Network Architect Cybersecurity

Posted Yesterday
Be an Early Applicant
San Antonio, TX, USA
In-Office
150K-194K Annually
Expert/Leader
Cloud • Information Technology • Productivity • Security • Software
The Role
Designs and administers secure enterprise network architectures for DoD environments, including routing, switching, firewalls, Zero Trust segmentation, network sensors, packet brokers, encrypted interconnects, and SIEM telemetry pipelines. Responsibilities include STIG compliance, network automation, performance tuning, incident response support, packet analysis, threat hunting collaboration, and RMF/ATO documentation. Requires active Top Secret clearance with SCI eligibility, extensive enterprise networking and cybersecurity experience, and relevant networking and security certifications.
Summary Generated by Built In
Job Summary & Responsibilities

Required Qualifications

  • Security Clearance: Active Top Secret clearance with SCI eligibility required.
  • Experience: Minimum of 10+ years of progressive, hands-on experience in enterprise network engineering and network security infrastructure within Department of Defense (DoD), intelligence community, or federal enterprise environments.
  • Education: Bachelor’s degree in Network Engineering, Computer Science, Cybersecurity, Information Technology, or an equivalent technical discipline (or 12+ years of relevant experience in lieu of degree).
  • Routing & Switching Mastery: Demonstrated expertise with enterprise routing protocols (BGP, OSPF, ISIS), VLAN/VXLAN design, spine-leaf topologies, and hardware platforms (Cisco Nexus/Catalyst, Juniper Junos, or Arista EOS).
  • Cybersecurity & Perimeter Defense: At least 4+ years of dedicated hands-on experience configuring and administering Next-Generation Firewalls (Palo Alto PAN-OS, Fortinet FortiGate, or Cisco Secure Firewall), VPN concentrators, and zero-trust segmentation policies.
  • Network Visibility & Sensor Deployment: Proven experience deploying and managing network traffic monitoring solutions, such as network TAPs, SPAN/RSPAN sessions, packet brokers (Gigamon, Ixia), or network intrusion sensors (Zeek, Suricata, Snort).
  • DoD Compliance Standards: Strong working knowledge of DISA Network Infrastructure STIGs, SCAP compliance tools, and secure boundary enforcement standards.
  • Certifications: Active DoD 8570/8140 IAT Level II (e.g., CompTIA Security+, CySA+) required; plus professional-level networking/security certification (e.g., Cisco CCNP Enterprise / Security, Palo Alto PCNSE, or Juniper JNCIP).

Preferred Experience

  • Network Automation: Proficiency in automating network workflows and configuration auditing using Python (Netmiko, Scrapli, Nornir), Ansible, and RESTCONF/NETCONF APIs.
  • Data & SIEM Pipeline Integration: Experience forwarding and optimizing high-volume network telemetry to Elastic Stack (ELK), Splunk, or Kafka architectures.
  • Advanced Cryptography: Familiarity with DoD Type-1 encryptors (KG-175 TACLANE) and NSA CSfC (Commercial Solutions for Classified) architectures.
  • Threat Frameworks: Understanding of the MITRE ATT&CK framework for Enterprise, specifically network attack vectors, C2 infrastructure detection, and lateral movement tactics.

Want to learn more about Government Services? Check us out on our platform:

https://www.wwt.com/public-sector

https://www.wwt.com/government-services

Preferred locations: San Antonio, TX

Certain states and localities require employers to post a reasonable estimate of salary range. A reasonable estimate of the current base pay range for this position is $150,000.00 to $194,000.00 annually. Actual salary will be based on a variety of factors, including shift, location, experience, skill set, performance, licensure and certification, and business needs. The range for this position in other geographic locations may differ. Certain positions may also be eligible for variable incentive compensation, such as bonuses or commissions, that is not included in the base pay.

The well-being of WWT employees is essential. So, when it comes to our benefits package, WWT has one of the best. We offer the following benefits to all full-time employees:

  • Health and Wellbeing: Health, Dental, and Vision Care, Onsite Health Centers, Employee Assistance Program, Wellness program
  • Financial Benefits: Competitive pay, Profit Sharing, 401k Plan with Company Matching, Life and Disability Insurance, Tuition Reimbursement
  • Paid Time Off: PTO and Sick Leave (starting at 20 days per year) & Holidays (10 per year), Parental Leave, Military Leave, Bereavement
  • Additional Perks: Nursing Mothers Benefits, Voluntary Legal, Pet Insurance, Employee Discount Program

We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that WWT remains a great place to work for All!

If you have any questions or concerns about this posting, please email [email protected].

Preferred Qualifications

Why WWT?


At World Wide Technology, we work together to make a new world happen. Our important work benefits our clients and partners as much as it does our people and communities across the globe. WWT is dedicated to achieving its mission of creating a profitable growth company that is also a Great Place to Work for All. We achieve this through our world-class culture, generous benefits and by delivering cutting-edge technology solutions for our clients.

Founded in 1990, WWT is a global technology solutions provider leading the AI and Digital Revolution. WWT combines the power of strategy, execution and partnership to accelerate digital transformational outcomes for organizations around the globe. Through its Advanced Technology Center, a collaborative ecosystem of the world's most advanced hardware and software solutions, WWT helps clients and partners conceptualize, test and validate innovative technology solutions for the best business outcomes and then deploys them at scale through its global warehousing, distribution and integration capabilities.

With over 12,000 employees across WWT and Softchoice and more than 60 locations around the world, WWT's culture, built on a set of core values and established leadership philosophies, has been recognized 14 years in a row by Fortune and Great Place to Work® for its unique blend of determination, innovation and creating a great place to work for all.

Want to work with highly motivated individuals on high-performance teams? Join WWT today!

 

What is the Government Services Team and why join? 

Our Government Services team provides cleared resources with a global reach to federal civilian, Department of Defense (DoD), and intelligence community markets. We excel at delivering innovative, operationally ready, and cost-effective IT solutions that accelerate the interoperability and resiliency of mission-critical systems.

What will you be doing?

World Wide Technology (WWT) is seeking a Network Architect Cybersecurity with at least 8 years of enterprise networking and cybersecurity infrastructure experience to support mission-critical Department of Defense (DoD) environments. In this role, you will serve as the primary network architect and security systems integrator, engineering resilient, high-speed, and highly secure network fabrics designed to transport, inspect, and analyze sensitive operational telemetry.

You will design and administer multi-site routed and switched backbones, implement Zero Trust network segmentation, configure Next-Generation Firewalls (NGFWs), and architect high-capacity network visibility architectures—integrating hardware taps, packet brokers, and network sensors (such as Zeek and Suricata) directly into enterprise security operations platforms.

Key Responsibilities:  

  • Enterprise Network Architecture & Operations: Design, deploy, configure, and maintain mission-critical enterprise routing, switching, and transport backbones (BGP, OSPF, EVPN-VXLAN, MPLS) across multi-site DoD and secure enclave environments.
  • Network Security & Boundary Defense: Architect, deploy, and manage Next-Generation Firewalls (NGFW - Palo Alto Networks, Fortinet, or Cisco Firepower), implementing strict zero-trust boundary controls, micro-segmentation, deep packet inspection, and IPS/IDS policies.
  • Sensor Infrastructure & Telemetry Ingestion: Architect and sustain passive/active network visibility infrastructure, including physical/virtual TAPs, network packet brokers (e.g., Gigamon, Ixia), and high-throughput network forensics engines (Zeek, Suricata) to ensure complete packet capture and telemetry ingestion.
  • DoD Compliance & Network Hardening: Harden all network routing, switching, and security appliances in strict adherence to DISA Security Technical Implementation Guides (STIGs), DoD boundary protection requirements, and NIST SP 800-53/Zero Trust Architecture (SP 800-207) controls.
  • Cyber Operations & SIEM Pipeline Alignment: Collaborate closely with SOC analysts and cyber platform teams to route, filter, and stream NetFlow, IPFIX, Syslog, and Zeek/Suricata logs into analytic data pipelines (Elastic Stack/ELK, Splunk, Kafka) for real-time threat detection.
  • Encrypted Transport & Secure Interconnects: Engineer, maintain, and audit secure site-to-site IPsec VPNs, MACsec links, and HAIPE/Type-1 cryptographic overlay tunnels ensuring data-in-transit confidentiality and regulatory compliance across enclaves.
  • Network Automation & Programmability: Develop automation playbooks and custom scripts using Python, Ansible, and REST APIs to streamline switch/router configurations, firmware lifecycle updates, ACL compliance audits, and telemetry routing.
  • Performance Tuning & High Availability: Analyze network telemetry, packet latency, jitter, and link utilization; optimize Quality of Service (QoS), jumbo frame support, and redundant fabric architectures (MLAG, vPC, BFD) to prevent packet loss under high sensor traffic loads.
  • Incident Response & Network Forensics Collaboration: Support cyber incident response and threat hunting investigations by performing advanced packet captures (PCAP analysis), tracing unauthorized lateral movement, and isolating compromised network segments.
  • Technical Documentation & ATO Artifacts: Produce authoritative network topologies, IP addressing schemas, data-flow diagrams, and technical risk documentation required for DoD Risk Management Framework (RMF) and Authority to Operate (ATO) packages.

Skills Required

  • Active Top Secret security clearance with SCI eligibility
  • 10+ years of progressive hands-on enterprise network engineering and network security infrastructure experience in DoD, intelligence community, or federal enterprise environments
  • Bachelor's degree in Network Engineering, Computer Science, Cybersecurity, Information Technology, or equivalent technical discipline; 12+ years relevant experience may substitute
  • Expertise with BGP, OSPF, ISIS, VLAN/VXLAN, spine-leaf topologies, and Cisco, Juniper, or Arista platforms
  • 4+ years configuring and administering next-generation firewalls, VPN concentrators, and Zero Trust segmentation policies
  • Experience deploying network TAPs, SPAN/RSPAN, packet brokers, or network intrusion sensors
  • Working knowledge of DISA Network Infrastructure STIGs, SCAP compliance tools, and secure boundary enforcement standards
  • Active DoD 8570/8140 IAT Level II certification such as CompTIA Security+ or CySA+
  • Professional-level networking or security certification such as CCNP, PCNSE, or JNCIP
  • Proficiency with Python network automation, Ansible, and RESTCONF/NETCONF APIs
  • Experience integrating network telemetry with Elastic Stack, Splunk, or Kafka
  • Familiarity with KG-175 TACLANE and NSA CSfC architectures
  • Understanding of the MITRE ATT&CK Enterprise framework, network attack vectors, C2 detection, and lateral movement
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL

Similar Jobs

World Wide Technology Logo World Wide Technology

Architect

Big Data • Cloud • Hardware • Software • App development
In-Office
San Antonio, TX, USA
9000 Employees
150K-194K Annually

Expedia Group Logo Expedia Group

Architect

AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Hybrid
Austin, TX, USA
16000 Employees
146K-252K Annually

Expedia Group Logo Expedia Group

Product Manager

AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Hybrid
Austin, TX, USA
16000 Employees
138K-220K Annually

Expedia Group Logo Expedia Group

Scientist

AdTech • eCommerce • Information Technology • Software • Travel • Generative AI
Hybrid
Austin, TX, USA
16000 Employees
138K-220K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account