Senior Network Engineer
Job description
Senior Network Engineer at Northwood Space.
About the role
In this pivotal role, you will serve as a senior individual contributor responsible for the design, deployment, and management of the core network infrastructure that supports Northwood's corporate sites and hybrid cloud environments. Your expertise will be critical in establishing and maintaining robust systems that cater to the operational needs of a dual-use space communications organization. Your contributions will directly influence the success of vital space missions through the application of advanced communication technologies.
Key facts
What you'll do
- Architect and construct local area network (LAN) infrastructures for various office locations and facilities, focusing on switching, routing, and VLAN segmentation to enhance network efficiency.
- Oversee the complete lifecycle of network hardware, which includes procurement, firmware updates, and comprehensive documentation to ensure optimal performance.
- Implement and sustain enterprise wireless networks, guaranteeing secure user access while maintaining isolated segments for operational systems.
- Develop and enforce zero-trust network architectures, incorporating microsegmentation and identity-aware access controls to enhance security.
- Configure and manage FortiGate firewalls to enforce security policies and manage security zones effectively.
- Administer Cloudflare Zero Trust configurations and tunnels to facilitate secure remote access and establish site-to-site connectivity.
- Collaborate closely with the security engineering team to enhance network detection capabilities, integrate SIEM solutions, and respond to incidents effectively.
- Design and manage hybrid network connectivity solutions that link on-premises facilities with AWS Commercial, AWS GovCloud, and Cloudflare environments.
- Ensure that network architecture complies with regulations pertaining to controlled unclassified information (CUI).
- Implement network monitoring and observability tools to track performance, availability, and security metrics.
- Develop and maintain network automation processes using tools such as Ansible or NetBox to streamline operations.
- Document network architecture, configurations, and standard operating procedures to maintain clarity and consistency.
- Work in partnership with the security engineering team to review firewall policies and provide compliance evidence for CMMC and FedRAMP standards.
- Collaborate with infrastructure and engineering teams to address operational needs and plan for future scalability.
- Integrate network infrastructure with identity management systems like Okta to enforce access policies effectively.
Requirements
- A Bachelor's degree in Engineering, Computer Science, or a related discipline, accompanied by at least 5 years of experience in enterprise networking, or a minimum of 7 years of relevant experience without a degree.
- Demonstrated expertise in enterprise switching, routing, VLAN design, and network segmentation within production environments.
- Proven track record in deploying and managing FortiGate firewall infrastructures, including policy and zone enforcement.
- Experience in designing and implementing zero-trust network architectures, emphasizing microsegmentation and identity-aware access controls.
- Familiarity with cloud networking in AWS, AWS GovCloud, or multi-cloud settings, including hybrid and private networking solutions.
- Hands-on experience with Cloudflare services, particularly Zero Trust, tunnels, and DNS management.
- Experience in deploying and managing enterprise wireless infrastructure across multiple locations.
- Proficiency with network monitoring, automation, and troubleshooting tools to ensure network reliability.
- Ability to obtain and maintain a TS/SCI clearance for sensitive information handling.
- U.S. citizenship or lawful permanent resident status is essential to comply with ITAR export regulations.
Nice to have
- An active TS clearance or higher is preferred.
- Familiarity with network automation tools such as Ansible and NetBox is advantageous.
- Industry certifications like CCNP, ACNP, or other relevant enterprise networking credentials are a plus.
- A background in aerospace, defense, critical infrastructure, or other sectors regulated by government standards is beneficial.
- Experience with ITAR compliance and network isolation strategies for controlled technical information is desirable.
- Knowledge of CMMC, NIST 800-171, and DFARS compliance requirements related to network architecture is a plus.
- Experience integrating network infrastructure with identity management platforms such as Okta or Azure Active Directory is advantageous.
Skills & tools
- FortiGate
- Cloudflare Zero Trust
- AWS
- AWS GovCloud
- Ansible
- NetBox
- Okta
- SIEM platforms
Practical notes
Northwood is committed to being an Equal Opportunity Employer. If you require any reasonable accommodations during the application or interview process, please let us know. In compliance with U.S. Government regulations regarding space technology exports, including ITAR, applicants must be U.S. citizens, lawful permanent residents, protected individuals, or eligible for necessary authorizations from the U.S. Department of State.