Job Description
Work Location: Ashburn, VA (onsite)
Travel Requirement: Up to 25%
Citizenship: US Citizenship required
Security Clearance: Must possess existing DHS EOD or DHS Suitability
The Network Engineer supports the U.S. Customs and Border Protection (CBP) Operational Technology Operations Center (OTOC) and the design, implementation, testing, deployment, operation, and sustainment of network infrastructure supporting the Office of Information and Technology (OIT) ISS OTOC. This is a full-time onsite position focused on network engineering, secure connectivity, Watchtower Mobile Device Management (MDM), laboratory validation, and field support for operational technology during an assigned 8-hour day shift.
The Network Engineer designs, configures, implements, validates, troubleshoots, documents, and sustains secure network infrastructure supporting OT and tactical systems across laboratory, enterprise, edge, cloud, and field environments. The position engineers solutions using routers, switches, firewalls, VPNs, wireless networks, network services, cloud connectivity, identity and certificate services, and endpoint technologies to provide reliable, resilient, and secure end-to-end communications.
The position provides hands-on network engineering support for Watchtower and associated Android, Windows, Linux, iOS, radio, sensor, wearable, and tactical endpoints; develops representative lab environments; performs network validation and acceptance testing; supports deployment readiness and technology fielding; and resolves complex network, performance, and interoperability issues. The Network Engineer coordinates with systems integrators, cybersecurity, engineering, OTOC operations, program leadership, vendors, and government stakeholders to implement and sustain approved network solutions in operational environments.
Responsibilities
Network Engineering and Architecture
- Design, configure, implement, test, troubleshoot, optimize, and document network solutions supporting OTOC, Watchtower, operational technology, and tactical systems.
- Configure and support routers, switches, firewalls, VPN gateways, wireless infrastructure, and associated network services in lab and operational environments.
- Support IPv4/IPv6 addressing, subnetting, VLANs, routing, switching, NAT, DNS, DHCP, VPNs, access control, and secure network segmentation.
- Engineer network connectivity across on-premise, cloud, edge, mobile, and disconnected or limited-connectivity environments.
- Analyze network paths and dependencies to identify connectivity, latency, packet loss, routing, name-resolution, firewall, VPN, or configuration issues.
- Use packet captures, logs, monitoring platforms, command-line tools, and other network diagnostic methods to isolate and resolve complex problems.
- Develop and maintain network diagrams, IP address plans, interface definitions, configuration baselines, port/protocol matrices, build records, and implementation documentation.
- Maintain network configuration management, backups, version control, standards, configuration baselines, and repeatable deployment practices.
- Engineer and review network changes for technical dependencies, capacity and performance impacts, security considerations, validation requirements, implementation sequencing, and rollback needs.
Watchtower and Operational Technology Networking
- Provide network engineering and connectivity support for the Watchtower MDM platform and supported OT and tactical devices.
- Validate network requirements for Android, Windows, Linux, iOS, radios, sensors, wearables, and other supported endpoints.
- Support device enrollment, provisioning, policy delivery, certificate distribution, remote management, compliance reporting, and over-the-air updates by ensuring required network paths and services are available.
- Validate Watchtower communications across enterprise, wireless, VPN, cloud, edge, offline, and disconnected-use scenarios.
- Troubleshoot connectivity between Watchtower services, managed endpoints, identity services, certificate infrastructure, cloud resources, and other integrated systems.
- Support secure communications architectures and certificate-based connectivity using PKI, X.509 certificates, Certificate Authorities, and client/server certificate lifecycle processes.
Network Laboratory Engineering and Testing
- Build, configure, and maintain representative network lab environments used to evaluate new technologies, network configurations, devices, software releases, and integration changes before operational fielding.
- Develop and execute network connectivity, interoperability, performance, failover, regression, and operational acceptance test procedures.
- Reproduce field network issues in the lab, collect diagnostic data, isolate root causes, validate fixes or workarounds, and document results.
- Validate routing, firewall rules, VPN connectivity, DNS/DHCP services, certificates, wireless connectivity, bandwidth requirements, and endpoint communications before deployment.
- Test network behavior under representative operational conditions, including degraded, edge, intermittent, or disconnected connectivity when applicable.
- Document test objectives, topology, configurations, procedures, results, defects, limitations, corrective actions, and deployment-readiness findings.
- Coordinate network test events with Systems Integrators, cybersecurity, OTOC support personnel, vendors, and government stakeholders.
Network Implementation and Field Deployment
- Engineer and support the staging, configuration, validation, implementation, deployment, and fielding of network-enabled technologies to operational locations.
- Perform site and deployment readiness assessments to identify network connectivity, addressing, routing, firewall, VPN, wireless, power, rack/space, and other infrastructure dependencies.
- Prepare network configurations, deployment packages, diagrams, implementation plans, test checklists, validation procedures, and rollback procedures.
- Perform pre-deployment verification of network devices, firmware/software versions, configurations, certificates, accounts, connectivity, and external dependencies.
- Provide onsite or remote network support during installation, activation, acceptance testing, and transition to operations.
- Troubleshoot field network issues and coordinate corrective actions with systems integration, cybersecurity, carriers/service providers, vendors, and OTOC support teams.
- Capture as-built network configurations, fielding results, lessons learned, known issues, and follow-on actions.
- Support transition of fielded technology to OTOC operations by providing network documentation, troubleshooting guidance, knowledge transfer, and escalation procedures.
Network Operations, Security, Performance, and Sustainment
- Monitor and assess network health, availability, utilization, performance, and connectivity using approved tools and methods.
- Provide Tier 2/Tier 3 network engineering support for incidents and problems requiring advanced protocol analysis, lab reproduction, configuration changes, performance analysis, or engineering coordination.
- Support incident, problem, and change management activities associated with network infrastructure, integrated systems, releases, deployments, and configuration changes.
- Perform root cause analysis for recurring or high-impact network issues and develop documented corrective and preventive actions.
- Coordinate with cybersecurity personnel to implement approved network security controls, segmentation, access restrictions, secure protocols, and remediation actions.
- Support network device lifecycle activities, including configuration, upgrades, patching, firmware updates, backup/restore, replacement, and decommissioning in accordance with approved processes.
- Maintain technical documentation, SOPs, troubleshooting guides, knowledge articles, network standards, and operational procedures.
- Provide technical briefings, demonstrations, knowledge transfer, and hands-on training to OTOC support personnel and government stakeholders as required.
Requirements
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Network Engineering, Systems Engineering, Communications, Business Technology, or a related field.
- 5+ years of progressively responsible experience in network engineering, network operations, enterprise networking, network architecture/design, operational technology networking, lab testing, technical fielding, or a related technical role.
- Demonstrated hands-on experience configuring and troubleshooting routers, switches, firewalls, VPNs, wireless networks, and enterprise network services.
- Strong knowledge of TCP/IP networking, IPv4/IPv6, subnetting, VLANs, routing, switching, NAT, DNS, DHCP, VPN technologies, firewall concepts, and network segmentation.
- Experience using packet analysis, network monitoring, logging, command-line, and diagnostic tools to troubleshoot connectivity and performance issues.
- Experience engineering network connectivity for Windows, Linux, mobile endpoints, identity services, certificates, cloud platforms, and/or operational technology.
- Experience building or supporting network lab/test environments and executing structured connectivity, interoperability, regression, performance, failover, or acceptance testing.
- Experience preparing, configuring, validating, implementing, and fielding network infrastructure or network-enabled technology into operational or customer environments.
- Demonstrated ability to troubleshoot multi-vendor and cross-domain technical issues and coordinate resolution across network, systems, cybersecurity, application, and vendor teams.
- Ability to create and maintain network diagrams, IP plans, configuration records, implementation procedures, test plans, deployment checklists, troubleshooting guides, and knowledge articles.
- Strong written and verbal communication skills and the ability to communicate effectively with technical teams, program leadership, vendors, and government stakeholders.
- Ability to work full-time onsite during an assigned 8-hour day shift and support fielding/deployment travel as mission requirements dictate.
Strong working knowledge of:
- Cisco or comparable enterprise routing and switching technologies
- Enterprise firewall and VPN technologies
- TCP/IP, IPv4/IPv6, VLANs, routing protocols, NAT, DNS, DHCP, and network segmentation
- Wireless networking and mobile/edge connectivity
- Windows Server and Desktop Operating Systems
- Linux Operating Systems
- Android and iOS Mobile Platforms
- Mobile Device Management (MDM) Solutions
- Active Directory and LDAP Administration
- Microsoft Azure Cloud Services
- AWS Cloud Services
- Virtualization Technologies (Hyper-V, VirtualBox, VMware)
- Knowledge and experience supporting Tactical Awareness Kit (TAK) software applications, including:
- TAK Server Administration
- ATAK/WinTAK Client Configuration
- TAK Infrastructure Deployment and Support
- Tactical Data Distribution and Network Engineering/Integration
- Experience with:
- Public Key Infrastructure (PKI)
- X.509 Certificates
- Certificate Authorities (CA)
- Client and Server Certificate Lifecycle Management
- Secure Communications Architectures
Preferred Qualifications
- Experience supporting Watchtower or a similar MDM, situational awareness, mobility, or operational technology platform.
- Experience engineering and fielding network technologies for government, public safety, defense, border security, tactical, or other mission-oriented environments.
- Experience with enterprise network monitoring and management platforms, packet capture/analysis tools, and centralized logging solutions.
- Experience with dynamic routing protocols, high availability, redundancy, failover, QoS, and network performance analysis.
- Experience supporting cloud networking, hybrid connectivity, virtual networks, security groups, gateways, and related Azure or AWS networking services.
- Experience supporting disconnected, edge, tactical, cellular, satellite, or limited-connectivity environments.
- Experience with network automation, scripting, configuration templating, or infrastructure-as-code concepts.
- Experience with network configuration management, release/change management, implementation planning, and transition-to-operations processes.
- Experience developing or executing formal network engineering test plans, test cases, acceptance criteria, and test reports.
- Relevant technical certifications such as Cisco CCNA/CCNP, CompTIA Network+/Security+, Juniper, Palo Alto Networks, Fortinet, Microsoft Azure, AWS, or comparable certifications.
About Sherpa 6:
At Sherpa 6 we love to solve problems and provide the best solutions for our customers. Our approach to a problem is to find a user-focused and design-driven solution that is simple yet functional and effective. We are a group of enthusiastic forward-thinkers who are excited to build amazing solutions with bleeding-edge technology. We hire people who are forward thinkers, passionate about what they do, love to collaborate and want to constantly learn. We enjoy what we do and we're not afraid to put the extra effort in to accomplish the mission; call us Sherpas. As a Service-Disabled Veteran Owned Small Business, we know what it means to serve. We have made it our mission to be the leaders in solutions that protect and give our Warfighters the edge they need when put into harm's way.
Background Screening/Check/Investigation:
Successful completion of a background screening/check/investigation will/may be required as a condition of hire.
ADA:
Sherpa 6 will make reasonable accommodations in compliance with the Americans with Disabilities Act 1990.
EEO/AA:
Sherpa 6 does not discriminate based on race, color, national origin, sex, religion age, disability, sexual orientation, gender identity, veteran status, height, weight, or marital status in employment or the provision of services and is an equal access/opportunity/affirmative action employer.
Benefits:
We offer a competitive benefits package, covering the cost of medical for you and your family; we also offer dental, vision, health and wellness benefits and a generous retirement savings plan. We believe that our employees can manage their workload and their personal life, therefore we extend a generous PTO policy. This allows our employees to balance their lives as they see fit.
Salary Range:
The proposed salary range is reflective across all Sherpa 6 locations, years of experience, and skill levels. Salary negotiations will be based on a host of factors including but not limited to your geographic location, prior experience, relevant skills, education, and certifications.