Senior Network Engineer IRES - SSFB/HSV/FBEL

Amentum•Colorado Springs, CO
•Onsite

About The Position

As a Senior Network Engineer supporting the Next Generation Environment (NGE) on the Integrated Research and Development for Enterprise Solutions (IRES) contract, you will serve as a senior technical contributor responsible for engineering, configuring, implementing, and securing the high-speed data center fabrics and software-defined network enclaves underpinning the Missile Defense Agency’s (MDA) unified digital environment. In this role, you will turn high-level architectural designs into resilient, automated network solutions by configuring Cisco Nexus Spine-Leaf EVPN-VxLAN fabrics, VMware NSX software-defined networks, Versa SD-WAN edge transport, F5 BIG-IP application delivery controllers, and Infoblox enterprise DDI services. You will collaborate across engineering, systems architecture, systems security, multi-contractor consortium performers, and Government stakeholder teams to deliver cohesive hybrid cloud and on-premises network transport. You will play a key role in standardizing infrastructure automation, resolving complex tier-3/4 routing issues, enforcing Zero Trust boundaries, and ensuring continuous network compliance with DoD, DISA, and MDA security requirements.

Requirements

  • 12, or more, years of general (full-time) work experience
  • 6, or more, years of directly related experience
  • 1, or more, years of experience working in a management or leadership role
  • Demonstrated, hands-on, engineering and administration experience with: Cisco Nexus (NX-OS) switches configured in Spine-Leaf / EVPN-VxLAN topologies.
  • Demonstrated, hands-on, engineering and administration experience with: VMware NSX software-defined network segmentation and gateway routing.
  • Demonstrated, hands-on, engineering and administration experience with: F5 BIG-IP LTM/GTM application delivery controllers.
  • Demonstrated, hands-on, engineering and administration experience with: Infoblox DDI/IPAM grid managers.
  • Demonstrated, hands-on, engineering and administration experience with: Versa SD-WAN enterprise solutions or equivalent software-defined WAN transport.
  • Hold a current DoW 8140/8570 IAT Level II or higher certification (e.g., Security+ CE, CySA+, CASP+ CE, CISSP).
  • Active DoW Secret security clearance with verified eligibility to obtain a Top Secret clearance (or active Top Secret).
  • Active DoW Secret Security Clearance

Nice To Haves

  • Active DoW Top Secret security clearance.
  • Cisco Certified Network Professional (CCNP Enterprise or Data Center)
  • VMware Certified Professional - Network Virtualization (VCP-NV) or VCAP-NV
  • F5 Certified Technology Specialist (F5-CTS)
  • Versa Certified SD-WAN Associate/Specialist
  • Infoblox Core DDI Configurator Associate (CDCA)
  • Practical experience scripting or automating network changes with Python, Ansible, or Terraform.
  • Experience supporting the Missile Defense Agency (MDA), the IRES contract, or secure DISA networks.
  • Experience with Agile/SAFe development methodologies and tools (Jira, Confluence).

Responsibilities

  • Configure, deploy, and administer Cisco Nexus (NX-OS) switches operating in high-performance Spine-Leaf topologies.
  • Build, maintain, and optimize EVPN-VxLAN virtual overlay networks, Multi-Site fabrics, vPC domains, and complex underlay routing baselines.
  • Deploy, configure, and manage VMware NSX components including NSX Edge nodes, Tier-0 and Tier-1 logical gateways, and distributed firewalls.
  • Implement policy-driven micro-segmentation rules within virtualized compute environments (vSphere/VCF) to isolate mission workloads and support multi-tenant enclaves.
  • Deploy, configure, and maintain F5 BIG-IP physical and virtual appliances, specifically Local Traffic Managers (LTM) and Global Traffic Managers (GTM).
  • Author and troubleshoot custom F5 iRules, and configure virtual servers, load-balancing pools, health monitors, and secure SSL/TLS decryption profiles.
  • Provision, deploy, and maintain Versa SD-WAN edge appliances (including Director, Analytics, and VOS) to establish secure transport across disparate WAN paths.
  • Configure secure tunneling, dynamic traffic steering rules, QoS queue policies, and security boundaries for remote sites and tactical test networks.
  • Administer enterprise-wide IP Address Management (IPAM), authoritative internal DNS zones, and DHCP scopes utilizing Infoblox Grid Manager.
  • Support the automation of DNS records and IP allocation using Infoblox APIs integrated with Infrastructure-as-Code pipelines.
  • Implement identity-aware access controls, 802.1X network access control (NAC), and FIPS-compliant cryptography tunnels (IPsec/MACsec).
  • Harden all network assets in accordance with DISA STIGs, Risk Management Framework (RMF) guidelines, and MDA cybersecurity requirements to support continuous ATO (cATO).
  • Coordinate and collaborate directly with external contractor performers and systems administrators across the program consortium during joint integration events, lab setups, and production cutovers.
  • Author and execute comprehensive Low-Level Designs (LLDs), Interface Control Documents (ICDs), standard operating procedures (SOPs), deployment runbooks, and cutover plans.
  • Develop and sustain Infrastructure-as-Code (IaC) playbooks and configuration management scripts (Ansible, Terraform, Python, Bash) to automate configuration deployments, perform validation checks, and remediate compliance drift.

Benefits

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service