{"schemaVersion":"jobsearcher.job.v1","id":"f5b307c5ea12015183cc53b3","url":"https://jobsearcher.com/jobs/f5b307c5ea12015183cc53b3","canonicalUrl":"https://jobsearcher.com/jobs/f5b307c5ea12015183cc53b3","title":"Network Architect","description":"Overview\nIn this role you will help drive modernization and secure network architectures for a high-visibility Defense program. You will work with government leaders to implement CSfC-compliant networks, focusing on scalable, multi-layered security and cryptographic boundaries. Your work enables compliant, robust communications across DoD/DoD contractors. This is a mission-driven role that combines advanced networking with NSA/CSfC standards to support critical defense missions.\n\nResponsibilitiesArchitect and operate CSfC networks with dual-layer encryption using Cisco and Aruba VPNsDesign, configure, and maintain CSfC architectures aligned with NSA packages (MA, MSC, CWLAN)Implement and tune Palo Alto NGFW policies, IDS/IPS, and App-ID/User-ID/URL filteringConfigure 802.1X network access control with Cisco ISE and Aruba ClearPassManage PKI components, certificates, OCSP, and hardened NTP infrastructurePrepare CSfC compliance artifacts and PMO submission packagesEnsure secure, multi-layer routing with BGP/OSPF and redundant IPsec tunnelsMaintain end-to-end security posture across CNDoD environments\nKey requirementsBachelor's degree or higher in a STEM field and 12-15 years of relevant experience (or equivalent)Active TS/SCI ClearanceActive DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, CISSP)Active Computing Environment certification (Cisco CCNA/CCNP, Aruba ACSA/ACSP)Extensive experience configuring Cisco IOS-XE/ASR and Aruba IPsec/SSL VPNs with IKEv2Experience with Palo Alto PAN-OS, Panorama, and IDS/IPSExperience with Cisco ISE and/or Aruba ClearPass 802.1X implementationsStrong PKI experience (X.509, CA hierarchies, CRLs, OCSP)Knowledge of CNSA Suite, post-quantum readiness, and HSMsFamiliarity with Ansible for automationCertifications like CCNP/CCIE Security/Enterprise, PCNSE, ACCX, or ACMXCisco IOS-XE/ASRAruba Mobility Controllers/GatewaysIPsec and SSL VPNs (IKEv2)BGP and OSPF dynamic routingPalo Alto PAN-OS and PanoramaPalo Alto IDS/IPS","company":"Validatek","rawCompany":"validatek","city":"McLean","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-09-15T04:18:29.123Z","occupations":[{"code":"15-1241.00","title":"Computer Network Architects","slug":"computer-network-architects"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"928110","title":"National Security","slug":"national-security"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Network Architect","description":"Overview\nIn this role you will help drive modernization and secure network architectures for a high-visibility Defense program. You will work with government leaders to implement CSfC-compliant networks, focusing on scalable, multi-layered security and cryptographic boundaries. Your work enables compliant, robust communications across DoD/DoD contractors. This is a mission-driven role that combines advanced networking with NSA/CSfC standards to support critical defense missions.\n\nResponsibilitiesArchitect and operate CSfC networks with dual-layer encryption using Cisco and Aruba VPNsDesign, configure, and maintain CSfC architectures aligned with NSA packages (MA, MSC, CWLAN)Implement and tune Palo Alto NGFW policies, IDS/IPS, and App-ID/User-ID/URL filteringConfigure 802.1X network access control with Cisco ISE and Aruba ClearPassManage PKI components, certificates, OCSP, and hardened NTP infrastructurePrepare CSfC compliance artifacts and PMO submission packagesEnsure secure, multi-layer routing with BGP/OSPF and redundant IPsec tunnelsMaintain end-to-end security posture across CNDoD environments\nKey requirementsBachelor's degree or higher in a STEM field and 12-15 years of relevant experience (or equivalent)Active TS/SCI ClearanceActive DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, CISSP)Active Computing Environment certification (Cisco CCNA/CCNP, Aruba ACSA/ACSP)Extensive experience configuring Cisco IOS-XE/ASR and Aruba IPsec/SSL VPNs with IKEv2Experience with Palo Alto PAN-OS, Panorama, and IDS/IPSExperience with Cisco ISE and/or Aruba ClearPass 802.1X implementationsStrong PKI experience (X.509, CA hierarchies, CRLs, OCSP)Knowledge of CNSA Suite, post-quantum readiness, and HSMsFamiliarity with Ansible for automationCertifications like CCNP/CCIE Security/Enterprise, PCNSE, ACCX, or ACMXCisco IOS-XE/ASRAruba Mobility Controllers/GatewaysIPsec and SSL VPNs (IKEv2)BGP and OSPF dynamic routingPalo Alto PAN-OS and PanoramaPalo Alto IDS/IPS","datePosted":"2026-09-15T04:18:29.123Z","dateModified":"2026-09-15T04:18:29.123Z","hiringOrganization":{"@type":"Organization","name":"Validatek","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"McLean","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f5b307c5ea12015183cc53b3"},"url":"https://jobsearcher.com/jobs/f5b307c5ea12015183cc53b3"}}