet handoffs supporting long-haul circuits.

Responsibilities

  • Design, implement, and maintain BGP routing architecture across the enterprise WAN, including peering relationships, autonomous system boundaries, and route policy enforcement.
  • Serve as the escalation authority for complex WAN faults — route flapping, asymmetric paths, MTU and fragmentation issues, black-holed prefixes, and provider circuit degradation.
  • Engineer and execute circuit installations, migrations, bandwidth upgrades, and site cutovers with documented rollback plans and minimal mission impact.
  • Develop and maintain routing policy standards, IP address and ASN allocation plans, and authoritative network documentation including logical and physical topology diagrams.
  • Configure and sustain QoS, traffic engineering, and path selection to prioritize command and control, VTC, and VoIP traffic across constrained transport.
  • Apply DISA STIGs to routing and transport devices, remediate IAVA findings, and support RMF assessment and authorization artifacts and POA&M closure.
  • Coordinate with DISA, NOC/SOC teams, transport providers, and site network personnel to schedule and validate maintenance actions and outage restoration.
  • Monitor WAN health and capacity using SolarWinds, NetFlow, and SNMP-based tooling; produce trend analysis and capacity recommendations for government leadership.
  • Manage Type 1 encryptor configuration and key management coordination in support of secure enclave connectivity.
  • Mentor junior network administrators, review proposed configuration changes, and represent WAN engineering positions at CCB and technical review boards.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service