Network Security Architect - Principal

Posted Yesterday
Be an Early Applicant
Fort Meade, MD, USA
In-Office
240K-310K Annually
Expert/Leader
Security • Cybersecurity
The Role
Leads the secure design, engineering, and evolution of enterprise network infrastructure supporting DISA and defense missions. Architects Cisco networks, Palo Alto firewalls, zero-trust boundaries, and cross-domain solutions; guides RMF, STIG, and ATO compliance; conducts threat modeling and vulnerability assessments; establishes configuration standards; mentors engineering teams; leads architecture reviews, site surveys, deployments, and migration planning. The role requires active Top Secret clearance with SCI eligibility and up to 10% travel.
Summary Generated by Built In

Purpose and Impact:


Are you ready to apply your leadership to shape the Cyber, Security, & Intel landscape? Amentum is seeking a Network Security Architect Lead, Principal to join our team of mission-driven professionals at Fort Meade, MD. In this role, you will lead challenging, high-visibility projects that directly impact the Nation’s defense and intelligence missions.


Supporting DISA, Amentum’s Intel and Cyber Division is expanding a proven team of highly skilled engineers and architects to design, deploy, and sustain an innovative IT enterprise solution. As the Principal Network Security Architect, you will serve as the technical visionary and authority for this team, defining secure network boundaries, driving the implementation of zero-trust architectures, and ensuring seamless security integration across complex enterprise environments.


Our team delivers secure, mission-critical capabilities where system integrity and rapid deployment are paramount. We are seeking a Network Security Architect Lead, Principal who combines meticulous security engineering discipline with strategic technical foresight. In this role, you will lead efforts to establish and maintain highly secure, resilient network architectures in a rapidly evolving operational threat environment. Success requires the ability to navigate complex, cross-functional technical dependencies independently while fostering collaborative engineering solutions across integrated teams. To excel, you must possess a proactive leadership mindset and the agility to rapidly master and govern the secure integration of next-generation systems and services.


Work Schedule:  8 Hours per day, Monday thru Friday


Essential Responsibilities:


  • The duties and responsibilities of the Network Security Architect Lead, Principal include but are not limited to the following:
  • Serve as the principal technical authority and visionary for the secure design, engineering, and evolution of the enterprise IT network infrastructure.
  • Architect and engineer high-performance, resilient network transport solutions leveraging enterprise Cisco routing and switching platforms across multi-site environments.
  • Design, deploy, and govern robust perimeter and boundary defense systems utilizing Palo Alto Next-Generation Firewalls (NGFW), including advanced threat prevention, SSL decryption, and security policy management.
  • Lead the security engineering efforts necessary to navigate the Risk Management Framework (RMF) Assessment & Authorization (A&A) process, ensuring all designs comply with DISA Security Technical Implementation Guides (STIGs) and secure an active Authority to Operate (ATO).
  • Define the architectural standards, blueprints, and TTPs for secure network integration, data flow segregation, and cross-domain solutions.
  • Set the technical and daily priorities for the network security engineering team, providing advanced mentorship, design standards, and escalation support for complex network anomalies.
  • Translate complex, high-level operational requirements and DISA security mandates into detailed technical specifications, low-level network designs (LLD), and security architecture diagrams.
  • Organize and lead technical architecture reviews, change control assessments, and security posture briefings with senior program leadership and DISA technical authorities.
  • Collaborate with Systems Engineers, Cloud Architects, and Project Managers to design secure interfaces and schedule authorized service interruptions (ASIs) for critical network upgrades.
  • Conduct comprehensive vulnerability assessments and threat modeling on the network architecture, identifying potential exploit vectors and engineering robust mitigation solutions.
  • Establish baseline configurations and configuration control templates for all network and security hardware, ensuring strict alignment with configuration management policies.
  • Lead technical site surveys, evaluate infrastructure readiness, produce detailed Network Bills of Materials (BOMs), and assist in generating migration schedules for enterprise site deployments.

Work Environment, Physical Demands, and Mental Demands:


  • Employee will work in a SCIF on a daily basis.
  • Employee may also be required to work in a datacenter environment for specified periods of time.

Minimum Requirements (Knowledge, Skills, and Abilities):


  • Fifteen (15) years of experience in network engineering, security architecture, or systems integration, with a primary focus on designing large-scale enterprise secure networks.
  • Seven (7) years of dedicated experience as a senior network security engineer, with at least three (3) years serving as a principal architect or technical lead overseeing security engineering teams.
  • Bachelor’s degree in Network Engineering, Computer Science, Information Technology (IT), Cybersecurity, or a related technical field (equivalent experience may be considered in lieu of a degree).
  • Extensive background designing and maintaining high-performance networks using Cisco routing and switching platforms (e.g., Nexus, Catalyst, ISR/ASR series) across enterprise and data center enclaves.
  • Hands-on technical depth engineering, configuring, and managing Palo Alto Next-Generation Firewalls (NGFWs), including Panorama, App-ID, User-ID, and advanced threat prevention profiles.
  • Proven experience navigating the Risk Management Framework (RMF) and designing network architectures that meet NIST SP 800-53 controls and DISA STIGs to secure and maintain a government Authority to Operate (ATO).
  • Active DoD 8140/8570.01-M Information Assurance Management (IAM) Level III or Information Assurance Technical (IAT) Level III certification (such as CISSP, CISM, or CompTIA CASP+) to meet secure environment compliance requirements.
  • Strong technical depth to produce complex architectural artifacts, including High-Level Designs (HLD), Low-Level Designs (LLD), Network Diagrams (Visio), and detailed Network Bills of Materials (BOMs).
  • Excellent communication, leadership, and technical presentation skills, with a track record of defending complex network security designs before DISA Technical Control Boards and senior leadership.
  • Ability to support non-standard hours, including scheduled maintenance windows, deployment surges, and emergency incident response architectures.
  • Ability to travel up to 10%.

Security Clearance Required:  


  • Must have active Top Secret clearance with SCI eligibility

Minimum Education:


  • Bachelor’s degree in Computer Science, Information Technology (IT), Systems Engineering, or related technical field. Additional years of experience can substitute for degree.

Required Certifications and Qualifications: 


(Minimum of 2 required, other within 180 days of hire):


  • Cisco Certified Internetwork Expert (CCIE) – Security
  • Palo Alto Networks Certified Network Security Engineer (PCNSE) or Palo Alto Networks Certified Network Security Consultant (PCNSC).
  • F5 Certified Administrator BIG-IP
  • HAIPE Configuration/Management Experience
  • CISSP-ISSAP (Information Systems Security Architecture Professional) or CISSP-ISSEP (Information Systems Security Engineering Professional) concentration.
  • Prior experience acting as a Lead Architect or Principal Engineer on high-consequence DISA or DoD programs at Fort Meade.
  • Familiarity with Software-Defined Networking (SDN) technologies such as Cisco SD-Access or Cisco SD-WAN.

#javelin


As part of our commitment to maintaining a safe and compliant work environment, Amentum is a drug-free workplace and requires all personnel to comply with company drug and alcohol policies as a condition of employment.  Employment is contingent upon successful completion of the drug screening process.  Please note that this may include pre-hire screening for marijuana, as well as other federally controlled substances due to Amentum’s role as a federal contractor and trusted partner to the US Government.  


Other Responsibilities:


Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.


Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities.


Procedure Compliance - Each employee must read, understand and implement the general and specific operational, safety, quality and environmental requirements of all plans, procedures and policies pertaining to his/her job. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.

       

Compensation Details:

$240,000 - $310,000

       

The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.


Benefits Overview:

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance

  • Paid time off and holidays

  • Retirement benefits (including 401(k) matching)

  • Educational reimbursement

  • Parental leave

  • Employee stock purchase plan

  • Tax-saving options

  • Disability and life insurance

  • Pet insurance


Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

       

Original Posting:

10/09/2026 - Until Filled

Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.

       

Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed,  marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters.

Skills Required

  • Fifteen years of experience in network engineering, security architecture, or systems integration, primarily designing large-scale secure enterprise networks.
  • Seven years of dedicated senior network security engineering experience, including three years as a principal architect or technical lead overseeing security engineering teams.
  • Bachelor’s degree in network engineering, computer science, information technology, cybersecurity, systems engineering, or a related technical field; equivalent experience may substitute.
  • Extensive experience designing and maintaining enterprise and data center networks using Cisco routing and switching platforms.
  • Hands-on experience engineering, configuring, and managing Palo Alto Networks NGFWs, including Panorama, App-ID, User-ID, and advanced threat prevention.
  • Experience with RMF, NIST SP 800-53 controls, DISA STIGs, and government Authority to Operate processes.
  • Active DoD 8140/8570.01-M IAM Level III or IAT Level III certification, such as CISSP, CISM, or CompTIA CASP+.
  • Ability to produce High-Level Designs, Low-Level Designs, Visio network diagrams, and network Bills of Materials.
  • Excellent communication, leadership, and technical presentation skills.
  • Ability to support non-standard hours, maintenance windows, deployment surges, and emergency incident response architectures.
  • Ability to travel up to 10%.
  • Active Top Secret security clearance with SCI eligibility.
  • At least two required certifications or qualifications from the listed options, with remaining qualifications obtainable within 180 days of hire.
  • CCIE Security certification.
  • Palo Alto PCNSE or PCNSC certification.
  • F5 Certified Administrator BIG-IP certification.
  • HAIPE configuration and management experience.
  • CISSP-ISSAP or CISSP-ISSEP concentration.
  • Lead Architect or Principal Engineer experience on high-consequence DISA or DoD programs at Fort Meade.
  • Familiarity with SDN technologies such as Cisco SD-Access or Cisco SD-WAN.

Amentum Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Amentum and has not been reviewed or approved by Amentum.

  • Healthcare Strength — Healthcare offerings are described as comprehensive, with medical, dental, and vision plans and multiple PPO/HSA options. Mental health support via an employee assistance program and other wellness resources is also included in the benefits mix.
  • Retirement Support — Retirement support is positioned as a meaningful part of total rewards through a 401(k) plan with employer matching. Profit-sharing contributions and immediate or near-term vesting in some cases further strengthen the retirement value proposition.
  • Leave & Time Off Breadth — Time-off benefits are presented as solid for the sector, including tiered PTO accrual by tenure and a set of paid holidays. Role-dependent flexible or remote work options and leave programs add to perceived work-life support.

Amentum Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chantilly, VA
18,261 Employees

What We Do

Amentum is a premier global technical and engineering services partner supporting critical programs of national significance across defense, security, intelligence, energy, and environment. We draw from a century-old heritage of operational excellence, mission focus, and successful execution underpinned by a strong culture of safety and ethics. Headquartered in Germantown, Md., we employ more than 20,000 people in 48 states and 28 foreign countries and territories. Visit us at amentum.com to explore how we deliver excellence for our customers’ most vital missions.

Similar Jobs

Hybrid
Laurel, MD, USA
205000 Employees
34K-66K Hourly
Hybrid
Elkridge, MD, USA
205000 Employees
34K-66K Hourly
Hybrid
Ellicott City, MD, USA
205000 Employees
34K-66K Hourly
Hybrid
Columbia, MD, USA
205000 Employees
34K-66K Hourly

Similar Companies Hiring

SEON Thumbnail
Artificial Intelligence • Cybersecurity
Budapest, Budapest
415 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account